Certificate authority (CA)
A Certificate Authority issues digital certificates within a PKI, binding identities to public keys so browsers and systems can trust them.
A Certificate Authority (CA) is the organisation within a PKI that issues digital certificates: it verifies who is applying for a certificate, then signs a data structure - usually formatted as X.509 - that binds an identity to a public key. Browsers, operating systems and applications trust a certificate because they trust the CA that signed it, not because they know the certificate holder directly.
A CA sits in a hierarchy: a root CA, kept offline and heavily protected, signs one or more intermediate CAs, which in turn issue end-user or website certificates. This chain lets a relying party verify trust step by step up to a root it already holds, without the root ever having to sign certificates directly. For qualified certificates under eIDAS, the issuing CA must belong to a QTSP that has passed a conformity assessment and appears on the EU Trusted List; its practices are published in a CP/CPS.