PKI Health Check

PKI Health Check (Engineering)

Project Description

The engagement

Unsung was engaged by an engineering sector organisation to conduct a comprehensive assessment of a PKI implementation delivered by a third-party organisation. The health check was commissioned following significant concerns regarding absent documentation, lack of demonstrable compliance, and resulting erosion of confidence in the digital trust assured by the PKI service.

These concerns were creating substantial organisational impact including reluctance to adopt the PKI service for new use cases, compliance concerns, and operational risk from inability to support the infrastructure effectively.

When a working platform still cannot be trusted

The distinction that mattered here was between a PKI that functions and a PKI that can be shown to function correctly. The platform was operating. Certificates were being issued and consumed. What the organisation could not do was demonstrate, to itself or to anyone else, that the service was configured as intended, that it complied with the standards it was meant to meet, or that the trust it underwrote was well founded.

That gap has consequences well beyond the technical estate. Assurance functions cannot sign off what cannot be evidenced. Architects will not extend a service they cannot describe. Operations teams cannot support infrastructure whose configuration is unknown to them. The result is a platform that continues to run while the organisation quietly stops relying on it, which is a poor return on the investment already made.

The compounding cost of unadopted trust services

Reluctance to adopt the PKI service for new use cases was the most commercially significant of the impacts identified. A certificate service earns its value through consolidation: the more of the estate it serves, the more the investment is justified and the more consistent the organisation's security posture becomes. Where teams avoid it, they do not stop needing certificates. They obtain them elsewhere, through public certificate authorities, local issuance or self-signed material, each of which fragments trust and creates management overhead invisible to the central function.

The organisation had therefore reached a decision point. It could continue with a service it could not evidence, replace infrastructure that was very possibly sound, or establish the facts and act on them. Commissioning an independent assessment was the least expensive of the three, and the only one that would produce a defensible basis for whichever route followed.

Why independence mattered

The implementation under review had been delivered by a third party. An assessment carried out by that party, or by anyone with a commercial interest in the follow-on work, would have struggled to carry weight internally regardless of its quality. Unsung was engaged specifically to provide an independent, vendor-neutral view: to report the platform as it was found, without regard to who had built it or what remediation might follow.

‍

Outcomes & Deliverables

Unsung delivered a comprehensive health check report providing clear visibility of PKI service status and a pragmatic path to demonstrable compliance.

A detailed report outlined findings across all dimensions of the PKI service, with evidence-based, prioritised recommendations and actionable steps to achieve demonstrable compliance whilst minimising technical debt. The assessment applied Unsung's established health check methodology, weighted here towards reconstruction of the undocumented baseline.

Current state analysis

We established what had actually been built. This covered certificate authority configuration, the certificate profiles and templates in use, Authority Information Access locations, and the mechanisms by which certificates were requested, issued and renewed. Revocation infrastructure was examined in detail, including CRL generation and distribution, alongside key protection arrangements, backup provision and monitoring capability. With no documentation available to check the platform against, the environment itself became the only reliable source, and the analysis was conducted accordingly.

Risk assessment and findings

Vulnerabilities, misconfigurations and process weaknesses were documented and categorised by risk level. Certificate validity periods, expiry tracking and the protection of sensitive material were assessed against good practice. Each finding was recorded with its context, its potential impact and a recommended mitigation, so that the organisation could sequence remediation against its own risk appetite rather than working from an undifferentiated issue list. Not every departure from ideal configuration warrants immediate action, and distinguishing the consequential from the cosmetic was central to making the report usable.

Governance and compliance review

The absence of Certificate Policy, Certificate Practice Statement and supporting operational documentation was itself a principal finding, since these artefacts are what allow an organisation to demonstrate compliance rather than assert it. We assessed what governance existed against the frameworks the organisation was expected to meet, and established what would be required to close the gap. Crucially, this was scoped as a route to demonstrable compliance rather than a documentation exercise for its own sake: policy that does not describe actual practice provides no assurance and creates audit exposure of its own.

Operational efficiency evaluation

Manual processes and performance constraints were identified, with recommendations covering automation, tooling and workflow improvements. The inability to support the infrastructure effectively was among the organisation's stated concerns, and addressing it required more than documentation. It required a clear view of which operational tasks the platform demanded, which of those were being performed, and which were being omitted because nobody knew they were necessary.

Strategic alignment and the path to compliance

We assessed how well the PKI supported the organisation's wider technology direction and what would be required for it to serve the new use cases teams had been reluctant to bring to it. Recommendations were framed around minimising technical debt, so that remediation strengthened the platform rather than layering further undocumented change onto an already opaque environment. Where reconfiguration was warranted, it was recommended as reconfiguration; where the finding pointed to a more fundamental architectural issue, that was stated plainly rather than deferred.

The report

The final report was written for technical and executive audiences alike, containing detailed observations, prioritised actions and practical recommendations with clear next steps. Its principal value was that it converted a diffuse loss of confidence into a specific, evidenced and sequenced set of actions. Confidence in a trust service is rebuilt by demonstrating that the service is understood and controlled, and that requires a documented baseline to build from.

‍

Challenges

A complete absence of documentation

Complete absence of documentation relating to architecture, implementation, or configuration necessitated a methodical, structured forensic approach to identify and capture all system integrations, data flows, user and system interactions, and configuration parameters across all platform components.

Assessment normally proceeds by comparing an environment against its documented design and investigating where the two diverge. With no design documentation in existence, that method was unavailable. The baseline had to be reconstructed from the platform itself, component by component, and then validated with the organisation. This is slower and demands considerably deeper platform knowledge, because the assessor must know what to look for without being told where to look.

Establishing integrations and dependencies without a map

System integrations and data flows are the elements most reliably lost when documentation is absent, and the most consequential to miss. A certificate authority in an enterprise environment is connected to directory services, key protection, monitoring, request interfaces and consuming applications, and any of those connections may carry an assumption that nobody has recorded. Establishing them required systematic examination of configuration and interfaces rather than reliance on institutional memory, which in this case had largely departed with the third-party implementer.

Reporting findings without apportioning blame

Assessing work delivered by another party carries an obvious risk of the report being read as a critique of a supplier rather than as a basis for action. Unsung's findings were framed around the current state and the route forward, evidenced from the platform and directed at what the organisation needed to do next. Keeping the report factual and forward-looking is what allows it to be acted on rather than contested.

Scoping the assessment against the concerns raised

The scope was drawn from the three impacts the organisation had identified: reluctance to adopt the service, compliance concerns and inability to support the infrastructure. Each pointed at a different dimension of the assessment. Adoption reluctance is addressed by establishing and communicating a reliable technical baseline. Compliance concerns are addressed through governance review and a documented route to evidencing control. Supportability is addressed by capturing configuration and operational requirements in a form the internal team can use. Scoping the health check against stated business impacts rather than against a generic checklist kept the findings tied to the decisions the organisation actually needed to make.

Minimising technical debt in the remediation path

Recommendations were framed to avoid a common outcome in remediation work, where each issue is fixed in isolation and the cumulative effect is an environment even harder to reason about than the one that preceded it. Where several findings shared a root cause, that was stated so the organisation could address the cause once rather than the symptoms repeatedly. Where a fix would have resolved an immediate issue at the cost of further undocumented complexity, the trade-off was made explicit. Sequencing mattered too: documentation and governance work was positioned ahead of configuration change, so that subsequent changes were made against a known baseline and recorded as they happened rather than adding to the deficit the assessment had been commissioned to address.

The report was written so that the organisation could act on it without further consultancy support. An assessment that requires its author to interpret it has limited value to a client whose core concern was an inability to support infrastructure independently.

‍

Technologies Used

Keyfactor EJBCA, Thales Key Protection
Unsung's health check methodology is vendor-neutral and applies across certificate authority and key protection platforms. Findings and recommendations are driven by the organisation's requirements, risk position and existing estate, not by any commercial relationship.

Related Services

Learn more about our PKI health check, PKI consultancy.