Skip to main content

Provisioning and managing certificates in the Web PKI

How service owners should securely provision and manage certificates in the Web PKI.
Yuichiro Chino via Getty Images

Certificates are an important part of providing encryption services. They are used to identify and authenticate clients and gateways at the point when encrypted connections are established. This guidance helps architects, designers and engineers to make appropriate choices when obtaining and managing certificates to authenticate their online services to users.

Note:

This guidance focuses on server authentication rather than client authentication. Most use cases for client authentication are better served with a privately hosted Public Key Infrastructure (PKI), which the NCSC address in separate guidance.



The recommendations in this guidance are targeted at mitigating one or more of these threats and are grouped as such.





Published

Reviewed

Version

1.0