This week's book giveaway is in the OCAJP 8 forum. We're giving away four copies of OCA Java SE 8 Programmer I Study Guide and have Edward Finegan & Robert Liguori on-line! See this thread for details.

PKI refers to a set of security services for authentication, encryption and digital certificate management under which documents are encrypted with a private key and decrypted using a publicly available key accessible to the recipient via a network.

Shouldn't it be reverse like "...encrypted with a public key and decrypted using private key..."?

Hi!
As far as I understand, you can encrypt data using either the public or private key, as long as you use the other, that is the private or public key, to decrypt the data.
The most common case is encryption using the public key, which is freely distributed. The encrypted data can then only be decrypted by the party that holds the private key, which is supposed to be a well-kept secret.
With signing of data only one party is supposed to be able to produce a signature of some data while anyone is supposed to verify from where the signature came. Thus, the private key is used to sign the data and the public key can then be used to verify the signature.
Best wishes!

The two main branches of public key cryptography are:

Public key encryption: ...

Digital signatures: a message signed with a sender's private key can be verified by anyone who has access to the sender's public key, thereby proving that the sender had access to the private key (and therefore is likely to be the person associated with the public key used), and the part of the message that has not been tampered with. On the question of authenticity, see also message digest.

Regards,
Dan

William Butler Yeats: All life is a preparation for something that probably will never happen. Unless you make it happen.