Skip to main content
  1. Index/

PKI (Public Key Infrastructure)

Public Key Infrastructure (PKI) is the framework that makes asymmetric cryptography operationally useful at scale. Asymmetric cryptography provides a mathematical relationship between a public key and a private key, but by itself it cannot answer the question a relying party cares about: whose public key is this? PKI answers that question by introducing a trusted third party — the Certificate Authority (CA) — that cryptographically binds a public key to an identity (a hostname, an organisation name, an email address, a SPIFFE ID) by signing a certificate. A relying party that trusts the CA can therefore trust any certificate the CA signs, without needing to know the subject directly. The chain of trust extends recursively: a Root CA signs Intermediate CA certificates, which sign end-entity certificates (also called leaf certificates). Root CA private keys are kept offline in HSMs and used rarely; intermediate CAs handle day-to-day issuance and can be revoked without rotating the root. The set of root CA certificates a system trusts is its trust store — browsers and operating systems ship with a pre-populated trust store of publicly-trusted roots, while private PKIs use custom roots distributed by administrators.

A PKI encompasses more than certificate issuance. Certificate revocation is the mechanism for marking a certificate invalid before its expiry — necessary when a private key is compromised, a subject’s identity changes, or a certificate is mis-issued. The two standard mechanisms are CRL (Certificate Revocation List), a periodically published signed list of revoked serial numbers fetched from a distribution point in the certificate, and OCSP (Online Certificate Status Protocol), a real-time query to a responder operated by the CA. Both have well-known operational weaknesses (CRL staleness, OCSP responder availability and privacy), which is why short certificate lifetimes — hours to days rather than years — have become the preferred mitigation in modern deployments: a certificate that expires tomorrow cannot be usefully revoked. Certificate lifecycle management covers the operational processes around issuance (CSR generation and validation), renewal (before expiry, automated where possible via ACME), and rotation (replacing a certificate and its associated key). Tools like Vault’s PKI engine, cert-manager on Kubernetes, and Let’s Encrypt automate these processes, eliminating the manual CSR/approval cycles that have historically caused outages from missed renewals.

PKI appears throughout the infrastructure stack in this glossary at every point where cryptographic identity is needed. TLS uses PKI to authenticate servers (and in mTLS, clients) via X.509 certificates. Secure Boot relies on a PKI rooted in the UEFI firmware trust store to validate bootloader and kernel signatures. Code signing uses a PKI to bind a public key to a software publisher so that a package manager or OS can verify a binary’s provenance. SPIFFE/SPIRE implements a specialised PKI scoped to workload identities within a trust domain, issuing short-lived X.509-SVIDs from a SPIRE-operated CA. OCI image signing via cosign, and attestation distribution via the referrers API, rely on a PKI (Sigstore’s certificate transparency-backed one, or a private CA) to bind signatures to developer identities. The transition to PQC has direct implications for PKI: every CA key, every leaf certificate, and every signature in the chain that was generated under RSA or ECDSA is potentially HNDL-exposed, and migration requires standing up a parallel PQC CA hierarchy — ML-DSA root and intermediate CAs — and re-issuing the entire certificate population under quantum-safe signatures.

Related

X.509

X.509 is the ITU-T standard (first published in 1988, currently at version 3) that defines the structure of a digital certificate: a signed data structure that binds a public key to an identity and a set of constraints, issued by a Certificate Authority whose signature vouches for the binding. It is the near-universal format for certificates in PKI, TLS, code signing, S/MIME encrypted email, SPIFFE X.509-SVIDs, and SSH host certificates. When someone refers to a TLS certificate, a CA certificate, or a code-signing certificate, they are referring to an X.509 certificate. The format is defined using ASN.1 (Abstract Syntax Notation One) and most commonly serialised as DER (Distinguished Encoding Rules, binary) or PEM (base64-wrapped DER with -----BEGIN CERTIFICATE----- headers, the format seen in most configuration files).

CRL (Certificate Revocation List)

A Certificate Revocation List (CRL) is a signed data structure, published by a Certificate Authority as part of its PKI operations, that lists the serial numbers of X.509 certificates the CA has revoked before their scheduled expiry date. A CA revokes a certificate when its private key is compromised, the subject’s identity information changes, the certificate was mis-issued, or the subject is no longer authorised. Without revocation, a compromised certificate remains trusted by all verifiers until it expires — which for long-lived CA and infrastructure certificates can be years. The CRL is the oldest revocation mechanism, defined in RFC 5280 alongside the X.509 v3 certificate format, and remains widely deployed for CA certificates, code signing certificates, and client certificates in contexts where OCSP is impractical.

OCSP (Online Certificate Status Protocol)

OCSP (Online Certificate Status Protocol), standardised in RFC 6960, is a request-response protocol that allows a verifier to query an OCSP responder — a service operated by the CA or a delegated party — for the current revocation status of a specific X.509 certificate. Where a CRL requires downloading an entire list and searching it locally, an OCSP query asks about exactly one certificate and receives a signed response: good (the certificate is currently valid and not revoked), revoked (revoked, with the revocation time and reason), or unknown (the responder does not know this certificate). The OCSP response is signed by the CA’s OCSP signing key (or a dedicated OCSP responder key with the id-pkix-ocsp-nocheck extension, exempt from its own revocation checking to prevent circularity) and carries a thisUpdate and nextUpdate timestamp defining its freshness window. Verifiers in strict mode reject responses outside the freshness window; in practice, OCSP responses are valid for 24 hours to 7 days depending on the CA’s policy, meaning OCSP shares CRL’s staleness problem, albeit with a smaller window.