Guidance
Design and build a privately hosted Public Key Infrastructure
Principles for the design and build of in-house Public Key Infrastructure (PKI)
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 12 of 21
Highly available Certificate Authorities refer to online intermediate CAs, not Root CAs, which are kept offline and unavailable for use. See principle 10 for more detail on root CAs.
An intermediate certificate authority (CA) acts as a trusted component within a PKI, performing such critical functions as certificate issuing, renewal, and revocation. Failure or unavailability of these functions would cause disruption, so you should design your CA and its supporting components to be highly available.
Clustering should be used to prevent the failure of one system component bringing down the whole PKI.
Backup and restore
Consider a back up and restore plan for your CA in the case of failure, this is especially important if distributing a new CA certificate to end entities is difficult.
The backup should include the state (authentication, revocation, registration database etc.) and the private key. See principle 10.
Backing up private keys
Secure handling of private keys is an important part of the backup process. Do not store private keys unencrypted. Here are some example methods that could be used:
There should be a clearly defined restore process for the whole PKI environment. This should be exercised on a regular basis.


