Solution Design and Delivery​

Issuing CA Expiry

Project Description

The engagement

Unsung was engaged to execute the replacement of an Issuing CA certificate and coordinate the re-issuance of all 15,000 end entity certificates deployed across the enterprise, maintaining zero business or operational impact. This engagement was necessitated by the underlying technology stack reaching end-of-life.

The client established a new hosting platform to support a replacement Issuing CA. However, the migration itself presented substantial complexity given the scale of certificate deployment, the diversity of certificate consumers, and the critical nature of many certificate-dependent services.

Where the complexity actually sits

Replacing an issuing certificate authority is a well-understood technical exercise. Re-issuing fifteen thousand end entity certificates across a live enterprise without disrupting a single service is not. The certificates in question sit inside applications, on devices, in configuration files and within integrations, many of them installed by teams that have since moved on and documented nowhere. Each one has to be replaced in the right place, in the right format, at a time its owning service can accommodate.

The client had already provisioned the new hosting platform, so the engagement was not primarily an infrastructure exercise. It was a coordination exercise conducted against a fixed expiry date, across a consumer base whose full extent was not initially known.

The visibility problem

The first practical difficulty in a migration of this scale is establishing what actually needs to move. Certificate inventories in large enterprises are rarely complete, because certificates are requested continuously by many teams over many years and the record of what was issued to whom degrades steadily. Working from an incomplete inventory means discovering the remainder during the migration, and in this context that means discovering them when they fail.

Establishing an accurate picture of the estate was therefore the necessary first step, and it determined how the rest of the engagement could be planned.

‍

Outcomes & Deliverables

Unsung successfully executed a complex, large-scale certificate migration whilst maintaining operational continuity.

Unsung conducted detailed analysis of Certificate Signing Requests submitted over the previous 12 months, providing comprehensive understanding of certificate usage patterns. The team collaborated closely with the client to define a risk-based migration strategy.

Comprehensive business communications were developed and deployed, with additional support resources mobilised throughout the migration period to respond promptly to incidents and ensure service continuity.

Discovery through CSR analysis

Rather than relying on an inventory that could not be assumed complete, we analysed twelve months of Certificate Signing Requests submitted to the existing service. This produced an evidence-based picture of the estate: which teams were requesting certificates, at what volume, for what purposes, with what profiles and attributes, and at what points in the year. Request data reflects what the organisation actually did rather than what its records say it did, which makes it a considerably more reliable basis for migration planning.

The twelve-month window was chosen deliberately, since it captures a full cycle of periodic and seasonal activity that a shorter sample would miss. The analysis identified certificate consumers who would otherwise have been discovered only at the point of failure, and it established the usage patterns on which the migration strategy was then built.

A risk-based migration strategy

Working closely with the client, the CSR analysis was translated into a migration strategy sequenced by risk and service criticality rather than by convenience. Lower-risk consumers moved first, proving the procedure while there was time to refine it. Business-critical services moved once the process was established and support demonstrably effective. Certificates approaching expiry independently were prioritised, so that the migration and the natural renewal cycle worked together rather than against one another.

Collaboration with the client was essential to this. Unsung could establish from the data what was being issued and how; only the client could confirm what each certificate supported in business terms and what disruption each service could tolerate. The strategy was a product of both.

Business communications

Comprehensive business communications were developed and deployed across the affected consumer base. With fifteen thousand certificates spread across many teams, communication was not an adjunct to the migration but a core delivery mechanism: the majority of certificate owners had to understand what was required of them, by when, and what to do if something did not work. Communications were targeted to consumer groups and timed against their migration windows, so that teams received relevant instruction at the point they needed to act rather than general notice well in advance of it.

Support and incident response

Additional support resources were mobilised throughout the migration period to respond promptly to incidents and ensure service continuity. Given the diversity of certificate consumers, support had to cover a wide range of platforms and integration patterns, and had to be available throughout rather than at defined checkpoints. Rapid response was the mechanism that protected the zero-impact requirement: in a migration of this scale isolated problems are inevitable, and what determines whether they become service-affecting is how quickly they are resolved.

Maintaining continuity at scale

Operational continuity was maintained across the full migration. That outcome rested on the sequence of decisions behind it: an evidence-based understanding of the estate from CSR analysis, sequencing by risk rather than convenience, communications timed to each consumer group, and support resourced to respond within the window in which a problem remains contained.

Working with an established target platform

The client had already established the new hosting platform for the replacement issuing CA, which shaped the engagement. Unsung's scope concentrated on validating that the platform would support the certificate profiles and issuance patterns identified through CSR analysis, configuring the certificate authority accordingly, and executing the migration onto it. Where an organisation has already invested in a target platform, the useful contribution is rarely to reopen that decision. It is to establish whether the platform will support what the estate actually requires, and to surface any gap early enough that it can be addressed within the available timeline.

‍

Challenges

Nuanced and varied certificate requirements

A diverse range of nuanced certificate requirements was identified across various end entity certificate consumers. Certificates that appear equivalent in an inventory frequently are not, differing in profile, key usage, naming, format or the manner in which the consuming system expects them to be presented. Each variation represents a potential migration failure if handled generically. The CSR analysis was what surfaced these variations in advance, allowing them to be accommodated in planning rather than encountered during execution.

Decision delays against a fixed deadline

Customer decision-making delays, combined with a fixed certificate expiry deadline, required implementation of tactical measures to maintain operational continuity.

These tactical measures included accelerated testing cycles, prioritised migration of certificates approaching expiry, and deployment of additional support resources to enable parallel migration activities.

This is a common and difficult dynamic. The deadline does not move, but the decisions required to meet it sit with stakeholders managing competing priorities. The response was to protect the critical path: compressing testing where it could be compressed safely, prioritising the certificates whose own expiry made them most urgent, and adding capacity so that migration activities could proceed in parallel rather than in sequence. Each measure bought time against the fixed date without compromising the zero-impact requirement.

Scale as a risk multiplier

Fifteen thousand certificates change the character of the risk. A procedure with a small failure rate produces a manageable number of exceptions at a scale of hundreds and an unmanageable number at a scale of thousands. Cohorting, prioritisation and dedicated support capacity were the controls that kept the exception volume within what the support model could absorb, which is what allowed continuity to be maintained across the whole estate rather than most of it.

Why an evidence-led approach mattered here

The alternative to CSR analysis would have been to migrate from the existing certificate inventory and handle the shortfall reactively. On an estate of fifteen thousand certificates that approach fails predictably, because the certificates missing from an inventory are disproportionately the ones nobody is actively managing, and therefore disproportionately the ones whose failure will be noticed only by the service that depends on them. Building the migration plan on request data rather than inventory records is what kept the exception volume within what the support model could absorb.

Coordination as the core discipline

The engagement is best understood as a coordination exercise carried out under a fixed deadline. The certificate authority replacement was bounded and predictable. The re-issuance of fifteen thousand certificates across many teams, platforms and change regimes was neither, and it was where the risk to operational continuity sat almost entirely.

Coordination at that scale depends on knowing the estate, sequencing the work against real business risk, telling each consumer what they need to know at the moment they need to know it, and having capacity available when something does not behave as expected. Each of those was addressed deliberately: the CSR analysis established the estate, the risk-based strategy set the sequence, targeted communications carried the instruction, and mobilised support absorbed the exceptions. Removing any one of them would have left the others insufficient.

It is also worth noting what the fixed deadline removed from the available options. There was no possibility of pausing to let a stalled decision resolve itself, and no scope to extend the schedule to accommodate a consumer group that proved more complex than expected. Every response had to work within the date, which is why tactical measures such as accelerated testing and parallel migration activity were introduced rather than simply requesting more time.

‍

Technologies Used

Keyfactor EJBCA, Thales Key Protection, VMware, Dell, Cisco
Unsung is vendor-neutral. The new hosting platform and certificate authority reflected the client's existing standards and strategic direction; our role was to design and execute the migration onto it without operational impact.

Related Services

This migration is one of the CA replacement paths explored in our guide to Active Directory Certificate Services in modern IT, which covers supplementation with CLM, full CA replacement, and hybrid approaches for organisations evaluating their options.

Learn more about our PKI design and build, certificate lifecycle management.