PKI (Public Key Infrastructure)
Definition
Frequently asked questions
What are the components of a public key infrastructure?
Four main elements. The certification authority issues and signs certificates. The registration authority verifies the identity of applicants. A publication service makes certificates and their revocation status available, in the form of lists or online responses. All of this is governed by a certification policy, a document that sets out the rules and levels of assurance.
Why is it called a chain of trust?
Because trust is transmitted step by step. A signer's certificate is signed by an intermediate authority, which is itself certified by a root authority. To validate a signature, software traces this chain back to a root it already knows. If even a single link is missing, expired, or revoked, the signature is not recognized.
What is the difference between a public key and a private key?
The two are mathematically linked but play opposite roles. The private key, which its holder keeps secret, is used to create a signature. The public key, distributed in the certificate, allows anyone to verify this signature. Knowing the public key does not allow you to find the private key: this is the principle of asymmetric cryptography.
Must a company manage its own PKI to sign?
No. Operating a PKI requires secure premises, hardware security modules for key protection, regular audits and strict procedures. Companies therefore rely on trusted service providers, who operate this infrastructure on their behalf and issue certificates on demand, at the time of signature.
Related guides
Related terms
Ready to Put These Concepts Into Practice?
Certyneo allows you to create eIDAS-compliant signature envelopes in just a few clicks, without installation.