docs/documentation/platform/pki/ca/overview.mdx
A Certificate Authority (CA) is the entity that signs and issues X.509 certificates. Before teams can issue certificates through Applications, product admins need to configure at least one CA.
Certificate Manager supports two types of CAs:
<CardGroup cols={2}> <Card title="Private CA" icon="lock" href="/documentation/platform/pki/ca/private-ca"> **Managed by Infisical**Create root and intermediate CAs directly in Infisical. Ideal for internal services, mTLS, and private networks where public trust isn't required.
Connect to public CAs (Let's Encrypt, DigiCert) or enterprise PKI (AWS PCA, Azure ADCS, Venafi). Use existing infrastructure or issue publicly trusted certificates.
| Use Case | Recommended CA |
|---|---|
| Internal services, mTLS between microservices | Private CA |
| Public-facing websites needing browser trust | External CA (Let's Encrypt, DigiCert) |
| Enterprise with existing PKI infrastructure | External CA (AWS PCA, Azure ADCS, Venafi) |
| IoT devices, internal device fleet | Private CA |
| Regulated environments with specific CA requirements | External CA (your approved provider) |
When using Private CAs, you typically create a hierarchy:
Root CA (offline, long-lived)
└── Intermediate CA (online, issues certificates)
└── Leaf Certificates (TLS, mTLS, devices)
Infisical integrates with major public and private CA providers:
<CardGroup cols={3}> <Card title="Let's Encrypt" icon="lock" href="/documentation/platform/pki/ca/lets-encrypt"> Free, automated, publicly trusted certificates. </Card> <Card title="DigiCert" icon="shield-check" href="/documentation/platform/pki/ca/digicert"> Enterprise-grade public and private certificates. </Card> <Card title="AWS PCA" icon="aws" href="/documentation/platform/pki/ca/aws-pca"> Private CA managed in AWS. </Card> <Card title="Azure ADCS" icon="microsoft" href="/documentation/platform/pki/ca/azure-adcs"> Active Directory Certificate Services. </Card> <Card title="Venafi" icon="building" href="/documentation/platform/pki/ca/venafi"> Enterprise certificate lifecycle management. </Card> <Card title="ACME CAs" icon="robot" href="/documentation/platform/pki/ca/acme-ca"> Any ACME-compatible CA. </Card> </CardGroup>View all External CA integrations →
[Certificate Policies →](/documentation/platform/pki/settings/policies)
[Certificate Profiles →](/documentation/platform/pki/settings/profiles)