The structure and service of Windows 2000 PKI, and the architecture of public key application service are discussed. Certificate services, the certificate hierarchical model of certificate authority and the attributes of certificate database are analyzed.