This document discusses certificates in Puppet and provides an overview of certificate management. It begins with an introduction to public key infrastructure (PKI) and the X.509 standard used by Puppet. It then covers Puppet certificate structures, filenames, and the REST API. The document also discusses setting up distributed Puppet environments with multiple certificate authorities and replacing a Puppet CA. It emphasizes the importance of security practices and guidelines for certificate lifecycle management.