Learning path

Full curriculum

Full curriculum

Unit content

Certificates and public-key infrastructure

A public key is useful for authenticating an identity only when the verifier has a trustworthy way to bind that key to the intended name or principal.

A digital certificate is a signed statement that binds identity information to a public key for a specified validity period and purpose.

In a public-key infrastructure (PKI), a verifier starts from one or more trusted root keys and validates a chain of signed certificates leading to the presented key.

Certificate validation must check more than the signature chain. Relevant checks include

  • whether the certificate is valid for the intended name or identity;
  • whether it is within its validity period;
  • whether its declared key usage permits the operation;
  • whether applicable revocation information says the credential should no longer be trusted.

A certificate does not make a server trustworthy in every sense. It authenticates a key-to-identity binding under the PKI's trust model; application behavior and authorization remain separate concerns.