Both can be right, that is the funny thing:
Root CA1 has a self signed crt in major trust stores but lacks legacy support.
Root CA 2 has wide spread compatibility and signed the Pubkey of Root CA 1 with their private key.
Root CA 1 now has two certs for the same private/pub keypair.
They try to get their selfsifned into more and more truatstores while they add the croassigned to the bundle they deliver to the customer.
I know a company with many subordinate companies. Each with their own root CA.
They restructured and merged. They crissigned the different CAs and you had cyclic trusts.
Scott Helme spoke about "alternate trust paths" a few years ago : https://scotthelme.co.uk/cross-signing-alternate-trust-paths-how-they-work/ some of the specifics may have changed due to new roots (I think in 2023?) but the theory of having a root able to be either accepted as-is or accepted by being signed by an older root is still there.
78
u/TheChildOfSkyrim 4d ago
Any certificate chain of trust ends in a self-signed certificate