PKI for Infra Professionals
Build, operate, troubleshoot, and automate certificate infra in 2 days
Duration: 2 Days
Format: Instructor-led Training or Virtual Instructor-led Training
Audience: Linux system administrators, DevOps engineers, SREs, security engineers, infrastructure engineers, and technical leads
Certificate infrastructure has become more operational than academic. Shorter public TLS certificate lifecycles, growing automation expectations, internal service encryption, Linux trust-store management, SSH certificate use, and private CA platforms all make PKI a daily production concern rather than a background security topic.
The CA/Browser Forum has moved toward reduced public TLS certificate validity periods, making certificate lifecycle automation increasingly important. OpenSSL 3.5 is now an LTS release line, keeping OpenSSL central to Linux-based certificate operations. Modern private CA tools such as step-ca also support automated X.509 and SSH certificate management, which reflects where infrastructure teams are heading.
This course is designed for professionals. The instructor brings over 30 years of industry experience and will use real industry-demanded content instead of presenting PKI as a purely academic subject.
Learning Outcomes
By the end of this course, participants will be able to:
- Explain core PKI concepts, certificate chains, trust anchors, revocation, and certificate lifecycle risks.
- Build and operate a Linux-based private CA for internal infrastructure use.
- Use OpenSSL and Linux command-line tools to generate, inspect, validate, issue, and troubleshoot certificates.
- Configure Linux trust stores and validate certificate trust across common services.
- Deploy TLS certificates for Linux-based web and application services.
- Understand CRL, OCSP, ACME, SCEP, and automated certificate enrollment concepts.
- Troubleshoot certificate chain, hostname, expiration, trust-store, and revocation-related issues.
- Validate interoperability with one Windows client scenario.
Prerequisites
- Working knowledge of Linux administration
- Basic understanding of TCP/IP networking
- Familiarity with SSH and command-line operations
- Basic understanding of web servers or application services
- Some exposure to TLS, HTTPS, or certificates is helpful but not mandatory
Training Outline
- Public Key Infrastructure Fundamentals for Linux Professionals
- PKI purpose and enterprise use cases
- Confidentiality, integrity, authentication, and non-repudiation
- Public key and private key concepts
- Symmetric and asymmetric cryptography
- Hashing and message integrity
- Digital signatures
- X.509 certificates
- Certificate authorities
- Root CAs and intermediate CAs
- Certificate chains
- Trust anchors
- Public CA versus private CA
- Internal PKI versus public Web PKI
- Certificate policies and operational governance
- Linux PKI Tooling and Environment Preparation
- Linux lab architecture
- OpenSSL installation and version validation
- Certificate utility tools
- Linux directory structure for PKI operations
- Secure key storage locations
- File permissions and ownership
- Randomness and entropy considerations
- Command-line certificate inspection
- PEM, DER, CRT, CER, KEY, CSR, P12, and PFX formats
- Certificate conversion workflows
- Building a Linux-Based Certificate Authority
- Root CA design
- Offline root CA considerations
- Intermediate issuing CA design
- CA private key generation
- CA certificate creation
- OpenSSL CA configuration
- Certificate serial number management
- CA database structure
- Certificate signing workflows
- Certificate validity planning
- Certificate extensions
- Basic constraints
- Key usage
- Extended key usage
- Subject Alternative Name handling
- CA backup and protection considerations
- Certificate Request and Issuance Workflows
- Private key generation
- Certificate signing request creation
- CSR fields and subject naming
- SAN-based certificate requests
- Server certificate issuance
- Client certificate issuance
- Service certificate issuance
- Wildcard certificate considerations
- Internal naming considerations
- Certificate renewal workflow
- Certificate replacement workflow
- Certificate retirement workflow
- Linux Trust Store Management
- Linux system trust model
- Red Hat-based trust store management
- Debian and Ubuntu trust store management
- Application-specific trust stores
- Browser trust considerations
- Java trust store considerations
- Container image trust considerations
- Adding internal root CAs
- Removing untrusted CAs
- Trust validation with command-line tools
- Cross-platform trust considerations
- TLS Deployment on Linux Services
- TLS certificate requirements
- NGINX certificate configuration
- Apache HTTP Server certificate configuration
- HAProxy certificate configuration
- System service certificate placement
- Private key permissions
- Certificate chain configuration
- Full-chain certificate files
- TLS protocol selection
- Cipher suite considerations
- Certificate reload versus service restart
- Service validation with OpenSSL and curl
- Certificate Validation, Revocation, and Status Checking
- Chain building
- Path validation
- Expiration checking
- Hostname validation
- Trust anchor validation
- Certificate Revocation List concepts
- Base CRL concepts
- Delta CRL concepts
- CRL distribution points
- OCSP concepts
- OCSP responder role
- OCSP stapling concepts
- Revocation limitations
- Practical revocation validation
- Automation and Modern PKI Operations
- Certificate lifecycle automation
- ACME protocol concepts
- Private ACME services
- SCEP concepts
- Automated enrollment design
- Short-lived certificate strategy
- SSH certificate concepts
- Machine identity management
- Service identity management
- Certificate inventory
- Expiration monitoring
- Renewal alerting
- GitOps and infrastructure automation considerations
- Secrets management integration considerations
- Troubleshooting PKI and TLS Issues on Linux
- Expired certificate errors
- Missing intermediate certificate errors
- Incorrect certificate chain errors
- Hostname mismatch errors
- Untrusted root errors
- Private key mismatch errors
- Permission-related certificate failures
- TLS handshake failures
- Application trust-store failures
- OpenSSL troubleshooting commands
- curl troubleshooting commands
- journalctl and service log review
- tcpdump and packet capture basics
- Common operational mistakes
- Cross-Platform Client Trust Validation
- Linux client validation
- Windows client trust-store import
- Browser-based certificate validation
- Internal CA trust verification
- HTTPS service validation from Windows
- Certificate chain viewing on Windows
- Common Windows client trust issues
- Linux-to-Windows interoperability considerations
- PKI Operational Best Practices
- CA hierarchy design
- Separation of root and issuing CA roles
- Key protection practices
- Certificate naming standards
- Validity period standards
- Renewal window planning
- Revocation planning
- Audit and logging considerations
- Documentation requirements
- Change control considerations
- Incident response for CA or key compromise
- Production readiness checklist
Disclaimer
This training outline is provided as a professional guideline for course planning and delivery. The trainer may modify, reorder, expand, reduce, or otherwise amend the topics, labs, and delivery approach at their discretion based on participant skill level, organizational requirements, technical constraints, time availability, and instructional judgment, without prior notice.
Practical, connected learning
My wider training approach brings hands-on implementation and systems thinking together, connecting technology with real operational needs.