Unit content
Certificates and public-key infrastructure
A public key is useful for authenticating an identity only when the verifier has a trustworthy way to bind that key to the intended name or principal.
A digital certificate is a signed statement that binds identity information to a public key for a specified validity period and purpose.
In a public-key infrastructure (PKI), a verifier starts from one or more trusted root keys and validates a chain of signed certificates leading to the presented key.
Certificate validation must check more than the signature chain. Relevant checks include
- whether the certificate is valid for the intended name or identity;
- whether it is within its validity period;
- whether its declared key usage permits the operation;
- whether applicable revocation information says the credential should no longer be trusted.
A certificate does not make a server trustworthy in every sense. It authenticates a key-to-identity binding under the PKI's trust model; application behavior and authorization remain separate concerns.