# Public-Key Infrastructure
Public-key infrastructure (PKI) is the system of certificate authorities, certificates, keys, validation rules, identities, and revocation mechanisms used to establish cryptographic trust.
## Notebook evidence
PDF page 12 of [[Scanned_20260730-1845]] groups CAC, ECA, and PIV. Pages 18–19 add Verisign, OpenID, Okta, SMS authentication, NS1, DNS apex, Let's Encrypt, ISRG Root X1, PKCS #1, and RSA. The notebook is tracing the invisible trust fabric beneath visible accounts and websites.
## Correction and boundary
The phrase `PKCS#1 256 RSA` likely compresses distinct ideas: RSA keys are normally much larger than 256 bits, while 256 more plausibly refers to SHA-256 in a signature suite. The exact notebook phrase remains preserved. Listing a certificate system does not establish that a certificate was issued, trusted, compromised, or used by a named account.
## Relationships
[[Common Access Card]] · [[Personal Identity Verification]] · [[Domain Name System]] · [[Digital Identity]]
## Source
- [[Scanned_20260730-1845]], PDF pages 12 and 18–19.