StudyToCert

All certifications / SecurityX / Lessons

CompTIA SecurityX CAS-005 · Domain 3: Security engineering

PKI engineering: certificate lifecycle, CA hierarchy, OCSP and CRLs, certificate pinning and mutual TLS

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Public key infrastructure (PKI) binds public keys to identities through certificates issued by certificate authorities (CAs). Senior engineers design the hierarchy, automate the lifecycle and troubleshoot trust failures. Outages from expired certificates are among the most common and avoidable incidents in IT.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SecurityX for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SecurityX study plan