Solution Design and Delivery​

Delivery of highly assured PKI Root

Project Description

The engagement

Unsung was commissioned by a defence sector client to deliver a new highly assured Root Certificate Authority incorporating demonstrable governance processes and comprehensive documentation to underpin a new private cloud platform. The engagement required establishing a trust anchor that would meet stringent defence sector assurance requirements.

The client required not only the technical implementation of the Root CA infrastructure but also comprehensive governance documentation demonstrating compliance with security policies, industry best practices, and regulatory requirements applicable to defence sector PKI operations.

Why a root CA is different

A root certificate authority is the point at which trust originates. Everything beneath it inherits its assurance, and nothing above it provides a check. That position gives root delivery a distinct character. The technical build is comparatively modest; the assurance around it is not. What matters is that the root key was generated under controlled conditions, that those conditions were witnessed and recorded, that the key has been protected appropriately since, and that all of this can be evidenced later to a party that was not present.

Roots are also effectively permanent within their operational life. A misconfigured issuing CA can be replaced; a root that was established without adequate assurance undermines every certificate that has since chained to it, and correcting it means rebuilding the hierarchy. This is why the governance documentation was as central to the engagement as the infrastructure.

Establishing a trust anchor for a new platform

The root was to underpin a new private cloud platform, which meant it was being established at the point where the trust model could still be designed properly rather than inherited. The decisions taken at this stage, covering hierarchy structure, key protection, certificate policy and the operating model around the root, would determine what the platform could support for the remainder of its life. Getting them right at the outset is considerably less expensive than revisiting them once services depend on the outcome.

Demonstrable governance as the requirement

The client's requirement was for demonstrable governance, and the emphasis on demonstrability was the operative part. In a defence context it is not sufficient for controls to be in place; the organisation must be able to evidence to assurance and accreditation authorities that they are in place, that they were followed, and that the evidence itself is trustworthy. That shapes how the work is executed, not merely how it is documented afterwards, because evidence produced at the time carries weight that reconstruction cannot.

‍

Outcomes & Deliverables

Unsung delivered a comprehensive package of governance and technical deliverables:

Governance deliverables:

  • Certificate Policy
  • Certificate Practice Statement
  • Key Signing Ceremony documentation, facilitation, and execution

Design deliverables:

  • Technical Design (High-Level Design)

Certificate Policy

The Certificate Policy defined the standards governing certificate usage across the hierarchy: what certificates may be issued, for what purposes, under what naming conventions, at what trust levels, and what identity verification a requestor must complete. It establishes which authorities may issue for which purposes, and it is the document against which the operation of the hierarchy is subsequently assessed. Producing it at the outset, before the root existed, meant the technical implementation was built to satisfy an agreed policy rather than the policy being written to describe whatever had been built.

Certificate Practice Statement

The Certification Practice Statement documented how the policy would be implemented in this specific environment, covering certificate lifecycle procedures, key management practice, physical security controls and incident response. The distinction between policy and practice statement matters for assurance: the policy states the requirement, the practice statement demonstrates how it is met. Together they give an accreditation authority the basis to assess the service, and they give the operating team the procedures to run it consistently.

Key Signing Ceremony

Unsung documented, facilitated and executed the Key Signing Ceremony. The ceremony is the controlled event at which root key material is generated and protected, conducted under witnessed procedure with each step scripted in advance and each action recorded as it occurs. Documentation was produced before the event, defining roles, the sequence of steps, the controls at each point and the evidence to be captured. Facilitation covered the conduct of the ceremony itself, including the participants, witnesses and the physical and procedural controls in force. Execution produced the root key material and the contemporaneous record demonstrating that it was generated correctly.

That record is the artefact the organisation relies upon for the operational life of the root. Its value derives entirely from having been produced at the time, under witness, which is why the ceremony is scripted and rehearsed rather than conducted from a general understanding of what should happen.

Technical Design

The High-Level Design covered the root certificate authority architecture, its relationship to the wider hierarchy, key protection through hardware security modules, and the operational and administrative arrangements required to run the service. Design addressed how the root would be secured and accessed for the infrequent occasions on which it is used, since a root is offline for the great majority of its life and the procedures for bringing it into use are as consequential as those governing its creation.

How the deliverables work together

The four deliverables form a single assurance package rather than a set of independent documents. The Certificate Policy states what the hierarchy is permitted to do. The Certification Practice Statement describes how that is achieved in this environment. The Technical Design specifies the infrastructure implementing it. The ceremony documentation evidences that the root at the base of it all was created under the controls the other three describe. Remove any one and the package no longer demonstrates what a defence sector assurance authority requires, which is why they were produced together and in that order rather than in parallel by separate workstreams.

This sequencing also protects against a common failure in root delivery, where the infrastructure is built first and the governance documentation written afterwards to describe it. Documentation produced that way records what happened rather than governing it, and provides correspondingly weaker assurance.

Underpinning a private cloud platform

The root was delivered to serve as the trust anchor for a new private cloud platform, and the design accounted for what that platform would eventually require of it. A hierarchy established to support a single early use case tends to constrain the platform later, at which point the options are an awkward extension of the existing structure or the establishment of a second hierarchy alongside it. Neither is attractive once services depend on the original. Designing the structure of the hierarchy against the platform's expected direction, rather than against its first requirement, is a low-cost decision at the outset and an expensive one to revisit.

‍

Challenges

The engagement presented significant timeline challenges requiring efficient execution and careful programme management.

A six-week deadline to ceremony

The client required the Key Signing Ceremony within six weeks of project commencement. Unsung successfully met this challenging timeline through deployment of proven solution accelerators including governance documentation templates and ceremony procedure frameworks developed across previous defence and government sector engagements.

Six weeks is a demanding timeline for root delivery, because the ceremony cannot proceed until the policy, practice statement, technical design and ceremony procedure are all complete and agreed. The ceremony is a fixed point that everything else must precede, and it cannot be brought forward by deferring the documentation, since the documentation is what the ceremony executes against.

Accelerators rather than shortcuts

The timeline was met through proven solution accelerators: governance documentation templates and ceremony procedure frameworks developed across previous defence and government engagements. The distinction between an accelerator and a shortcut is worth drawing. The accelerators removed the effort of establishing structure from scratch, so that time was spent on the decisions specific to this client rather than on assembling a document skeleton. Every deliverable was tailored to the client's environment, policies and assurance obligations. What was reused was the structure and the procedural framework, both already tested in comparable environments.

Programme management under a fixed ceremony date

With the ceremony date fixed, careful programme management determined whether the deadline was met. Documentation, design and technical preparation had to converge on a single point, with dependencies between them managed so that no strand became the constraint. Review and approval cycles were planned into the schedule rather than assumed, since governance documentation in a defence context requires stakeholder review that cannot be compressed at short notice. Sequencing the approvals was as material to meeting the date as producing the documents.

Preparing the client to hold the root

A root certificate authority is used rarely and must be available and correctly controlled when it is. The engagement therefore had to leave the client able to hold and operate the root long after delivery closed, with documented procedures for bringing it into use, the controls governing access to it, and the evidence trail supporting its continued assurance. Delivery of a root that only the implementer understands would satisfy the immediate requirement and fail the assurance obligation that follows it for the life of the hierarchy.

Six weeks from commencement to a witnessed key signing ceremony, with policy, practice statement and technical design complete and approved beforehand, was the measure of the engagement. The date held because the dependencies between those deliverables were managed as the critical path from the outset.

‍

Technologies Used

Microsoft Windows Server, ADCS, Thales, VMware
Unsung is vendor-neutral and works across certificate authority and hardware security module platforms. Our defence and government consultants bring extensive experience of high-assurance environments, with many holding SC and DV clearance.

Related Services