Skip to main content

IT security

What is PKI (Public Key Infrastructure)?

PKI is the infrastructure of certificates and keys that proves digital identity: the foundation of secure communication between people and systems.

In short

PKI (Public Key Infrastructure) is the combined system of digital certificates, cryptographic key pairs and issuing authorities that makes it possible to prove identity digitally, for people, machines and systems alike.

Every time a browser shows a padlock, an employee logs in with a certificate, or two servers communicate over encryption, it is PKI that delivers the trust. For businesses, PKI is the foundation of secure communication, strong identity on Wi-Fi and VPN, machine identity and the signing of documents and code.

Most PKI incidents are caused not by attacks but by expired certificates with no clear ownership, and the consequence is outages of websites, integrations and logins.

MI Support IT has many years of specialist experience with enterprise PKI, from designing certificate hierarchies and Active Directory Certificate Services to automated renewal and expiry monitoring, and has over the years supplied dedicated PKI specialists to some of Denmark's very largest companies and organisations.

Back to the glossary

What is PKI?

PKI (Public Key Infrastructure) is the combined system of digital certificates, cryptographic key pairs and issuing authorities (CAs) that makes it possible to prove identity digitally. When your browser shows a padlock, when an employee logs in with a certificate, or when two servers communicate over encryption, it is PKI that delivers the trust.

In short, a certificate binds a public key to an identity (a person, a machine or a domain), and a certificate authority vouches for that binding.

Why does PKI matter for businesses?

  • Secure communication: TLS certificates encrypt traffic to websites, APIs and internal systems.
  • Strong identity: Certificate-based login to Wi-Fi, VPN and workstations is significantly harder to steal than passwords.
  • Machine identity: Servers, IoT devices and applications can prove to each other who they are.
  • Signing: Documents, code and emails can be signed so the recipient knows the content is genuine and unaltered.

The typical pitfall: expired certificates

An expired certificate means an outage: websites show errors, integrations stop, and users cannot log in. Most PKI incidents are caused not by attacks but by a lack of overview: hundreds of certificates, each with its own expiry date, spread across systems that no one fully owns.

If you want to go deeper into the encryption behind the certificates, continue with What is encryption?, and Microsoft's documentation for Active Directory Certificate Services on Microsoft Learn is the reference for Windows-based PKI.

The whole topic, including HSM requirements, eIDAS and a maturity checklist, is covered in our free e-book PKI and HSM in practice.

How MI Support IT can help

We have many years of specialist experience with enterprise PKI, from designing certificate hierarchies and Active Directory Certificate Services to automated renewal and expiry monitoring. Among other things, we have supplied PKI specialists to some of Denmark's largest companies. Read more under PKI Management.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.