EXPLORE RESOURCES

PKI Articles

31 Articles

Certificate Transparency Logs: What Developers Need to Know

Certificate Transparency is one of those pieces of internet infrastructure that quietly runs in the background, doing important work most developers never directly interact with, until the day it directly affects them, whether through a surprise notification about an unexpected certificate or a debugging session trying to understand why a browser is behaving unexpectedly. This article covers what developers actually need to know about how Certificate Transparency logs work and why they matter.

Multi-Domain (SAN) Certificates for Modern Web Architectures

Modern applications rarely live on a single domain anymore. A typical product might span a main website, a separate API domain, a customer portal, and several regional or brand variations, each needing certificate coverage. Multi-domain certificates, built around the Subject Alternative Name extension, exist specifically to handle this reality cleanly. This article covers how they work and where they fit into modern web architecture.

Self-Signed Certificates: When to Use Them and When to Avoid

Self-signed certificates get a bad reputation, and often deservedly so, but the reputation is more nuanced than a blanket rule of never using them. This article covers exactly what a self-signed certificate is, the genuine situations where it makes sense, and the situations where reaching for one is a mistake waiting to surface.

What Makes a Certificate Trusted? The Chain of Trust Explained

A certificate can be cryptographically perfect, correctly signed, properly formatted, and still be worthless if nothing trusts the entity that signed it. Trust in the certificate world is not an inherent property of a certificate; it is inherited, link by link, through a structure called the chain of trust. This article explains exactly how that chain works and what actually makes a certificate trusted.

Certificate Inclusion in CI/CD Pipelines: Best Practices

Continuous integration and continuous deployment pipelines have become the place where a huge share of an organization\’s software, infrastructure, and increasingly AI-driven services gets built and shipped. Certificates need to move through these pipelines securely and reliably, without becoming either a security liability or a deployment bottleneck. This article covers the best practices for handling certificates well inside CI/CD workflows.

Integrating Certificates in Node.js Applications

Node.js powers a huge share of modern web backends, APIs, and increasingly the orchestration layers behind AI-driven services, which makes handling certificates correctly inside a Node.js application a genuinely common and consequential task. This article covers the practical patterns for working with certificates across Node.js applications, from serving HTTPS traffic to authenticating outbound requests.

Passwordless Authentication: Using Certificates Instead of Passwords

Passwords have been the default authentication method for decades, and they have also been a persistent source of breaches, phishing losses, and help desk tickets for exactly as long. Certificate-based authentication offers a genuinely different approach: instead of proving identity with something memorized, an entity proves identity with something cryptographically possessed. This article looks at how certificate-based passwordless authentication actually works and why organizations are increasingly adopting it.

When and Why You Should Revoke a Certificate

Revocation is the emergency brake of the certificate world, and like any emergency brake, its value depends entirely on people knowing when to actually pull it. Too hesitant, and a compromised certificate stays trusted far longer than it should. Too trigger-happy, and legitimate services get disrupted unnecessarily. This article covers the situations that genuinely call for revocation, and the reasoning behind each one.

OCSP vs CRL: Modern Certificate Revocation Methods

Every PKI eventually has to answer the same operational question: when a client needs to know whether a certificate has been revoked, how does it find out, quickly, reliably, and without unnecessary overhead? Certificate Revocation Lists, covered in depth elsewhere in this series, were the original answer. The Online Certificate Status Protocol, OCSP, emerged as a more real-time alternative. This article compares the two directly and looks at where each fits in a modern PKI.

Certificate Revocation Lists (CRLs): What They Are and How They Work

Issuing a certificate is only half of the trust equation. The other half is being able to un-trust it before its natural expiration, if something goes wrong. Certificate Revocation Lists are one of the two primary mechanisms, alongside OCSP covered elsewhere in this series, that make revocation actually enforceable rather than merely theoretical. This article explains what a CRL is, how it works, and where it still fits into a modern PKI.

Machine Certificates: Authenticating Servers, Scripts, and AI Agents

Every certificate discussion eventually runs into the same reality: the population of things needing an identity is no longer dominated by people. Servers, scripts, service accounts, containers, and increasingly AI agents now vastly outnumber human users on most corporate networks, and each one needs a way to prove who it is before it is trusted with anything. This article looks at machine certificates specifically, the credentials that authenticate non-human entities, and what makes managing them different from managing certificates for a public website.

How Digital Certificates Actually Work: The Cryptography Behind Them

Certificates get discussed constantly in terms of what they do: encrypt traffic, prove identity, unlock the padlock icon. Far less often does anyone explain the actual mathematics making any of that possible. This article opens the hood on the cryptography behind digital certificates, translated into terms that do not require a mathematics degree to follow.

Certificate 201: Intermediate Concepts in PKI Management

Understanding what a certificate is and how to get one issued covers the fundamentals, but running a PKI program well requires a second layer of knowledge that only becomes relevant once an organization has more than a handful of certificates to manage. This article picks up where the basics leave off, covering the intermediate concepts that separate a functioning PKI from a well-governed one.

How Public Key Infrastructure Secures Modern Networks

Modern networks move an almost unimaginable volume of traffic every second, much of it invisible to the people relying on it. Underneath that traffic sits a quiet assumption: that the server on the other end is who it claims to be, and that nobody in the middle can read or alter what is being sent. Public Key Infrastructure is what makes that assumption safe to make. This article looks at exactly how PKI secures modern networks, from the classic web browsing case to the newer world of AI-driven network activity.

What Is PKI and Why Every Organization Needs It

Public Key Infrastructure, almost universally shortened to PKI, is one of those terms that gets used constantly in security circles and rarely explained plainly. Ask ten IT professionals to define it in one sentence and you will likely get ten different answers, each technically correct and each missing part of the picture. This article gives PKI the plain-language explanation it deserves, and makes the case for why no organization, regardless of size or industry, can safely operate without it today.