Skip to main content
Guidance

Design and build a privately hosted Public Key Infrastructure

Principles for the design and build of in-house Public Key Infrastructure (PKI)

Page 10 of 21

1. Understand what you are building

Before designing a private PKI solution, you should have a clear picture of what you are trying to build.
  1. The PKI use case and the functions it enables
  2. Parties involved, i.e organisations and teams, as well as any delegated third parties
  3. What is being authenticated and verified i.e. users, hardware devices or services
  4. Security value of the assets using the PKI. Are you protecting a high value or low value asset? The answer to this question will determine "how secure" you will make your PKI and what security components you require with in the architecture. You want to make sure your PKI design is secure enough for your needs.
  5. Availability requirements

If possible, it would be helpful to understand the authentication or verification flows that the private PKI is required to support. An example could be a user to a web service or a device to a VPN end point our Authentication policy guidance can help understand different types of authentication.

Published

Reviewed

Version

1.0