Skip to main content
Guidance

Design and build a privately hosted Public Key Infrastructure

Principles for the design and build of in-house Public Key Infrastructure (PKI)

Page 17 of 21

8. Enable frictionless and automated certificate renewal, without impacting security

Automated certificate renewal will support the use of short certificate lifetimes and reduce the risk of certificates unexpectedly expiring

You should use automated certificate renewal as this will support the use of short certificate lifetimes and reduce the risk of certificates unexpectedly expiring.

Automated certificate renewals will reduce the administrative overhead of renewing certificates on a regular basis. However, any automated certificate requests should be authenticated and authorised by the CA. All communications between the CA and the requester should be transmitted over a secure transport.

When to renew

When to renew a certificate will be a function of the required security, certificate validity period and availability requirements.

An "overlap period" is recommended, allowing a suitable amount of time for a failed certificate request to be investigated by a support team. There is a trade off between early and later renewal. Early renewal is good for resilience, but can put more pressure on the PKI. Later renewal, is more risky when it comes to availability, but will put less pressure on the overall PKI.

There is a balance to be struck between availability and the capacity of the PKI to handle the resulting volume of certificate requests.

Logging

Certificates nearing their expiry date, or failing to renew should be logged and alerted. This will enable you to investigate before an availability issue occurs.

This alert should be forwarded to a central monitoring facility and the end entity should also receive the alert, in case action needs to be taken locally.

Published

Reviewed

Version

1.0