PKI (Public Key Infrastructure)

PKI, or public key infrastructure, is a framework of technologies, policies, and processes that manages digital certificates and cryptographic keys. It helps systems verify identities and supports secure communication.

What Is a PKI?

A PKI establishes trust between users, devices, applications, and services through digital certificates.

A digital certificate links a public key to an identified subject, such as a website domain or device. A certificate authority signs the certificate after completing the required validation.

Other systems can check that signature and determine whether they trust the certificate’s issuer. This allows them to evaluate the claimed identity without having a direct relationship with the certificate holder.

PKI includes the processes for issuing, distributing, renewing, and revoking certificates. It also establishes rules for protecting the associated private keys. DigiCert’s PKI overview explains how these capabilities support both public websites and private systems.

What Is PKI in Cyber Security?

In cybersecurity, PKI helps establish whether a public key belongs to the identity a system expects to communicate with.

For example, a browser connecting to a website needs to authenticate the server. An enterprise network may need to authenticate a managed laptop before allowing it to connect.

PKI supports several security functions:

  • Authentication of users, devices, and services
  • Encrypted communication through protocols such as TLS
  • Digital signatures that help verify data integrity and origin
  • Certificate-based access to enterprise resources

Authentication and authorization serve different purposes. A valid certificate can help establish identity, but application policies still determine what that identity may access.

What Are the Main Components of PKI?

These components work together to issue certificates and maintain trust throughout their use.

Certificate Authority (CA)

A certificate authority issues and digitally signs certificates. Its signature allows other systems to verify who issued a certificate and whether its contents have changed.

A root CA acts as a trust anchor. Intermediate CAs typically issue certificates beneath that root.

Registration Authority (RA)

A registration authority validates certificate requests according to the organization’s policies. It may check an applicant’s identity or authority to request a certificate.

The RA function can be separate from the CA or integrated into the same service.

Digital Certificates

A certificate typically contains:

  • The subject’s identity or identifiers
  • The subject’s public key
  • The issuing certificate authority
  • A validity period
  • A serial number
  • Permitted uses and other extensions
  • The issuer’s digital signature

The certificate does not contain the subject’s private key.

Public and Private Keys

Public key cryptography uses mathematically related key pairs. The public key can be shared, while the private key must remain protected.

For digital signatures, the private key signs and the public key verifies. Some algorithms also support public key encryption, but not every key type supports every operation. Cloudflare’s public key cryptography guide explains the underlying model.

Certificate Repositories and Status Services

Repositories make certificates and related information available. Certificate revocation lists (CRLs) and Online Certificate Status Protocol (OCSP) services can provide information about revoked certificates.

How clients check and enforce revocation status depends on the application and its configuration.

Certificate Policies

Policies define who can request certificates, how requests are validated, and which uses are permitted. They also establish responsibilities for renewal, key protection, and incident response.

How Does PKI Work?

A typical certificate lifecycle follows these steps:

  1. A device, service, or user generates a key pair in an approved environment.
  2. A certificate request submits the public key and required identity information.
  3. The CA or RA validates the request against its issuance policy.
  4. The CA signs and issues the certificate.
  5. The certificate holder presents it when establishing a connection or performing another supported operation.
  6. The receiving system validates the certificate and, where required, checks proof of possession of the corresponding private key.
  7. The certificate is renewed, replaced, or revoked as circumstances change.

Validation can include checking the certificate chain, validity period, expected identity, permitted uses, and applicable revocation information. A certificate presented by another system should not be trusted merely because it exists. Cloudflare’s PKI implementation guide discusses certificate trust and key protection.

What Is a Real-Life Example of PKI?

Opening an HTTPS website is a common example.

The website presents a TLS certificate. The browser checks that the certificate covers the requested hostname and chains to a trusted root, along with other required checks.

During the TLS handshake, the server proves possession of the corresponding private key. The connection establishes symmetric session keys to protect the traffic that follows.

A valid certificate helps authenticate the connection to the domain. It does not guarantee that the website’s content, products, or business practices are trustworthy.

Where Is PKI Used?

Enterprises use PKI across customer-facing services and internal infrastructure.

  • HTTPS: Authenticates websites and supports encrypted browser connections
  • Mutual TLS: Allows both sides of a connection to authenticate with certificates
  • Enterprise Wi-Fi and VPNs: Supports certificate-based user or device authentication
  • Code signing: Helps recipients verify software publishers and detect changes to signed code
  • Secure email: Supports message signing and encryption through S/MIME
  • IoT environments: Gives supported devices certificate-based identities
  • Workload security: Authenticates services communicating across distributed applications

These uses require appropriate certificate profiles and application support. A certificate issued for one purpose is not automatically suitable for another. Keyfactor’s PKI guide covers certificate and key management across enterprise environments.

Public PKI vs. Private PKI

AspectPublic PKIPrivate PKI
TrustRoots distributed through public trust programsRoots trusted by explicitly configured systems
Typical usePublic-facing websitesInternal services, managed devices, and workloads
Issuance rulesSubject to applicable public trust requirementsDefined by the organization within its security requirements
Client acceptanceDepends on the relevant browser, operating system, or application trust storeRequires the organization’s trust configuration
ManagementCertificates issued through publicly trusted CAsCan be operated internally or through a managed service

“Public” and “private” describe the trust model. They do not mean that one uses public keys while the other uses only private keys.

What Are the Main PKI Security Risks?

PKI depends on reliable issuance, protected keys, and accurate certificate management.

  • Stolen private keys can enable impersonation or unauthorized signing
  • Expired certificates can interrupt application connections
  • Weak enrollment controls can allow unauthorized certificate requests
  • Compromised CAs can undermine trust across many systems
  • Missing ownership records can delay renewal and incident response
  • Inconsistent revocation checks can leave clients accepting compromised credentials

Organizations should inventory certificates, assign owners, automate renewal where appropriate, and monitor deployment failures. Sensitive private keys may require hardware-backed protection, such as a hardware security module.

For enterprises, PKI also needs to align with identity and access management. Certificate ownership, approved use, and retirement should remain accountable throughout an identity’s lifecycle.

Frequently Asked Questions About PKI

Is PKI the Same as Encryption?

No. Encryption is a cryptographic operation that protects confidentiality. PKI manages certificates, keys, and trust relationships that support encryption, authentication, and digital signatures.

Is PKI the Same as SSL or TLS?

No. TLS is a protocol for protecting communications. PKI supplies the certificate trust framework commonly used for TLS authentication. SSL is the older predecessor to TLS.

Does a Digital Certificate Include a Private Key?

No. A certificate contains a public key. Some export formats bundle a certificate with its private key, but these remain separate cryptographic objects.

Can PKI Replace Passwords?

Certificate-based authentication can replace passwords in supported workflows. Deployment still requires secure enrollment, private key protection, and a process for handling lost or compromised devices.

How Can Sennovate Help With Identity Security?

Explore Sennovate’s identity and access management services to discuss how certificate-based identities fit into your access controls and identity lifecycle processes.