Summary
They are used to identify and authenticate clients and gateways at the point when encrypted connections are established. This guidance helps architects, designers and engineers to make appropriate choices when obtaining and managing certificates to authenticate their online services to users. This guidance focuses on server authentication rather than client authentication. Most use cases for client authentication are better served with a privately hosted Public Key Infrastructure (PKI), which the NCSC address in separate guidance. In the Web Public Key Infrastructure (Web PKI), certificates are used to demonstrate ownership of a domain or service to the end user.