SaveMyCert
Cloud basics

What is public key infrastructure (PKI)?

Public key infrastructure (PKI) is the framework of certificate authorities, digital certificates and public/private key pairs that lets people and systems trust each other’s identities online. Asymmetric encryption can protect a message to someone’s public key, but it cannot by itself tell you that the public key really belongs to who you think it does. PKI fills that gap, and it is the reason the padlock in your browser means something. This guide explains the problem, the main pieces, how PKI underpins HTTPS and signatures, and what happens when certificates expire or must be revoked.

The trust problem PKI solves

PKI exists to answer one question: how do you know a public key genuinely belongs to the website or person claiming it? Public keys are meant to be shared openly, which means an attacker can also hand you a key and pretend to be someone else. Without a way to bind a key to a verified identity, encryption would protect your traffic perfectly while sending it to the wrong party. PKI provides that binding. If you are new to key pairs, our symmetric vs asymmetric encryption guide explains the cryptography this builds on.

The main pieces: keys, certificates and authorities

PKI is built from three basic ingredients that work together:

  • Key pair: a public key shared openly and a private key kept secret by its owner.
  • Digital certificate: a document that ties a public key to an identity, such as a website’s domain name, and carries details like who issued it and how long it is valid.
  • Certificate authority (CA): a trusted organisation that checks identities and digitally signs certificates, vouching that the key and identity belong together.

How the chain of trust works

Your browser or operating system ships with a list of CAs it already trusts. When a site presents its certificate, the browser checks that a trusted CA signed it, directly or through a chain of intermediate authorities, and that the certificate matches the site you asked for. Because the CA’s signature cannot be forged without its private key, a valid chain lets you trust the site’s public key even though you have never met the site. That chain of trust is the central idea: trust flows from a small set of authorities you already rely on down to the certificate in front of you.

Where PKI is used: HTTPS and signatures

PKI’s best-known job is underpinning HTTPS. During the TLS handshake the server presents its certificate, the client validates it through the CA chain, and only then do the two sides agree the keys that protect the connection. Our what is SSL/TLS and HTTP vs HTTPS guides cover the protocol side. PKI is also used for digital signatures, such as signing software or documents so recipients can verify the publisher, and for authenticating devices and users within organisations. In the cloud, providers offer managed certificate services so you do not have to run a CA yourself, and our what is encryption in the cloud guide shows how this fits alongside key management.

Expiry and revocation

Certificates are deliberately not permanent: each has an expiry date, after which clients stop trusting it, which limits the damage if a key is ever stolen and forces regular renewal. If a private key is compromised before expiry, the issuing authority can revoke the certificate, and clients can check revocation status through published lists or online status checks. Expired certificates are one of the most common causes of sudden, embarrassing outages, which is why many teams automate renewal. Exam-depth detail on certificates and key management is in our /revision library, which covers that syllabus lesson by lesson.

Ready to start studying — free?

Original practice questions, timed mock exams and revision notes. No card, nothing to pay.

Jump straight into an exam
SCS-C03CC

Questions, answered

PKI, or public key infrastructure, is the system of certificate authorities, digital certificates and key pairs that lets you verify who you are communicating with online. It binds a public key to a verified identity so that encryption and signatures can be trusted.

Sources

Exam details in this post come from the vendor's published exam guide, which is the authority on what is tested and how.

Keep reading

Cloud basics
What is ransomware? How it works and how to protect against it
Cloud basics
What is social engineering? Common techniques and defences
Cloud basics
What is the CIA triad? Confidentiality, integrity and availability
Cloud basics
ALB vs NLB: which AWS load balancer should you use?