Guidance
Design and build a privately hosted Public Key Infrastructure
Principles for the design and build of in-house Public Key Infrastructure (PKI)
Pages
Page 9 of 21
The PKI principles
12 principles for the design and build of in-house public key infrastructure (PKI)
- 1. Understand what you are building Before designing a private PKI solution, you should have a clear picture of what you are trying to build.
- 2. Protect your private keys Securing your private keys will reduce the likelihood of compromise.
- 3. Certificates Authorities should be highly available and resilient to both attack and failure Failure or unavailability of Certificate Authority functions would cause disruption, so you should design your CA and its supporting components to be highly available.
- 4. Develop a robust certificate registration procedure A failure of the registration system could lead to fraudulently issued (or 'mis-issued') certificates
- 5. Authenticate and authorise requests to Certificate Authorities A certificate authority must have sufficient confidence in the requester and approver
- 6. Keep certificate lifetimes as short as practical Short certificate lifetimes reduce the window of opportunity for an attacker
- 7. Use a separate intermediate CA per technology or organisation function
Separating Certificate Authorities in this way will reduce the impact of compromise of a single CA and provide a separation of duty between each CA.
- 8. Enable frictionless and automated certificate renewal, without impacting security Automated certificate renewal will support the use of short certificate lifetimes and reduce the risk of certificates unexpectedly expiring
- 9. Monitor your PKI environment CA logs should be exported in real time to a central logging facility, to give full visibility of PKI operations.
- 10. Keep the root CA offline and be unavailable for use
If the root CA were to be compromised, an attacker could gain control of the entire PKI and compromise trust in the entire system, including any sub-systems reliant on the PKI.
- 11. Use current, strong, cryptographic algorithms and plan for new ones
The minimum cryptographic profiles used in your PKI should be in line with current recommended guidelines.
- 12. Use certificate revocation
Using certificate revocation will reduce the impact of a compromised certificate.