
Explore how public key infrastructure uses certificates from certificate authorities to secure web traffic, with root and subordinate CAs, certification paths, and encryption locks.
Explore certificate authority services, including web enrollment, web auto enrollment, policy groups, and online responders, and how they issue certificates and verify revocation via CRL, OCSP, and CDP.
Configure a lab PKI topology with a domain controller, root and subordinate CAs, web enrollment, policy server, and OCSP services on Windows Server 2016 and Windows 11.
Install and configure Active Directory and DNS services, promote the server to a domain controller for a new forest and domain, then log in as domain administrator.
Install and configure the root certificate authority by domain joining, selecting a standalone root certificate authority, and configuring the subordinate certificate authority with CRL and CDP links for issuance.
Configure and deploy a subordinate CA within an existing PKI by generating a certificate signing request, issuing the subordinate certificate from the root CA, and enabling web enrollment and templates.
Learn how to secure a domain by creating a certificate signing request, obtaining a CA-signed certificate, and binding HTTPS on port 443 using IIS manager.
Generate a CSR in IIS, obtain a certificate from the subordinate CA, install the certificate chain including the root CA, then bind https on port 443 to encrypt traffic.
Configure domain policies to auto enroll user and computer certificates by crafting templates, enabling auto enrollment in group policy, and publishing certificates in Active Directory to support AAA server authentication.
Explore certificate extension types such as base64, p12, and p7b, and distinguish extensions that store private keys, public keys, and certificate chains from certificate-only formats.
Learn how online certificate responders use OCSP to verify certificates without downloading large CRL lists, configure OCSP response signing, publish the OCSP URL, and validate certificates.
In this course, we will explore the fundamentals of Public Key Infrastructure (PKI) and its role in securing digital applications, transactions, identities, and supply chains. By the end of this course, you will have a comprehensive understanding of how PKI works, its components, and its applications.
Public Key Infrastructure (PKI) is a system that uses digital certificates to authenticate users, devices, and services. PKI uses asymmetric encryption to create a secure connection for data encryption and signing.
How PKI works
An organization requests a digital certificate from a Certificate Authority (CA).
The Registration Authority (RA) verifies the identity of the organization or user.
The CA issues the digital certificate, which is signed with the CA's private key.
The CA publishes the public key, which can be used to encrypt or verify a digital signature.
The public key is used to encrypt data, which is then decrypted with the private key.
Components of PKI
Certificate Authority (CA)
A trusted third-party that issues, stores, and signs digital certificates. CAs also maintain a Certificate Revocation List (CRL).
Registration Authority (RA)
Verifies the identity of the user or device requesting a digital certificate.
Digital Certificate
An electronic credential that authenticates the identity of a user, device, or service.
Certificate Lifecycle Management (CLM)
Manages the lifecycle of digital certificates, including issuing, renewing, and revoking them.
PKI is used to secure digital applications, transactions, identities, and supply chains.