An intermediary between the CA and PKI system. Used to verify and approve identities during certificate requests. Often setup when direct communication with CA is impractical.