Skip to main content
Guidance

Design and build a privately hosted Public Key Infrastructure

Principles for the design and build of in-house Public Key Infrastructure (PKI)

Page 18 of 21

9. Monitor your PKI environment

CA logs should be exported in real time to a central logging facility, to give full visibility of PKI operations.

CA logs should be exported in real time to a central logging facility, to give full visibility of PKI operations.

What to watch

Some example areas of interest for your monitoring solutions are:

  • certificates that have been generated
  • certificates that have been revoked
  • inventory of CAs in an environment
  • certificates close to expiry
  • certificates receiving revocation checks
  • failed certificate renewals
  • failed authentication request for a certificate
  • certificate authorisation failure. i.e An entity requesting a certificate which they are not authorised to have issued

This is not an exhaustive list. You may find there are certain areas that are relevant to your environment that you need to log and monitor for.

Monitoring goals

The purpose of the monitoring system is to alert you and your organisation to the following:

  • rogue CA issuing certificates that it should not be issuing
  • availability being affected by a certificate not being renewed
  • subjects requesting a certificate they are not authorised to receive
  • a certificate being revoked maliciously by allowing an administrator to audit revoked certificates when investigating an issue. This will help find out if a malicious revocation has occurred

Access to theses logs should be limited to individuals that require access. Write permission should be limited, and you should have measures in place to detect changes in the logs.

Published

Reviewed

Version

1.0