What Is PKI?
Public Key Infrastructure, or PKI, is the complete system used to create, issue, manage, verify, renew, and revoke digital certificates.
A CA is one part of PKI, but PKI includes more than just the CA.
Component | Role |
|---|---|
Certificate Authority | Issues and signs certificates |
Digital Certificate | Binds a public key to an identity |
Root CA | Top-level trusted authority |
Intermediate CA | Issues certificates on behalf of the root CA |
Trust Store | List of trusted root certificates in browsers or operating systems |
Revocation System | Helps identify certificates that should no longer be trusted |
PKI is what allows HTTPS, TLS, secure email, VPNs, device certificates, and many enterprise authentication systems to work reliably.
Chain of Trust
The chain of trust is the certificate path that connects a website or server certificate back to a trusted root CA.
A common certificate chain looks like:
Website certificate => Intermediate CA certificate => Root CA certificate
The browser or client checks each certificate in the chain. If every signature is valid and the chain ends at a trusted root CA, the certificate can be accepted.
During certificate validation, a client usually checks:
Certificate signature: Was each certificate signed by the correct issuer?
Domain name: Does the certificate match the website being visited?
Validity period: Has the certificate expired?
Revocation status: Has the certificate been revoked?
Trusted root: Does the chain end at a root CA trusted by the browser or operating system?
If any important check fails, the browser shows a certificate warning or blocks the connection.
Chain of Trust in Digital Certificates
Certificate Pinning
Certificate pinning is a security technique where an application remembers or restricts which certificate, public key, or CA should be accepted for a specific server.
Normally, a client trusts any valid certificate chain that leads to a trusted CA. With certificate pinning, the client adds an extra rule: the certificate or public key must also match the pinned value.
Certificate pinning can help reduce the risk of trusting a wrongly issued or fraudulent certificate. However, it must be used carefully because incorrect pinning can break real users if certificates are rotated or replaced.
Certificate pinning is most suitable when:
The app controls both sides: The same organization controls the client app and server.
Certificate rotation is planned: Backup pins and renewal processes are managed properly.
The risk justifies it: The application has a strong reason to restrict trust beyond normal PKI validation.
For many normal websites, standard PKI validation with properly issued TLS certificates is preferred over manual pinning because bad pin management can cause outages.
PKI, CA, Chain of Trust, and Pinning
Concept | Main Purpose |
|---|---|
Certificate Authority | Issues trusted digital certificates |
PKI | Manages certificates, keys, trust, and revocation |
Chain of Trust | Verifies a certificate path back to a trusted root |
Certificate Pinning | Restricts trust to specific certificates, keys, or CAs |
These concepts work together to solve the trust problem in public key cryptography. Encryption protects data, but PKI helps verify that the encryption is happening with the correct party.
Be the first to add a comment.