Choose your language
Public Key Infrastructure (PKI) Training
More than 2 million students worldwide

Public Key Infrastructure (PKI) Training

4.5

Master Public Key Infrastructure from cryptographic fundamentals to enterprise deployment and advanced security hardening. This training covers every layer of PKI — architecture, certificate lifecycle, CA operations, and emerging threats. Whether you manage TLS certificates, operate a CA, or design trust frameworks, you will leave with the technical depth to do it right.

Dedika for businesses

What you will learn:

This course covers the full PKI stack, starting with symmetric and asymmetric cryptography, digital signatures, and X.509 certificate structure. You will learn how to design CA hierarchies, operate root key ceremonies, and integrate HSMs for key protection. The curriculum addresses certificate lifecycle workflows including enrolment, renewal, and revocation using OCSP and CRL. You will configure PKI for TLS, S/MIME, code signing, and device authentication in enterprise environments. Advanced modules cover PKI automation with DevOps tooling, cloud-native certificate management, and post-quantum migration planning. Compliance frameworks, audit requirements, and governance structures are also included to prepare you for real-world programme ownership.

How you study in practice Public Key Infrastructure (PKI) Training

How you practise Public Key Infrastructure (PKI) Training

For companies looking to train their team

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the specific needs of your company.

Click here

Course content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Cryptography and PKI

  • Lesson 1 • Digital Signatures

    Teaches how private keys sign data and public keys verify signatures. Directly underpins certificate trust mechanisms covered next.

  • Lesson 2 • Public and Private Key Pairs

    Explains how asymmetric key pairs are generated and mathematically related. Prepares students for certificate-based identity binding.

  • Lesson 3 • Core Cryptographic Concepts

    Introduces encryption types, key lengths, and algorithm families. Establishes vocabulary used throughout the entire course.

  • Lesson 4 • Trust Models and the Need for PKI

    Examines why ad-hoc key exchange fails at scale and how PKI solves it. Sets the motivation for the entire course structure.

  • Lesson 5 • Hash Functions and Data Integrity

    Covers one-way hash functions and their role in verifying data integrity. Connects hashing to digital signatures introduced later.

Chapter 2See details

PKI Architecture and Components

  • Lesson 1 • Certificate Authorities Explained

    Defines the CA role, its responsibilities, and its position in the trust chain. Anchors all subsequent component discussions.

  • Lesson 2 • PKI Hierarchy Design

    Teaches single-tier, two-tier, and three-tier CA hierarchy models. Students select appropriate hierarchy depth for given scenarios.

  • Lesson 3 • Certificate Repositories and Distribution

    Explains LDAP directories, HTTP repositories, and CDN-based distribution. Ensures students understand how relying parties access certificates.

  • Lesson 4 • Registration Authorities and Enrolment

    Covers the RA role in identity vetting before certificate issuance. Shows how enrolment separates identity verification from signing.

  • Lesson 5 • Validation Authorities and Status Services

    Introduces OCSP responders and CRL distribution points as real-time status services. Bridges architecture to revocation topics ahead.

Chapter 3See details

X.509 Certificates In Depth

  • Lesson 1 • Certificate Encoding and Formats

    Explains DER, PEM, PKCS#7, and PKCS#12 encoding formats and their use contexts. Prevents format-mismatch errors in deployment.

  • Lesson 2 • X.509 Certificate Structure

    Walks through the TBSCertificate fields, version numbers, and serial numbers. Provides the structural literacy needed for all certificate tasks.

  • Lesson 3 • Certificate Path Validation

    Teaches the algorithm for building and validating a certification path. Students trace trust from end-entity to root CA step by step.

  • Lesson 4 • Certificate Profiles and Policies

    Defines certificate profiles for end-entity, CA, and code-signing use cases. Connects profiles to policy OIDs embedded in certificates.

  • Lesson 5 • Standard Certificate Extensions

    Covers critical and non-critical extensions including key usage and subject alternative names. Students learn which extensions govern certificate behaviour.

Chapter 4See details

CA Operations and Key Management

  • Lesson 1 • CA Installation and Initial Setup

    Guides through hardware selection, OS hardening, and CA software installation. Establishes a secure operational baseline before key generation.

  • Lesson 2 • HSM Integration and Key Protection

    Covers HSM partitioning, key import/export controls, and backup procedures. Ensures CA private keys never exist unprotected outside the HSM.

  • Lesson 3 • Root CA Key Ceremony

    Details the formal key ceremony process including witness roles and script execution. Students understand why ceremony rigor protects the entire PKI.

  • Lesson 4 • CA Policy and Practice Documents

    Explains Certificate Policy and Certification Practice Statement authoring. Connects documentation to operational and compliance obligations.

  • Lesson 5 • CA Audit and Compliance Monitoring

    Teaches log collection, audit log integrity, and compliance reporting for CA operations. Prepares students for external audits and self-assessments.

Chapter 5See details

Certificate Lifecycle Management

  • Lesson 1 • Certificate Issuance and Approval

    Explains CA signing operations, approval workflows, and issuance policies. Connects enrolment to the signed certificate artifact.

  • Lesson 2 • Certificate Request and Enrolment

    Covers PKCS#10 CSR creation, SCEP, EST, and CMP enrolment protocols. Students generate and submit valid certificate requests.

  • Lesson 3 • Certificate Expiration and Archival

    Addresses expiration monitoring, graceful decommissioning, and long-term archival requirements. Closes the lifecycle loop started at enrolment.

  • Lesson 4 • Certificate Renewal and Rekeying

    Distinguishes renewal from rekeying and defines when each is appropriate. Prevents service disruption from expired certificates.

  • Lesson 5 • Certificate Revocation

    Teaches revocation reasons, CRL generation, and OCSP stapling. Students execute revocation and verify propagation to relying parties.

Chapter 6See details

PKI Deployment in Enterprise Environments

  • Lesson 1 • Directory Services and PKI Integration

    Covers publishing certificates to directory services and auto-enrolment via group policy. Automates certificate distribution across enterprise endpoints.

  • Lesson 2 • Code Signing Certificate Deployment

    Explains code-signing certificate issuance, signing workflows, and timestamp authority use. Protects software supply chains through verified publisher identity.

  • Lesson 3 • Device and Machine Identity Certificates

    Addresses certificate-based device authentication for network access and IoT. Scales PKI concepts to non-human identity management.

  • Lesson 4 • TLS Certificate Deployment

    Covers server certificate provisioning, cipher suite selection, and TLS handshake validation. Directly addresses the most common PKI deployment scenario.

  • Lesson 5 • Email Signing and Encryption with S/MIME

    Teaches S/MIME certificate issuance, client configuration, and cross-organization trust. Enables secure email workflows within and beyond the enterprise.

Chapter 7See details

PKI Security, Threats, and Hardening

  • Lesson 1 • Cryptographic Agility and Algorithm Deprecation

    Teaches how to plan algorithm migrations without service disruption. Prepares organisations for deprecation of weak algorithms and hash functions.

  • Lesson 2 • PKI Threat Landscape

    Catalogues CA compromise, rogue certificate, and mis-issuance threats with real examples. Motivates the hardening controls taught throughout this chapter.

  • Lesson 3 • CA Hardening Controls

    Applies defence-in-depth controls including air-gapping, dual control, and role separation. Reduces attack surface of the most critical PKI components.

  • Lesson 4 • Certificate Transparency and Monitoring

    Explains CT logs, log auditing, and domain monitoring for unauthorised issuance. Gives organisations visibility into certificates issued on their behalf.

  • Lesson 5 • Incident Response for PKI Compromise

    Defines response procedures for CA key compromise, mass revocation, and trust anchor replacement. Students execute a PKI incident response tabletop.

Chapter 8See details

Advanced PKI Topics and Strategy

  • Lesson 1 • Post-Quantum Cryptography Readiness

    Introduces lattice-based and hash-based post-quantum algorithms and their PKI implications. Enables students to assess and plan quantum-safe migrations.

  • Lesson 2 • PKI Metrics and Continuous Improvement

    Defines operational KPIs, certificate inventory health metrics, and improvement cycles. Closes the course with a framework for ongoing PKI excellence.

  • Lesson 3 • PKI Governance and Programme Management

    Defines PKI governance structures, steering committees, and policy review cycles. Positions PKI as a managed programme rather than a one-time deployment.

  • Lesson 4 • Cloud and Managed PKI Services

    Evaluates cloud-hosted CA services, shared responsibility models, and vendor assessment criteria. Helps students decide between on-premises and managed PKI.

  • Lesson 5 • Cross-Domain and Federation Trust

    Covers bridge CAs, cross-certification, and federated identity trust models. Enables PKI interoperability across organisational and national boundaries.

Certification

Your valid completion certificate

This course is for you:

  • Security engineers: responsible for TLS, identity systems, or certificate infrastructure.

  • Systems administrators: managing certificates across servers, devices, or cloud workloads.

  • DevOps engineers: integrating automated certificate provisioning into deployment pipelines.

  • Compliance officers: needing technical fluency to evaluate PKI audit requirements.

  • IT architects: designing trust frameworks for enterprise or multi-cloud environments.

  • Career changers: moving into identity security from networking or general IT roles.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos help a lot with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQ

Who is Dedika?

Is the certificate valid in Nigeria?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course