
Cryptography: Learn Public Key Infrastructure (PKI) from Scratch Course
Master Public Key Infrastructure from the ground up — from cryptographic primitives to full CA deployments. This course gives security professionals and IT engineers the technical depth to design, operate, and troubleshoot PKI systems with confidence. You'll work through X.509 certificates, trust hierarchies, revocation mechanisms, and emerging standards like post-quantum cryptography.
What you will learn:
Understand core cryptographic concepts including symmetric encryption, asymmetric key pairs, and hash functions.
Design and deploy multi-tier PKI hierarchies using OpenSSL, HSMs, and enterprise CA tools.
Configure and operate CRL and OCSP revocation infrastructure to meet production reliability standards.
Manage the complete certificate lifecycle from CSR creation through renewal, suspension, and revocation.
Apply PKI to TLS, S/MIME, code signing, IoT device identity, and cloud-native environments.
Interpret and draft Certificate Policy and CPS documents aligned with CA/Browser Forum requirements.
How you study in practice Cryptography: Learn Public Key Infrastructure (PKI) from Scratch Course
How you practice Cryptography: Learn Public Key Infrastructure (PKI) from Scratch Course
For companies that want to train their team
With Dedika for Business, the course includes exercises and examples tailored to your own business and the way your company needs.
Course content
8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsCryptography Fundamentals and Core Concepts
Cryptography Fundamentals and Core Concepts
Lesson 1 • Asymmetric Encryption and Key Pairs
Explains public/private key mathematics and how asymmetric encryption solves key distribution. Directly enables understanding of PKI certificate mechanics.
Lesson 2 • Cryptographic Hash Functions
Defines hashing properties—collision resistance, preimage resistance, and determinism. Hashes are essential to certificate integrity and digital signatures.
Lesson 3 • History and Purpose of Cryptography
Traces cryptography from classical ciphers to modern algorithms, establishing why it matters. Provides context for every PKI mechanism introduced later.
Lesson 4 • Digital Signatures and Non-Repudiation
Shows how private keys sign data and public keys verify it, ensuring authenticity. Non-repudiation is a core PKI guarantee students must internalize early.
Lesson 5 • Symmetric Encryption Explained
Covers shared-key encryption mechanics, common algorithms, and performance trade-offs. Establishes the baseline before asymmetric cryptography is introduced.
Chapter 2HideHide detailsSee detailsPKI Architecture and Core Components
PKI Architecture and Core Components
Lesson 1 • PKI Trust Models and Hierarchies
Compares single-root, cross-certification, and bridge CA models for establishing inter-organizational trust. Students select appropriate models for given scenarios.
Lesson 2 • Certificate Authorities and Trust Anchors
Explains how CAs issue, sign, and revoke certificates, establishing the root of trust. Students understand why CA compromise is catastrophic.
Lesson 3 • What Is Public Key Infrastructure
Defines PKI as a framework of policies, hardware, software, and procedures. Connects cryptographic primitives from Chapter 1 to a structured trust system.
Lesson 4 • Registration Authorities and Subscribers
Covers the RA's identity-vetting function and the subscriber's obligations. Clarifies the division of labor that keeps CA operations secure.
Lesson 5 • PKI Repositories and Distribution Points
Describes LDAP directories, HTTP repositories, and OCSP responders used to publish certificates and revocation data. Connects to later revocation chapters.
Chapter 3HideHide detailsSee detailsDigital Certificates: Structure and Standards
Digital Certificates: Structure and Standards
Lesson 1 • X.509 Certificate Format Deep Dive
Walks through every X.509 v3 field—version, serial number, subject, issuer, validity, and public key. Provides the technical literacy needed for all later PKI tasks.
Lesson 2 • Certificate Encoding and File Formats
Explains DER, PEM, PKCS#7, PKCS#12, and JKS formats and their interoperability. Students convert between formats confidently in lab environments.
Lesson 3 • Certificate Extensions and Constraints
Covers critical and non-critical extensions including key usage, extended key usage, and name constraints. Extensions control what a certificate is authorized to do.
Lesson 4 • Certificate Chain Validation Process
Details path building, signature verification at each level, and policy chaining. Students trace validation failures to their root cause systematically.
Lesson 5 • Certificate Profiles and Policy OIDs
Defines certificate profiles for end-entity, CA, and code-signing use cases. Policy OIDs link certificates to the governing Certificate Policy document.
Chapter 4HideHide detailsSee detailsCertificate Lifecycle Management
Certificate Lifecycle Management
Lesson 1 • Certificate Enrollment and Request Formats
Covers PKCS#10 CSR creation, required fields, and submission protocols. Proper enrollment is the entry point to every certificate's lifecycle.
Lesson 2 • Certificate Suspension and Revocation
Covers CRL and OCSP revocation mechanisms, reason codes, and timing requirements. Revocation is the primary response to key compromise or policy violation.
Lesson 3 • Certificate Expiration and Archival
Addresses expiration handling, certificate archival for long-term validation, and cleanup procedures. Ensures compliance with retention policies after certificate end-of-life.
Lesson 4 • Certificate Issuance and Signing
Explains how a CA signs a CSR, applies extensions, and returns the certificate. Students understand the signing ceremony and its security controls.
Lesson 5 • Certificate Renewal and Re-keying
Distinguishes renewal (same key) from re-keying (new key) and when each is appropriate. Prevents service outages caused by expired certificates.
Chapter 5HideHide detailsSee detailsCertificate Revocation Mechanisms
Certificate Revocation Mechanisms
Lesson 1 • Revocation Checking in Applications
Shows how browsers, OS clients, and custom apps perform revocation checks. Students configure and test revocation enforcement in real software stacks.
Lesson 2 • Certificate Revocation Lists In Depth
Examines CRL structure, delta CRLs, and distribution point configuration. Students publish and consume CRLs correctly in enterprise environments.
Lesson 3 • OCSP Stapling and Performance
Explains how servers staple OCSP responses to TLS handshakes, reducing client latency. Stapling is the modern best practice for high-traffic environments.
Lesson 4 • OCSP Protocol and Responders
Details OCSP request/response format, responder signing, and nonce usage. OCSP provides real-time revocation status without full CRL downloads.
Lesson 5 • Revocation Infrastructure High Availability
Covers load balancing, geo-redundancy, and SLA requirements for revocation services. Downtime in revocation infrastructure can break all certificate validation.
Chapter 6HideHide detailsSee detailsPKI Policy, Governance, and Compliance
PKI Policy, Governance, and Compliance
Lesson 1 • CA/Browser Forum Baseline Requirements
Covers the publicly trusted CA requirements for certificate content, validity periods, and key sizes. Non-compliance results in distrust by major browser vendors.
Lesson 2 • PKI Risk Management and Incident Response
Identifies PKI-specific risks—key compromise, mis-issuance, and CA breach—and response procedures. Students build incident response playbooks for PKI environments.
Lesson 3 • Validation Levels and Assurance Classes
Distinguishes Domain Validation, Organization Validation, and Extended Validation certificate classes. Assurance level determines vetting rigor and relying-party trust.
Lesson 4 • Certificate Policy and CPS Documents
Explains the RFC 3647 framework for writing CP and CPS documents and their legal weight. These documents define the rules every PKI participant must follow.
Lesson 5 • Audit and Compliance Frameworks
Maps PKI operations to WebTrust, ETSI, and internal audit requirements. Regular audits verify that CA practices match published policy commitments.
Chapter 7HideHide detailsSee detailsPKI Deployment and Operations
PKI Deployment and Operations
Lesson 1 • Automating Certificate Issuance with ACME
Covers the ACME protocol for automated domain validation and certificate issuance. Automation eliminates manual renewal errors and reduces operational overhead.
Lesson 2 • PKI Monitoring and Operational Health
Defines metrics, alerting, and dashboards for CA availability, certificate expiry, and CRL freshness. Proactive monitoring prevents silent PKI failures.
Lesson 3 • Designing a PKI Hierarchy
Guides students through sizing, tier selection, and naming conventions for a PKI deployment. Good design decisions here prevent costly restructuring later.
Lesson 4 • Building a CA with OpenSSL
Step-by-step root and intermediate CA creation using OpenSSL configuration files. Students gain hands-on command-line proficiency with the most widely used PKI tool.
Lesson 5 • Hardware Security Modules for CA Keys
Explains HSM integration for protecting CA private keys against extraction. HSMs are mandatory in high-assurance PKI deployments and audit requirements.
Chapter 8HideHide detailsSee detailsAdvanced PKI Topics and Emerging Standards
Advanced PKI Topics and Emerging Standards
Lesson 1 • Certificate Transparency and Audit Logs
Explains CT log structure, SCT embedding, and how monitors detect mis-issuance. CT is now mandatory for publicly trusted TLS certificates.
Lesson 2 • Short-Lived Certificates and Zero-Touch PKI
Covers the trend toward certificates with very short validity periods that eliminate revocation complexity. Students evaluate trade-offs between automation cost and revocation overhead.
Lesson 3 • Decentralized Identity and Verifiable Credentials
Introduces DIDs, verifiable credentials, and their relationship to traditional PKI trust models. Students assess where decentralized identity complements or replaces PKI.
Lesson 4 • PKI in Cloud and Containerized Environments
Addresses managed CA services, service mesh mTLS, and secrets management integration. Cloud-native PKI patterns differ significantly from traditional on-premises deployments.
Lesson 5 • Post-Quantum Cryptography and PKI
Surveys NIST-selected post-quantum algorithms and their impact on certificate key sizes and performance. Students plan migration strategies before quantum threats materialize.
Your valid completion certificate
This course is for you:
Systems administrator: managing certificates daily but lacking formal PKI training.
Security analyst: investigating TLS and trust failures without deep cryptographic grounding.
Network engineer: deploying secure infrastructure who needs to understand certificate validation.
DevOps engineer: automating deployments and wanting to integrate certificate management properly.
IT auditor: reviewing PKI compliance controls without hands-on implementation experience.
Career changer: moving into cybersecurity and building a rigorous, credential-worthy skill set.
What our students say
Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.

I like the content and the presentation style and video transcription, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top trainings
FAQ
Who is Dedika?
Is the certificate valid in the United States?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















