What is public key infrastructure (PKI)?
Public key infrastructure (PKI) is the framework of certificate authorities, digital certificates and public/private key pairs that lets people and systems trust each other’s identities online. Asymmetric encryption can protect a message to someone’s public key, but it cannot by itself tell you that the public key really belongs to who you think it does. PKI fills that gap, and it is the reason the padlock in your browser means something. This guide explains the problem, the main pieces, how PKI underpins HTTPS and signatures, and what happens when certificates expire or must be revoked.
The trust problem PKI solves
PKI exists to answer one question: how do you know a public key genuinely belongs to the website or person claiming it? Public keys are meant to be shared openly, which means an attacker can also hand you a key and pretend to be someone else. Without a way to bind a key to a verified identity, encryption would protect your traffic perfectly while sending it to the wrong party. PKI provides that binding. If you are new to key pairs, our symmetric vs asymmetric encryption guide explains the cryptography this builds on.
How the chain of trust works
Your browser or operating system ships with a list of CAs it already trusts. When a site presents its certificate, the browser checks that a trusted CA signed it, directly or through a chain of intermediate authorities, and that the certificate matches the site you asked for. Because the CA’s signature cannot be forged without its private key, a valid chain lets you trust the site’s public key even though you have never met the site. That chain of trust is the central idea: trust flows from a small set of authorities you already rely on down to the certificate in front of you.
Where PKI is used: HTTPS and signatures
PKI’s best-known job is underpinning HTTPS. During the TLS handshake the server presents its certificate, the client validates it through the CA chain, and only then do the two sides agree the keys that protect the connection. Our what is SSL/TLS and HTTP vs HTTPS guides cover the protocol side. PKI is also used for digital signatures, such as signing software or documents so recipients can verify the publisher, and for authenticating devices and users within organisations. In the cloud, providers offer managed certificate services so you do not have to run a CA yourself, and our what is encryption in the cloud guide shows how this fits alongside key management.
Expiry and revocation
Certificates are deliberately not permanent: each has an expiry date, after which clients stop trusting it, which limits the damage if a key is ever stolen and forces regular renewal. If a private key is compromised before expiry, the issuing authority can revoke the certificate, and clients can check revocation status through published lists or online status checks. Expired certificates are one of the most common causes of sudden, embarrassing outages, which is why many teams automate renewal. Exam-depth detail on certificates and key management is in our /revision library, which covers that syllabus lesson by lesson.
Original practice questions, timed mock exams and revision notes. No card, nothing to pay.
Questions, answered
Sources
Exam details in this post come from the vendor's published exam guide, which is the authority on what is tested and how.
- ISC2 Certified in Cybersecurity exam outline — ISC2
- AWS Certified Security – Specialty (SCS-C03) exam guide — Amazon Web Services