Skip to main content

Public Key Infrastructure (PKI)

PKI is the people, policies, processes, and technology used to issue, validate, renew, and revoke public-key certificates.

What is Public Key Infrastructure (PKI)?

PKI is the people, policies, processes, and technology used to issue, validate, renew, and revoke public-key certificates. A certificate binds a public key to an identity or other subject information. A certification authority can be operated by the same organization or by a third party. Public-key pairs support several operations, including digital signatures and key establishment. The public-encrypt and private-decrypt pattern is not a complete description of PKI.

Why it matters

PKI gives systems a scalable way to bind public keys to named subjects and trust domains. TLS, mutual TLS, code signing, and many device identities depend on correct certificate validation and key management.

How it works

  1. A subject generates or receives a key pair, and an approved process validates the identity or attributes to bind to its public key.
  2. A certification authority signs a certificate, and relying parties validate its chain, purpose, time limits, name, and other required constraints.
  3. Operators protect private keys and renew, replace, or revoke certificates as keys, identities, algorithms, and trust relationships change.

Example

An internal certificate authority issues a certificate to an application service. Pomerium trusts that authority for the route, verifies the upstream server identity, and can present its own client certificate when the service requires mutual TLS.

Pomerium boundary

Pomerium uses certificates for downstream and upstream TLS. Deployment-level downstream mTLS settings select trusted client certificate authorities. Route-level upstream TLS settings can select a custom certificate authority, an expected server name, and a client certificate. The deployment operator remains responsible for the certificate lifecycle and private keys.

Limits and non-claims

  • A compromised certification authority or private key can let an attacker present a certificate that appears valid.
  • Certificate inventory, renewal, revocation, and algorithm migration require continuous operational control.
  • A valid certificate authenticates a key and subject binding, but it does not authorize every resource action.

Evaluation checklist

  • Which trust anchors, names, usages, constraints, algorithms, time rules, and revocation profile apply?
  • How does a validated certificate identity map to the requested resource and action?
  • Can CA compromise, key theft, unsafe issuance, stale revocation, or failed rotation defeat trust?

Sources and further reading

Keep learning

Security Operations and RiskStandards and Protocols

Encryption

Encryption transforms plaintext into ciphertext under a cryptographic key. Symmetric encryption uses a shared secret key.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo