SPKI/SDSI is a distributed access control mechanism in which the policy statements for resource access are issued by multiple principals. A set of SPKI/SDSI policy statements forms a state of system. Many important properties of such states need to be known and analyzed. Unlike other trust management language, SPKI/SDSI certificate structure is rather complex. In this paper, a first-order logic semantics is presented. The soundness of the semantics is proved. Using this semantics we can check if a given SPKI/SDSI state satisfies some given policy question.