Training
PKI and electronic signature training
Four days to understand how a PKI protects information and transactions, and how one is deployed in practice: cryptography, certification authorities, HSMs, electronic signature, visible stamp. A fifth day visiting our PKI infrastructure in a data centre.
- Duration
- 4 days of training + 1 visit day
- Participants
- 12 people at most per session
- Format
- Theory and practice, equipment provided
- Certificate
- Named training certificate
On the programme
Cryptography
The basics, and how they secure the confidentiality, integrity, authenticity and non-repudiation of data.
- Hash functions and asymmetric cryptography
- Key and certificate management
- The algorithms implemented in a PKI
- Challenges ahead, including post-quantum cryptography
Public key infrastructure
How certificates are issued, verified and revoked to establish the identity of the parties to a transaction.
- Certification, registration and timestamping authorities
- HSMs and PKCS#11 tokens: administration and development
- Generating CA and end-entity certificates with OpenSSL
- Parsing and validation: certificates, CRLs, OCSP
Trust services
The concrete applications: electronic signature, strong authentication, visible electronic stamp.
- Electronic signature and validation of signed documents
- Visible electronic stamp: demonstrations
- How a PKI is deployed in practice
- Visit of a PKI infrastructure in production
By the end of the training, you will be able to
- Explain the cryptographic algorithms that a PKI puts to work
- Place the actors of a PKI: certification, registration and timestamping authorities
- Describe the main trust services that are built on a PKI
- Administer and program cryptographic devices: HSMs, PKCS#11 tokens
- Generate authority and end-entity certificates with OpenSSL
- Parse and validate the signed objects of a PKI: certificates, CRLs, OCSP responses
- Understand and validate signed documents
Practical details
- Prerequisites
- A good working knowledge of operating systems, networks and IT security.
- Format
- Theory and practice. Course material supplied, equipment provided for the hands-on sessions.
- Included
- Training material, the visit to the PKI data centre (Tier IV), two networking dinners.
- Seats
- Twelve people at most per session. A 10% discount for the second person, and 15% from the third person on.
Tailored training and skills transfer
Every deployment of Remote Trust PKI, NGSIGN or QRSecure ends with training the teams who will run it, through to their full autonomy. We also run PKI and electronic signature awareness workshops for national agencies, bringing together the IT decision-makers of a country’s public and private organisations.
| Audience | Content | Deliverables |
|---|---|---|
| PKI administrators | Installation, authority configuration, HSM management, key ceremony, backup and recovery | Operations manual, administration procedures |
| Registration operators | Processing requests, identity verification, approval, revocation, AED management | Operator guide, file templates |
| Developers | API integration, signing, validation, visible stamp generation | API reference, examples, test environment |
| Auditors and managers | Reading the logs, compliance checks, indicators and reports | Audit guide, dashboards |
Book your seat at the next session
Tell us how many people you are enrolling and their starting level. We confirm the dates, the venue and the terms.