Design and build a privately hosted Public Key Infrastructure
Pages
Page 2 of 21
Introduction to PKI
What does a PKI do?
A Public Key Infrastructure (PKI) is used to confirm identity. It does this by proving ownership of a private key. It is a 'trust service' which can be used to verify that a sender or receiver of data are exactly who they claim to be.
A privately hosted PKI serves this purpose within an organisation, rather than as a publicly available service. A private PKI will be used to authenticate entities on an internally hosted service, like a VPN. This is in contrast to a publicly hosted PKI service which will authenticate end entities on public services, like an internet facing public web site.
Our guidance uses the term end entity which refers to something that is represented with in the PKI. An end entity could be a device like a laptop, phone or tablet alternatively it could be a network device or a software service.
By 'organisation' here, we're talking about any group of ' end entities'. This could be a company, made up of people, their laptops, phones and tablets. But, it could also include less obvious ' end entities' like networking devices or any 'smart' technology that we want to communicate with.
Uses of PKIs
A private PKI can act as a trust service for a number of different technologies or systems. Examples include, providing identity and trust services in VPNs, internal web applications, IoT, and end user device authentication.
Why securing your private PKI is important
The trust and authentication part of a system is always an attractive target for attackers because compromise can result in access to such a wide range of data and services, or higher levels of privilege. Since compromise is potentially catastrophic, a system's PKI should be designed with security in mind.
Privately hosted PKI's should not be shared across communities with significantly different security expectations, or operational considerations because it's important to ensure that your PKI is secure enough for your needs.