What Is PKI (Public Key Infrastructure)?

Public key infrastructure (PKI) is the set of policies, software, hardware and people used to issue, manage and revoke digital certificates. It lets people, servers, applications and devices prove who they are and protect the data they send over open networks.

How PKI works

PKI is built on public key cryptography, also called asymmetric cryptography. Each user, server or device has a key pair. The private key stays secret with its owner. The public key can be shared with anyone.

Anyone can use the public key to check a signature made with the private key. The public key is also used to set up encrypted connections that only the private key holder can complete.

A public key on its own does not say who owns it. A digital certificate solves this. It is a signed file that binds a public key to a name, such as a website domain, a person or a device. A trusted certificate authority (CA) signs it.

Most certificates use the X.509 format. RFC 5280 defines how X.509 certificates and certificate revocation lists are used on the internet.

The main parts of a PKI

  • Certificate authority (CA): issues and signs certificates and publishes their status.
  • Registration authority (RA): checks the identity of the requester before the CA issues a certificate. It is often part of the CA software.
  • Certificates and key pairs: the X.509 certificates and the keys they describe.
  • Revocation services: certificate revocation lists (CRLs) and the Online Certificate Status Protocol (OCSP, RFC 6960). They tell software that a certificate was cancelled before its end date.
  • Hardware security modules (HSMs): protect the CA’s private keys. See what an HSM is and how it works.
  • Policies: a Certificate Policy (CP) and a Certification Practice Statement (CPS) set the rules. RFC 3647 gives a common structure for these documents.

The chain of trust

Trust flows down a chain. At the top is a root CA. Its certificate is self-signed and is installed in the trust stores of browsers, operating systems or company devices. Root keys are usually kept offline.

The root signs one or more intermediate CAs. The CAs that sign the end-entity certificates used by servers, users and devices are called issuing CAs.

When software sees a certificate, it checks each signature up the chain to a root it trusts. It also checks the dates, the allowed key uses and whether the certificate was revoked.

Public PKI and private PKI

A public PKI is run by CAs whose roots are trusted by default in major browsers and operating systems. Publicly trusted TLS certificates must follow the CA/Browser Forum Baseline Requirements and the rules of each browser’s root program.

A private PKI is run by an organization for its own users, devices and internal services. Outside browsers do not trust it by default. It gives more control over certificate content and lifetime, but the organization must install its own root certificate on every device that needs to trust it.

Many organizations use both. Public certificates protect websites that customers visit. Private certificates protect internal systems, VPNs, Wi-Fi and devices.

Where PKI is used

  • HTTPS (TLS) for websites and APIs, including mutual TLS between services
  • Email signing and encryption (S/MIME)
  • Code signing for software and updates
  • Document signing and digital signatures
  • VPN and Wi-Fi access, for example 802.1X with EAP-TLS
  • Smart card and certificate-based login
  • IoT and device identity

Common PKI challenges

  • Certificates that expire without warning and cause outages
  • Private keys stored without enough protection
  • No full list of which certificates exist and who owns them
  • Revocation checks that are slow or skipped
  • Shorter certificate lifetimes that make manual renewal hard. This is the problem certificate lifecycle management solves.
  • Planning for post-quantum cryptography. NIST published its first post-quantum standards, FIPS 203, FIPS 204 and FIPS 205, in August 2024. PKI teams now need crypto agility: the ability to change algorithms without rebuilding everything.

How DictaLabs helps

DictaLabs CA issues, manages and revokes X.509 certificates for users, servers, devices, applications and documents. It supports Root, Intermediate, Issuing and subordinate CA structures, offline root CAs, HSM integration through PKCS#11, and revocation through CRLs and OCSP. It can be deployed on-premises, in the cloud or in a hybrid setup.

For design work, DictaLabs PKI consulting and managed PKI services cover Root and Intermediate CA hierarchy design, public versus private PKI strategy, CP and CPS documents, and day-to-day managed PKI operations.

If you want an outside view of your current setup, DictaLabs offers a free PKI and certificate risk assessment. PKI engineers review your certificate environment and send a report within 48 hours.

Next step

Planning a new PKI or fixing an old one? Talk to a PKI expert at DictaLabs.

Related