Resources
Resources: PKI Guides and Glossary
Practical guides and plain-English definitions on certificates, certificate authorities, keys, timestamps, eIDAS trust services and identity. Start with the glossary for quick answers, or pick a topic for step-by-step detail.
PKI glossary
Short, plain-English definitions of the terms used across our guides.
- GlossaryWhat Is PKI (Public Key Infrastructure)?How keys, certificates, certificate authorities and revocation work together.Read the definition
- GlossaryWhat Is Certificate Lifecycle Management (CLM)?The stages of finding, tracking, renewing and revoking every certificate, and the protocols that automate them.Read the definition
- GlossaryWhat Is an HSM (Hardware Security Module)?How tamper-resistant hardware creates, stores and uses cryptographic keys, and where HSMs are required.Read the definition
- GlossaryWhat Is an RFC 3161 Timestamp?How a signed time-stamp token proves that data existed at a certain time, and how to verify it.Read the definition
- GlossaryWhat Is a Qualified Trust Service Provider (QTSP) under eIDAS?What qualified status means under eIDAS and eIDAS 2.0, and the steps to become a QTSP.Read the definition
Certificates and lifecycle
Find, renew and automate every certificate before it expires.
GuideWhat Is Certificate Lifecycle Management? A Plain-English Guide for 2026Certificate lifecycle management (CLM) finds, tracks, renews and retires every certificate you use. Learn the five lifecycle stages, why CLM matters more in 2026 and how to start.Read the guide
Guide47-Day TLS Certificates: What the CA/Browser Forum Timeline Means for Your TeamPublic TLS certificates now last at most 200 days, dropping to 100 days in March 2027 and 47 days in March 2029. Here is the CA/Browser Forum timeline and a plan to automate renewals before each deadline.Read the guide
GuideAutomating Certificates with ACME, SCEP and EST: When to Use EachACME, SCEP and EST all automate certificate enrollment and renewal. Learn how each works, where each fits, and how to manage all three from one place.Read the guide
GuideThe 10-Point PKI Health Check: Find Outage Risks Before They HitA 10-point PKI health check covering inventory, expiry, ownership, cryptography, keys, CA hierarchy, revocation, automation, policy and incident readiness, with a scoring table.Read the guide
CA design and governance
Choose what to run yourself and document it so it passes audit.
GuidePrivate CA vs Public CA: Which Certificates Should You Issue Yourself?Public CAs secure what outsiders must trust; private CAs secure what you control. Compare trust, rules, lifetimes, cost and risk, and see which certificates to issue yourself.Read the guide
GuideWriting a CP/CPS That Passes Audit: Common Gaps Auditors FindA CP/CPS passes audit when it is specific, current and matched to real operations. See the RFC 3647 structure, 10 common gaps auditors find and a pre-audit checklist.Read the guide
GuidePost-Quantum Cryptography: A Practical Migration Plan for Your PKIA practical eight-step plan to make your PKI post-quantum ready: inventory, risk ranking, crypto agility, hybrid testing and a staged move to NIST's ML-KEM and ML-DSA.Read the guide
Timestamps, signatures and trust services
Prove when data was signed and what makes a signature legally valid.
GuideHow RFC 3161 Timestamping Proves When a Document Was SignedAn RFC 3161 timestamp binds a document's hash to a trusted time, signed by a Time Stamping Authority. Learn how tokens are issued and verified, where they are used and what eIDAS says about them.Read the guide
GuideDigital Signatures vs Electronic Signatures: What Is Legally Valid?Electronic and digital signatures are not the same thing. Learn what each proves, how eIDAS, ESIGN and UETA treat them, and which level your documents need.Read the guide
GuideBecoming a Qualified Trust Service Provider under eIDAS 2.0: A Step-by-Step ChecklistA step-by-step checklist for becoming a Qualified Trust Service Provider under eIDAS 2.0, from gap analysis and ETSI standards to the conformity assessment, notification and staying qualified.Read the guide
Keys and identity
Protect private keys and pick the right identity platform.
GuideWhy Keys Belong in an HSM: Crypto APIs ExplainedWhy private keys belong in a hardware security module, how applications reach HSMs through PKCS#11, JCE and REST crypto APIs, and how to design a central crypto service.Read the guide
GuideKeycloak vs WSO2 Identity Server: Choosing an Open-Source IAM PlatformKeycloak and WSO2 Identity Server both offer open-source SSO, MFA and directory integration. Here is how they differ, and six questions to help you choose.Read the guide
GuideConfiguring Keycloak as an External IDP for Remote Signing SolutionIn today’s digitally-driven world, secure identity and access management are paramount. Integrating an Identity Provider (IDP) such as Keycloak into your system not only…Read the guide
More from the blog
Earlier articles from the DictaLabs team.
GuideRole of PKI & CLM: Securing Communications, Transactions, and BeyondIn an era dominated by digital interactions, ensuring the security and integrity of data exchange is paramount for businesses and organizations across various sectors.…Read the guide
GuideSecuring IoT Communication: The Role of PKI in Device SecurityIn the ever-expanding realm of IoT (Internet of Things), where devices communicate seamlessly to enhance efficiency and convenience, security stands as a paramount…Read the guide
Products and services
Where these topics meet DictaLabs software and expert services.
Products
- vScrawldigital signature and document workflow management, with native PDF signing, audit trails and multi-step approvals.
- Certinium CLMcertificate lifecycle management with centralized visibility, automation and governance for certificates, whichever certificate authority issues them.
- DictaLabs CAcertificate authority software to issue, manage and revoke digital certificates for users, devices, applications and documents.
- DictaLabs TSAa time stamping authority that issues cryptographically signed timestamps as trusted evidence of when digital data existed.
- Cryptographic APIs (crypto service)a REST-based cryptographic service for key management, HSM integration and cryptographic operations, so applications do not handle keys directly.
Services
- PKI Development and ConsultanciesPKI consulting, secure software development and managed PKI services.
- Trust Service Provider (TSP)design, documentation and audit readiness for trust services, including CP/CPS development and eIDAS support.
- Identity Managementidentity and access management, from single sign-on and passwordless authentication to fine-grained authorization.
- Application Securitysecurity testing, open-source scanning and remediation support for applications, infrastructure and endpoints.
- PKI Risk Assessmenta free PKI and certificate risk assessment, with a report in 48 hours.
Markets we serve
Digital signature and trust service rules in the regions DictaLabs works with.
- PKI and digital signatures in the USAESIGN, UETA and PKI for signing workflows in the United States.
- eIDAS and trust services in EuropeeIDAS signature levels, trust services and PKI in the European Union.
- PKI and digital signatures in the GCCElectronic transactions laws in the UAE, Saudi Arabia, Qatar, Bahrain, Oman and Kuwait.
- PKI and digital signatures in PakistanThe Electronic Transactions Ordinance 2002 and digital signatures in Pakistan.
Have a question we have not covered?
Tell us about your PKI, certificate or signing project and a DictaLabs specialist will get back to you.
