Choose your language
Cryptography: Learn Public Key Infrastructure (PKI) from Scratch Course
More than 2 million students worldwide

Cryptography: Learn Public Key Infrastructure (PKI) from Scratch Course

Master Public Key Infrastructure from the ground up — from cryptographic primitives to full CA deployments. This course gives security professionals and IT engineers the technical depth to design, operate, and troubleshoot PKI systems with confidence. You'll work through X.509 certificates, trust hierarchies, revocation mechanisms, and emerging standards like post-quantum cryptography.

Dedika for businesses

What you will learn:

  • Understand core cryptographic concepts including symmetric encryption, asymmetric key pairs, and hash functions.

  • Design and deploy multi-tier PKI hierarchies using OpenSSL, HSMs, and enterprise CA tools.

  • Configure and operate CRL and OCSP revocation infrastructure to meet production reliability standards.

  • Manage the complete certificate lifecycle from CSR creation through renewal, suspension, and revocation.

  • Apply PKI to TLS, S/MIME, code signing, IoT device identity, and cloud-native environments.

  • Interpret and draft Certificate Policy and CPS documents aligned with CA/Browser Forum requirements.

How you study in practice Cryptography: Learn Public Key Infrastructure (PKI) from Scratch Course

How you practice Cryptography: Learn Public Key Infrastructure (PKI) from Scratch Course

For companies that want to train their team

With Dedika for Business, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Cryptography Fundamentals and Core Concepts

  • Lesson 1 • Asymmetric Encryption and Key Pairs

    Explains public/private key mathematics and how asymmetric encryption solves key distribution. Directly enables understanding of PKI certificate mechanics.

  • Lesson 2 • Cryptographic Hash Functions

    Defines hashing properties—collision resistance, preimage resistance, and determinism. Hashes are essential to certificate integrity and digital signatures.

  • Lesson 3 • History and Purpose of Cryptography

    Traces cryptography from classical ciphers to modern algorithms, establishing why it matters. Provides context for every PKI mechanism introduced later.

  • Lesson 4 • Digital Signatures and Non-Repudiation

    Shows how private keys sign data and public keys verify it, ensuring authenticity. Non-repudiation is a core PKI guarantee students must internalize early.

  • Lesson 5 • Symmetric Encryption Explained

    Covers shared-key encryption mechanics, common algorithms, and performance trade-offs. Establishes the baseline before asymmetric cryptography is introduced.

Chapter 2See details

PKI Architecture and Core Components

  • Lesson 1 • PKI Trust Models and Hierarchies

    Compares single-root, cross-certification, and bridge CA models for establishing inter-organizational trust. Students select appropriate models for given scenarios.

  • Lesson 2 • Certificate Authorities and Trust Anchors

    Explains how CAs issue, sign, and revoke certificates, establishing the root of trust. Students understand why CA compromise is catastrophic.

  • Lesson 3 • What Is Public Key Infrastructure

    Defines PKI as a framework of policies, hardware, software, and procedures. Connects cryptographic primitives from Chapter 1 to a structured trust system.

  • Lesson 4 • Registration Authorities and Subscribers

    Covers the RA's identity-vetting function and the subscriber's obligations. Clarifies the division of labor that keeps CA operations secure.

  • Lesson 5 • PKI Repositories and Distribution Points

    Describes LDAP directories, HTTP repositories, and OCSP responders used to publish certificates and revocation data. Connects to later revocation chapters.

Chapter 3See details

Digital Certificates: Structure and Standards

  • Lesson 1 • X.509 Certificate Format Deep Dive

    Walks through every X.509 v3 field—version, serial number, subject, issuer, validity, and public key. Provides the technical literacy needed for all later PKI tasks.

  • Lesson 2 • Certificate Encoding and File Formats

    Explains DER, PEM, PKCS#7, PKCS#12, and JKS formats and their interoperability. Students convert between formats confidently in lab environments.

  • Lesson 3 • Certificate Extensions and Constraints

    Covers critical and non-critical extensions including key usage, extended key usage, and name constraints. Extensions control what a certificate is authorized to do.

  • Lesson 4 • Certificate Chain Validation Process

    Details path building, signature verification at each level, and policy chaining. Students trace validation failures to their root cause systematically.

  • Lesson 5 • Certificate Profiles and Policy OIDs

    Defines certificate profiles for end-entity, CA, and code-signing use cases. Policy OIDs link certificates to the governing Certificate Policy document.

Chapter 4See details

Certificate Lifecycle Management

  • Lesson 1 • Certificate Enrollment and Request Formats

    Covers PKCS#10 CSR creation, required fields, and submission protocols. Proper enrollment is the entry point to every certificate's lifecycle.

  • Lesson 2 • Certificate Suspension and Revocation

    Covers CRL and OCSP revocation mechanisms, reason codes, and timing requirements. Revocation is the primary response to key compromise or policy violation.

  • Lesson 3 • Certificate Expiration and Archival

    Addresses expiration handling, certificate archival for long-term validation, and cleanup procedures. Ensures compliance with retention policies after certificate end-of-life.

  • Lesson 4 • Certificate Issuance and Signing

    Explains how a CA signs a CSR, applies extensions, and returns the certificate. Students understand the signing ceremony and its security controls.

  • Lesson 5 • Certificate Renewal and Re-keying

    Distinguishes renewal (same key) from re-keying (new key) and when each is appropriate. Prevents service outages caused by expired certificates.

Chapter 5See details

Certificate Revocation Mechanisms

  • Lesson 1 • Revocation Checking in Applications

    Shows how browsers, OS clients, and custom apps perform revocation checks. Students configure and test revocation enforcement in real software stacks.

  • Lesson 2 • Certificate Revocation Lists In Depth

    Examines CRL structure, delta CRLs, and distribution point configuration. Students publish and consume CRLs correctly in enterprise environments.

  • Lesson 3 • OCSP Stapling and Performance

    Explains how servers staple OCSP responses to TLS handshakes, reducing client latency. Stapling is the modern best practice for high-traffic environments.

  • Lesson 4 • OCSP Protocol and Responders

    Details OCSP request/response format, responder signing, and nonce usage. OCSP provides real-time revocation status without full CRL downloads.

  • Lesson 5 • Revocation Infrastructure High Availability

    Covers load balancing, geo-redundancy, and SLA requirements for revocation services. Downtime in revocation infrastructure can break all certificate validation.

Chapter 6See details

PKI Policy, Governance, and Compliance

  • Lesson 1 • CA/Browser Forum Baseline Requirements

    Covers the publicly trusted CA requirements for certificate content, validity periods, and key sizes. Non-compliance results in distrust by major browser vendors.

  • Lesson 2 • PKI Risk Management and Incident Response

    Identifies PKI-specific risks—key compromise, mis-issuance, and CA breach—and response procedures. Students build incident response playbooks for PKI environments.

  • Lesson 3 • Validation Levels and Assurance Classes

    Distinguishes Domain Validation, Organization Validation, and Extended Validation certificate classes. Assurance level determines vetting rigor and relying-party trust.

  • Lesson 4 • Certificate Policy and CPS Documents

    Explains the RFC 3647 framework for writing CP and CPS documents and their legal weight. These documents define the rules every PKI participant must follow.

  • Lesson 5 • Audit and Compliance Frameworks

    Maps PKI operations to WebTrust, ETSI, and internal audit requirements. Regular audits verify that CA practices match published policy commitments.

Chapter 7See details

PKI Deployment and Operations

  • Lesson 1 • Automating Certificate Issuance with ACME

    Covers the ACME protocol for automated domain validation and certificate issuance. Automation eliminates manual renewal errors and reduces operational overhead.

  • Lesson 2 • PKI Monitoring and Operational Health

    Defines metrics, alerting, and dashboards for CA availability, certificate expiry, and CRL freshness. Proactive monitoring prevents silent PKI failures.

  • Lesson 3 • Designing a PKI Hierarchy

    Guides students through sizing, tier selection, and naming conventions for a PKI deployment. Good design decisions here prevent costly restructuring later.

  • Lesson 4 • Building a CA with OpenSSL

    Step-by-step root and intermediate CA creation using OpenSSL configuration files. Students gain hands-on command-line proficiency with the most widely used PKI tool.

  • Lesson 5 • Hardware Security Modules for CA Keys

    Explains HSM integration for protecting CA private keys against extraction. HSMs are mandatory in high-assurance PKI deployments and audit requirements.

Chapter 8See details

Advanced PKI Topics and Emerging Standards

  • Lesson 1 • Certificate Transparency and Audit Logs

    Explains CT log structure, SCT embedding, and how monitors detect mis-issuance. CT is now mandatory for publicly trusted TLS certificates.

  • Lesson 2 • Short-Lived Certificates and Zero-Touch PKI

    Covers the trend toward certificates with very short validity periods that eliminate revocation complexity. Students evaluate trade-offs between automation cost and revocation overhead.

  • Lesson 3 • Decentralized Identity and Verifiable Credentials

    Introduces DIDs, verifiable credentials, and their relationship to traditional PKI trust models. Students assess where decentralized identity complements or replaces PKI.

  • Lesson 4 • PKI in Cloud and Containerized Environments

    Addresses managed CA services, service mesh mTLS, and secrets management integration. Cloud-native PKI patterns differ significantly from traditional on-premises deployments.

  • Lesson 5 • Post-Quantum Cryptography and PKI

    Surveys NIST-selected post-quantum algorithms and their impact on certificate key sizes and performance. Students plan migration strategies before quantum threats materialize.

Certification

Your valid completion certificate

This course is for you:

  • Systems administrator: managing certificates daily but lacking formal PKI training.

  • Security analyst: investigating TLS and trust failures without deep cryptographic grounding.

  • Network engineer: deploying secure infrastructure who needs to understand certificate validation.

  • DevOps engineer: automating deployments and wanting to integrate certificate management properly.

  • IT auditor: reviewing PKI compliance controls without hands-on implementation experience.

  • Career changer: moving into cybersecurity and building a rigorous, credential-worthy skill set.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the presentation style and video transcription, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQ

Who is Dedika?

Is the certificate valid in the United States?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course