# About certificate on the CA device

**URL:** <https://community.blokada.org/t/about-certificate-on-the-ca-device/13744>\
**Category:** Other Discussions\
**Tags:** ad-blocking, dns, android\
**Created:** [May 26, 2021, 1:33pm UTC](https://community.blokada.org/t/about-certificate-on-the-ca-device/13744 "2021-05-26T13:33:01Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jeiel\_18](https://dub1.discourse-cdn.com/flex017/user_avatar/community.blokada.org/jeiel_18/32/15494_2.png) [@Jeiel\_18](https://community.blokada.org/u/Jeiel_18)\
**Post date:** [May 26, 2021, 1:33pm UTC](https://community.blokada.org/t/about-certificate-on-the-ca-device/13744/1 "2021-05-26T13:33:01Z")

</div>

I found a solution to apply CA safely to users:

“The root certificate private key is offline, so this one can’t be stolen.  
It was used to generate an intermediate key that is stored in a TPM.  
This intermediate key is used to generate short lived “edge” certificate that is only valid 5 days and is regenerated every day.  
The edge certificate is transferred encrypted and stored in memory only on our DNS edge servers.”

---

<div class="post-metadata">

**Author:** ![system](https://dub1.discourse-cdn.com/flex017/user_avatar/community.blokada.org/system/32/7003_2.png) [@system](https://community.blokada.org/u/system)\
**Post date:** [June 2, 2021, 1:33pm UTC](https://community.blokada.org/t/about-certificate-on-the-ca-device/13744/2 "2021-06-02T13:33:34Z")

</div>

This topic was automatically closed after 7 days. New replies are no longer allowed.
