PKI Design & Implementation

Build PKI you can trust for years.

Production-grade PKI designed around security, resilience and automation.

EJBCAOffline RootIssuing CAOCSPCRLHSM

PKI is easy to deploy. Getting it right is harder.

A certificate authority becomes critical infrastructure the moment your applications, devices, identities and services depend on it.

Poor architecture creates long-term problems: exposed keys, unreliable revocation, difficult renewals, operational dependencies and costly migrations.

We design the trust infrastructure before those problems become yours.

The approach

From trust architecture to production

Rather than dropping in a CA and walking away, we take the entire lifecycle into account.

01 · Architecture

Architecture

We define the CA hierarchy, trust model, cryptography, revocation strategy and operational boundaries before any keys are generated.

02 · Implementation

Implementation

We build the root and issuing infrastructure, integrate the required services, and establish secure key management with HSM backing.

03 · Automation

Automation

We connect issuance, renewal, deployment and revocation to the systems that depend on certificates via ACME and REST.

04 · Handover

Handover

You receive the documentation, runbooks and operational knowledge needed to run the environment confidently.

Your PKI should not become the next legacy system you have to replace. Designed for production. Built for long-term operation.

What you get

A PKI foundation your infrastructure can depend on

Secure CA architecture

Offline roots and controlled issuing infrastructure designed around your risk profile.

Reliable certificate validation

OCSP, CRL and AIA services designed for dependable certificate lifecycle operations.

Protected keys

Modern cryptography (ECDSA P-384 / SHA-512) and HSM integration where required.

Operational readiness

Automation, documentation, runbooks and a clear path into production.

Process

Five steps from architecture to operation

01

Assess

Map trust anchors, certificate profiles and consuming services.

02

Design

Define hierarchy, cryptography, revocation and operational boundaries.

03

Build

Deploy root and issuing CA with HSM-backed keys and OCSP.

04

Integrate

Wire ACME, REST, Salt and Vault into your existing systems.

05

Operate

Hand over runbooks, quarterly health checks and ongoing support.

Technology

The stack we deploy

Every component runs in our own production lab and has been validated against real workloads, not just product brochures.

Certificate Authority

EJBCARFC 5280

EJBCA cluster (active/active behind HAProxy) with MariaDB Galera. Sub-second OCSP. Stable for years.

Cryptography

ECDSA P-384SHA-512

ECDSA P-384 with SHA-512 signatures as the modern baseline. RSA only when legacy clients require it.

Hardware security

PKCS#11SoftHSM2HSM

HSM integration for tiers where keys must never be extractable. SoftHSM2 for development.

Validation authority

OCSPCRLAIA

OCSP responder co-located or peered. CRL published over HTTP per RFC 5280. AIA paths verified.

Enrolment protocols

ACMEEJBCA RESTCMPSCEP

ACME for web-server certificates, REST for service accounts, CMP/SCEP for legacy clients.

Compliance & audit

NIS2eIDASCA/B BR

Audit-ready logging, retention policy and evidence collection. NIS2 Article 21 from day one.

Ready to build PKI properly?

Starting from scratch, replacing legacy infrastructure, or strengthening an existing environment: we can help.