Digital Trust

What is PKI?

From the bottom of the ocean to the edge of space, PKI establishes trust. At DigiCert, we help you manage and extend it across entire ecosystems. That’s digital trust for the real world.

93%

of organizations consider digital trust important to their business

{{anchor:What is PKI}}

Passwords

Passwords no longer cut it

Your information is as essential as any of your business assets. Adding extra layers of security to your most valuable systems and data is no longer just an option—it’s a necessity. With PKI, you can employ advanced authentication and encryption methods to mitigate risks to your network.

What is PKI

What is PKI?

Public Key Infrastructure (PKI) is a system of processes, technologies, and policies that allows you to encrypt and sign data. You can issue digital certificates that authenticate the identity of users, devices, or services. These certificates create a secure connection for both public web pages and private systems—such as your VPN, internal Wi-Fi, wiki pages, and other services that support MFA.

Private PKI

What is private PKI?

Private PKI allows you to issue your own private SSL certificates off a unique intermediate root often maintained by a publicly trusted CA. This allows you to tailor certificates around unique needs and deploy on-demand certificates for internal purposes.

{{anchor:Use cases}}

Common PKI use cases

Common PKI use cases

Securing web pages

Encrypting files

Authenticating and encrypting email

Authenticating nodes to wireless

Authenticating VPN connections

PKI isn’t just for web security

Despite common misconceptions, PKI is a perfect match for the exploding IoT sector, providing critical authentication measures.

PKI for IoT

Customizable

Digital certificates can size up or down to accommodate any type of device

Scalable

PKI easily scales so you can manage high volumes of certificates effectively

Competitive

IoT certificates are cost-effective and priced for high-volume

Related resources

Webpage

PKI ebook — where you need trust, you need PKI

Learn more

White paper

5 steps to building a scalable PKI

Learn more

Blog

How to build a PKI that scales interview series

Learn more

{{anchor:Talk to an expert}}

Talk to an expert to learn how DigiCert solutions can help you deliver digital trust

By supplying my personal information and clicking submit, I agree to receive communications about DigiCert products and services, and I agree to DigiCert and its affiliates processing my data in accordance with DigiCert’s Privacy Policy.

form sheet template
/forms/eloqua-gtm-system-master-form-contact-us
toc
701Vu00001q2THWIA2
contactUsType
sales

{{anchor:FAQs}}

FAQs

What is PKI?
Public Key Infrastructure (PKI) is a system of processes, technologies, and policies that allows you to encrypt and/or sign data. With PKI, you can issue digital certificates that authenticate the identity of users, devices, or services. These certificates work for both public web pages and private internal services (e.g., to authenticate devices connecting with your VPN, Wiki, Wi-Fi, etc.)
Why should my organization use PKI?

With Public Key Infrastructure (PKI), you can significantly increase the security level of your network. Three key benefits make this possible:

  • Authentication: Validate identities to ensure only authorized users and devices have access to a server.
  • Encryption: Use a certificate to create an encrypted session, so information can be transmitted privately.
  • Data Integrity: Ensure any messages or data transferred to and from devices and servers are not altered.
How is PKI used?

Common use cases for PKI include, but are not limited to:

  • Securing web pages
  • Encrypting files
  • Authenticating and encrypting email messages using S/MIME
  • Authenticating nodes connecting to a wireless network
  • Authenticating connections to your VPN
  • Authenticating connections to sites and services containing corporate data using TLS mutual authentication
What’s end-to-end encryption?
End-to-end encryption is when a message is encrypted at your device, and the decryption is done at the recipient’s device. This means that no third party can intercept your sensitive data.
What is a CA?
A Certificate Authority (CA) is a trusted third party that verifies the identity of an organization applying for a digital certificate. After verifying the organization’s identity, the CA issues a certificate and binds the organization’s identity to a public key. A digital certificate can be trusted because it is chained to the CAs root certificate.
What is a digital certificate?
A digital certificate vouches for the holder’s identity. Like a driver’s license, the certificate has been issued by a trusted third party, cannot be forged, and contains identifying information.
What are public and private keys, and how are they related?
Public and private keys are used to encrypt and decrypt information. Only the private key can decrypt information encrypted by the public key. This key pair is known as asymmetric cryptography. The two keys are mathematically related, but it’s impossible to determine one key using the other.
What are public and private roots?
A root certificate provides the signature when binding an identity to the public key. This is how you identify whether a certificate is valid, and whether you should trust it.
Does DigiCert offer solutions for both public and private PKI?
The short answer is, yes. DigiCert offers solutions for both public and private PKI, along with a platform and RESTful API, which allow you to automate certificate management and customize PKI workflows. Issuing a private digital certificate with DigiCert is a fraction of the cost of a public certificate.
What’s MPKI?
Managed PKI (MPKI) is a solution provided by a CA that allows you to begin automating certificate processes and customizing PKI workflows. Once your organization requires a high volume of certificates, you’ll benefit from an MPKI solution that simplifies certificate management.
Should we set up an internal CA (build) or use a hosted CA (buy)?
You can secure your internal services using an internal CA — organizations commonly do this using Microsoft CA. However, building and maintaining an internal CA can be expensive and time-consuming. Many CAs provide hosted solutions that save you from some of the hardware, software, and personnel costs of building an internal PKI.
What is a Certificate Policy?
A Certificate Policy (CP) is a document created to identify the different actors of a PKI and their roles and duties. The CP specifies practices like how certificates can be used, how names are chosen, and how keys are generated. For in-depth information, see RFC 3647: https://tools.ietf.org/html/rfc3647
What is key storage and how should we handle it?
Key storage, often referred to as key archival, is securely storing the private key in case it’s lost. To meet FIPS compliance and ensure the highest level of security, we suggest storing your keys using a Hardware Security Module (HSM).
What is an HSM?
An HSM is a cryptographic hardware-based option for secure key storage. Typically HSMs are on-premises and require internal resources to maintain. Less expensive options exist — for example, Microsoft Azure Key Vault provides secure storage of keys in Microsoft’s cloud HSM.
How do I get started with building a PKI?

To get started, evaluate your environment by considering your needs and technology. We suggest these five steps:

  • Identify your non-negotiable network security risks
  • Pinpoint the network security risks PKI can mitigate
  • Develop the right mix of public and private PKI
  • Decide whether to build (internal CA) or buy (hosted CA)
  • Determine how to automate delivery of certificates to devices

If you need help, contact one of our PKI architects at enterprise@digicert.com.