Guidance
Design and build a privately hosted Public Key Infrastructure
Principles for the design and build of in-house Public Key Infrastructure (PKI)
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 17 of 21
You should use automated certificate renewal as this will support the use of short certificate lifetimes and reduce the risk of certificates unexpectedly expiring.
Automated certificate renewals will reduce the administrative overhead of renewing certificates on a regular basis. However, any automated certificate requests should be authenticated and authorised by the CA. All communications between the CA and the requester should be transmitted over a secure transport.
When to renew
When to renew a certificate will be a function of the required security, certificate validity period and availability requirements.
An "overlap period" is recommended, allowing a suitable amount of time for a failed certificate request to be investigated by a support team. There is a trade off between early and later renewal. Early renewal is good for resilience, but can put more pressure on the PKI. Later renewal, is more risky when it comes to availability, but will put less pressure on the overall PKI.
There is a balance to be struck between availability and the capacity of the PKI to handle the resulting volume of certificate requests.
Logging
Certificates nearing their expiry date, or failing to renew should be logged and alerted. This will enable you to investigate before an availability issue occurs.
This alert should be forwarded to a central monitoring facility and the end entity should also receive the alert, in case action needs to be taken locally.


