What is PKI?
PKI (Public Key Infrastructure) is the combined system of digital certificates, cryptographic key pairs and issuing authorities (CAs) that makes it possible to prove identity digitally. When your browser shows a padlock, when an employee logs in with a certificate, or when two servers communicate over encryption, it is PKI that delivers the trust.
In short, a certificate binds a public key to an identity (a person, a machine or a domain), and a certificate authority vouches for that binding.
Why does PKI matter for businesses?
- Secure communication: TLS certificates encrypt traffic to websites, APIs and internal systems.
- Strong identity: Certificate-based login to Wi-Fi, VPN and workstations is significantly harder to steal than passwords.
- Machine identity: Servers, IoT devices and applications can prove to each other who they are.
- Signing: Documents, code and emails can be signed so the recipient knows the content is genuine and unaltered.
The typical pitfall: expired certificates
An expired certificate means an outage: websites show errors, integrations stop, and users cannot log in. Most PKI incidents are caused not by attacks but by a lack of overview: hundreds of certificates, each with its own expiry date, spread across systems that no one fully owns.
If you want to go deeper into the encryption behind the certificates, continue with What is encryption?, and Microsoft's documentation for Active Directory Certificate Services on Microsoft Learn is the reference for Windows-based PKI.
The whole topic, including HSM requirements, eIDAS and a maturity checklist, is covered in our free e-book PKI and HSM in practice.
How MI Support IT can help
We have many years of specialist experience with enterprise PKI, from designing certificate hierarchies and Active Directory Certificate Services to automated renewal and expiry monitoring. Among other things, we have supplied PKI specialists to some of Denmark's largest companies. Read more under PKI Management.