Doorman service for private network

#1

Hope someone can help me on this.

My understanding from Corda docs is that Corda network is a semi-private. Seems to me that everyone sends a CSR with required information (legalname & emailaddress as in Corda example) to the doorman (there is limited detail about the doorman, but I know that Corda will provide one), will then get certificates and access to the network.

My Questions:

  • If I want to fully control who (the node) can access to the network, do I need to build my own doorman service?
  • Will the doorman also act as an intermediate CA to sign the certificates?