
Public Key Infrastructure (PKI) Training
Master Public Key Infrastructure from cryptographic fundamentals to enterprise deployment and advanced security hardening. This training covers every layer of PKI — architecture, certificate lifecycle, CA operations, and emerging threats. Whether you manage TLS certificates, operate a CA, or design trust frameworks, you will leave with the technical depth to do it right.
What you will learn:
This course covers the full PKI stack, starting with symmetric and asymmetric cryptography, digital signatures, and X.509 certificate structure. You will learn how to design CA hierarchies, operate root key ceremonies, and integrate HSMs for key protection. The curriculum addresses certificate lifecycle workflows including enrolment, renewal, and revocation using OCSP and CRL. You will configure PKI for TLS, S/MIME, code signing, and device authentication in enterprise environments. Advanced modules cover PKI automation with DevOps tooling, cloud-native certificate management, and post-quantum migration planning. Compliance frameworks, audit requirements, and governance structures are also included to prepare you for real-world programme ownership.
How you study practically Public Key Infrastructure (PKI) Training
How you practise Public Key Infrastructure (PKI) Training
For companies looking to train their teams
With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.
Course content
8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsFoundations of Cryptography and PKI
Foundations of Cryptography and PKI
Lesson 1 • Digital Signatures
Teaches how private keys sign data and public keys verify signatures. Directly underpins certificate trust mechanisms covered next.
Lesson 2 • Public and Private Key Pairs
Explains how asymmetric key pairs are generated and mathematically related. Prepares students for certificate-based identity binding.
Lesson 3 • Core Cryptographic Concepts
Introduces encryption types, key lengths, and algorithm families. Establishes vocabulary used throughout the entire course.
Lesson 4 • Trust Models and the Need for PKI
Examines why ad-hoc key exchange fails at scale and how PKI solves it. Sets the motivation for the entire course structure.
Lesson 5 • Hash Functions and Data Integrity
Covers one-way hash functions and their role in verifying data integrity. Connects hashing to digital signatures introduced later.
Chapter 2HideHide detailsSee detailsPKI Architecture and Components
PKI Architecture and Components
Lesson 1 • Certificate Authorities Explained
Defines the CA role, its responsibilities, and its position in the trust chain. Anchors all subsequent component discussions.
Lesson 2 • PKI Hierarchy Design
Teaches single-tier, two-tier, and three-tier CA hierarchy models. Students select appropriate hierarchy depth for given scenarios.
Lesson 3 • Certificate Repositories and Distribution
Explains LDAP directories, HTTP repositories, and CDN-based distribution. Ensures students understand how relying parties access certificates.
Lesson 4 • Registration Authorities and Enrolment
Covers the RA role in identity vetting before certificate issuance. Shows how enrolment separates identity verification from signing.
Lesson 5 • Validation Authorities and Status Services
Introduces OCSP responders and CRL distribution points as real-time status services. Bridges architecture to revocation topics ahead.
Chapter 3HideHide detailsSee detailsX.509 Certificates In Depth
X.509 Certificates In Depth
Lesson 1 • Certificate Encoding and Formats
Explains DER, PEM, PKCS#7, and PKCS#12 encoding formats and their use contexts. Prevents format-mismatch errors in deployment.
Lesson 2 • X.509 Certificate Structure
Walks through the TBSCertificate fields, version numbers, and serial numbers. Provides the structural literacy needed for all certificate tasks.
Lesson 3 • Certificate Path Validation
Teaches the algorithm for building and validating a certification path. Students trace trust from end-entity to root CA step by step.
Lesson 4 • Certificate Profiles and Policies
Defines certificate profiles for end-entity, CA, and code-signing use cases. Connects profiles to policy OIDs embedded in certificates.
Lesson 5 • Standard Certificate Extensions
Covers critical and non-critical extensions including key usage and subject alternative names. Students learn which extensions govern certificate behaviour.
Chapter 4HideHide detailsSee detailsCA Operations and Key Management
CA Operations and Key Management
Lesson 1 • CA Installation and Initial Setup
Guides through hardware selection, OS hardening, and CA software installation. Establishes a secure operational baseline before key generation.
Lesson 2 • HSM Integration and Key Protection
Covers HSM partitioning, key import/export controls, and backup procedures. Ensures CA private keys never exist unprotected outside the HSM.
Lesson 3 • Root CA Key Ceremony
Details the formal key ceremony process including witness roles and script execution. Students understand why ceremony rigor protects the entire PKI.
Lesson 4 • CA Policy and Practice Documents
Explains Certificate Policy and Certification Practice Statement authoring. Connects documentation to operational and compliance obligations.
Lesson 5 • CA Audit and Compliance Monitoring
Teaches log collection, audit log integrity, and compliance reporting for CA operations. Prepares students for external audits and self-assessments.
Chapter 5HideHide detailsSee detailsCertificate Lifecycle Management
Certificate Lifecycle Management
Lesson 1 • Certificate Issuance and Approval
Explains CA signing operations, approval workflows, and issuance policies. Connects enrolment to the signed certificate artifact.
Lesson 2 • Certificate Request and Enrolment
Covers PKCS#10 CSR creation, SCEP, EST, and CMP enrolment protocols. Students generate and submit valid certificate requests.
Lesson 3 • Certificate Expiration and Archival
Addresses expiration monitoring, graceful decommissioning, and long-term archival requirements. Closes the lifecycle loop started at enrolment.
Lesson 4 • Certificate Renewal and Rekeying
Distinguishes renewal from rekeying and defines when each is appropriate. Prevents service disruption from expired certificates.
Lesson 5 • Certificate Revocation
Teaches revocation reasons, CRL generation, and OCSP stapling. Students execute revocation and verify propagation to relying parties.
Chapter 6HideHide detailsSee detailsPKI Deployment in Enterprise Environments
PKI Deployment in Enterprise Environments
Lesson 1 • Directory Services and PKI Integration
Covers publishing certificates to directory services and auto-enrolment via group policy. Automates certificate distribution across enterprise endpoints.
Lesson 2 • Code Signing Certificate Deployment
Explains code-signing certificate issuance, signing workflows, and timestamp authority use. Protects software supply chains through verified publisher identity.
Lesson 3 • Device and Machine Identity Certificates
Addresses certificate-based device authentication for network access and IoT. Scales PKI concepts to non-human identity management.
Lesson 4 • TLS Certificate Deployment
Covers server certificate provisioning, cipher suite selection, and TLS handshake validation. Directly addresses the most common PKI deployment scenario.
Lesson 5 • Email Signing and Encryption with S/MIME
Teaches S/MIME certificate issuance, client configuration, and cross-organization trust. Enables secure email workflows within and beyond the enterprise.
Chapter 7HideHide detailsSee detailsPKI Security, Threats, and Hardening
PKI Security, Threats, and Hardening
Lesson 1 • Cryptographic Agility and Algorithm Deprecation
Teaches how to plan algorithm migrations without service disruption. Prepares organisations for deprecation of weak algorithms and hash functions.
Lesson 2 • PKI Threat Landscape
Catalogues CA compromise, rogue certificate, and mis-issuance threats with real examples. Motivates the hardening controls taught throughout this chapter.
Lesson 3 • CA Hardening Controls
Applies defence-in-depth controls including air-gapping, dual control, and role separation. Reduces attack surface of the most critical PKI components.
Lesson 4 • Certificate Transparency and Monitoring
Explains CT logs, log auditing, and domain monitoring for unauthorised issuance. Gives organisations visibility into certificates issued on their behalf.
Lesson 5 • Incident Response for PKI Compromise
Defines response procedures for CA key compromise, mass revocation, and trust anchor replacement. Students execute a PKI incident response tabletop.
Chapter 8HideHide detailsSee detailsAdvanced PKI Topics and Strategy
Advanced PKI Topics and Strategy
Lesson 1 • Post-Quantum Cryptography Readiness
Introduces lattice-based and hash-based post-quantum algorithms and their PKI implications. Enables students to assess and plan quantum-safe migrations.
Lesson 2 • PKI Metrics and Continuous Improvement
Defines operational KPIs, certificate inventory health metrics, and improvement cycles. Closes the course with a framework for ongoing PKI excellence.
Lesson 3 • PKI Governance and Programme Management
Defines PKI governance structures, steering committees, and policy review cycles. Positions PKI as a managed programme rather than a one-time deployment.
Lesson 4 • Cloud and Managed PKI Services
Evaluates cloud-hosted CA services, shared responsibility models, and vendor assessment criteria. Helps students decide between on-premises and managed PKI.
Lesson 5 • Cross-Domain and Federation Trust
Covers bridge CAs, cross-certification, and federated identity trust models. Enables PKI interoperability across organisational and national boundaries.
Your valid completion certificate
This course is for you:
Security engineers: responsible for TLS, identity systems, or certificate infrastructure.
Systems administrators: managing certificates across servers, devices, or cloud workloads.
DevOps engineers: integrating automated certificate provisioning into deployment pipelines.
Compliance officers: needing technical fluency to evaluate PKI audit requirements.
IT architects: designing trust frameworks for enterprise or multi-cloud environments.
Career changers: moving into identity security from networking or general IT roles.
What our students say
Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.

Top training programmes
FAQ
Who is Dedika?
Is the certificate valid in Kenya?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















