What Is PKI?
PKI (Public Key Infrastructure) is a framework of trust consisting of digital certificates, certificate authorities (CAs), and cryptographic key pairs. Its core purpose is to enable two parties to authenticate each other and encrypt the communication between them.
The asymmetric cryptography on which PKI is built works as follows: every entity (server, user, or application) holds a key pair — a public key and a private key. The public key can be shared with anyone; the private key is held exclusively by its owner and must never be shared.
What Are SSL and TLS?
SSL (Secure Sockets Layer) and its successor TLS (Transport Layer Security) are protocols that encrypt network communications. Although SSL is technically obsolete today, the term "SSL certificate" remains in widespread use; in practice, these certificates operate with the TLS protocol.
The padlock icon and "https://" prefix in your browser's address bar indicate that the connection between the server and the browser is encrypted with TLS.
How Does a Digital Certificate Work?
- A web server sends a Certificate Signing Request (CSR) to a certificate authority (CA).
- The CA verifies the server's identity and signs the digital certificate.
- When a browser connects to the server, it receives the certificate.
- The browser verifies that the certificate was signed by a trusted CA.
- The TLS handshake completes and encrypted communication begins.
Certificate Types
DV (Domain Validation)
Only domain name ownership is verified. Suitable for basic websites; contains no organizational information.
OV (Organization Validation)
Both the domain name and the organization's identity are verified. The company name appears in the certificate; this is the recommended level for corporate websites.
EV (Extended Validation)
The most comprehensive validation process. Used in environments requiring a high level of trust, such as banks and financial institutions.
Wildcard Certificates
Issued in the format *.organization.com; these certificates cover all subdomains of a parent domain. They simplify management for organizations that use a large number of subdomains.
SAN (Subject Alternative Name) Certificates
Structures that cover multiple different domain names within a single certificate.
Enterprise PKI Infrastructure
Large organizations can build their own internal PKI (Private CA). In this setup:
- Root CA: Sits at the top of the certificate chain; typically kept offline.
- Intermediate CA: Signs certificates for end entities; operates online.
- End-Entity Certificates: Issued for servers, users, and applications.
Internal PKI is used for VPN clients, Wi-Fi authentication (802.1X), email signing, and code signing, among other areas.
The Critical Importance of Certificate Management
When certificates expire, service outages occur. Large organizations may need to manage hundreds or even thousands of certificates. An uncontrolled certificate inventory leads to unexpected expirations, weak encryption algorithms, and trust chain errors.
Certificate Lifecycle Management (CLM) tools automate this process:
- Centralized inventory of all certificates
- Automatic alerts based on expiration dates
- Automatic renewal and deployment
- Compliance reporting
Common Issues
| Issue | Consequence |
|---|---|
| Expired certificate | Website/service inaccessible, user warnings |
| Weak encryption (SHA-1, 1024-bit RSA) | Security vulnerability and browser warning |
| Private key compromise | All encrypted communications are at risk |
| Misconfiguration | Missing intermediate CA, certificate chain errors |
| Wildcard certificate over-sharing | Single point of failure risk |
KVKK and Regulatory Compliance
Under KVKK, the use of secure communication channels for the transfer of personal data is mandatory. TLS encryption and valid certificates are the technical fulfillment of this requirement. Certificate requirements for integrations with e-Government and public institutions are formally defined.
Conclusion
PKI and SSL/TLS certificate management form the foundation of corporate digital trust. An uncontrolled certificate inventory creates the conditions for critical service outages and security vulnerabilities. As NRC Sistem, we analyze your organization's certificate inventory and help you manage the certificate lifecycle end-to-end through internal PKI design and the integration of CLM tools.