Consultancy

Transition From Expiring Issuing CA

Project Description

The engagement

Unsung was engaged to build a new Issuing CA and orchestrate the transition of all people, systems, and services from an existing certificate service approaching expiry, maintaining zero business or operational impact. The engagement was driven by the imminent expiry of the existing Issuing CA certificate.

The client environment featured an expansive and technically diverse user base spanning multiple project teams, each with unique technology stacks and certificate usage requirements.

Why issuing CA expiry is a hard deadline

Most infrastructure deadlines can be moved. This one cannot. An issuing certificate authority whose own certificate expires stops being able to issue, and every certificate depending on it ceases to validate as the chain fails. The date is fixed at the point the certificate is created, it is visible years in advance, and no amount of escalation alters it. That combination makes it one of the few genuinely immovable dates in enterprise IT, and it defined every aspect of how this engagement was planned and run.

The scope was also broader than a platform replacement. Building the new issuing CA was necessary but not sufficient; the transition of every consuming system, service and team had to be orchestrated as well. In practice the build is the smaller part of an engagement like this. The larger part is moving a diverse consumer base across without any of them noticing.

The scale of the consumer challenge

An expansive and technically diverse user base spanning multiple project teams, each with its own technology stack and certificate usage requirements, means there is no single transition procedure that will serve everyone. Each team has different integration points, different tooling, different release cycles and different tolerances for change. Some can move within days; others are constrained by their own change windows. Treating them as a homogeneous population would have guaranteed either a very slow transition or a series of avoidable failures.

‍

Outcomes & Deliverables

Unsung delivered an accelerated build and transition programme that successfully migrated all services:

Within three weeks, Unsung delivered a production-ready Issuing CA. Communications and support strategies derived from user acceptance testing enabled clear stakeholder communication and extensive risk management.

Certificate consumers were batched into transition cohorts based on risk assessment and service criticality. Beyond the core CA replacement, the new Issuing CA combined with bespoke signing scripts increased signing throughput tenfold per hour.

Compressed discovery and requirements

The engagement opened with discovery and due diligence scoped to what the deadline permitted, concentrating on the questions that would determine the design: what certificates were being issued, to whom, through what interfaces, and with what dependencies. Requirements were baselined quickly and formally so that the build could begin against an agreed position rather than a shifting one. Under compressed timelines the temptation is to shorten this phase furthest, which is precisely the wrong economy, since every requirement missed at this stage surfaces later as rework during transition when there is no time to absorb it.

Design and accelerated build

Technical design covered the issuing CA architecture, its relationship to the existing trust hierarchy, key protection, and the certificate profiles the new service would need to support. Build activity prepared the platform, installed and hardened the base components, and configured the certificate authority together with the operational management layer covering access control, monitoring, auditing and alerting. A production-ready issuing CA inside three weeks was possible because the phases were compressed and run in parallel where dependencies allowed, not because steps were omitted: the configuration was documented, the platform was tested and the service was accepted on the same basis it would have been under a longer timeline.

User acceptance testing as the basis for transition planning

User acceptance testing served a dual purpose here. It validated the platform, and it generated the intelligence on which the communications and support strategies were built. Watching real consumers attempt the transition revealed where the friction actually sat: which integrations needed additional guidance, which steps were commonly misunderstood, and which technology stacks required specific instruction. Communications derived from observed behaviour rather than assumption are substantially more effective, and the support model could be resourced against known demand rather than a guess.

Risk-based transition cohorts

Certificate consumers were batched into transition cohorts based on risk assessment and service criticality. This is the mechanism that made a large, diverse transition manageable within a fixed deadline. Lower-risk consumers moved first, proving the procedure and surfacing issues while there was still time to address them. The most critical services moved once the process was well established and the support model demonstrably working. Cohorting also allowed effort to be concentrated where it was needed, with intensive support for the teams that required it and a self-service route for those that did not.

Communications, support and risk management

Comprehensive stakeholder communication was maintained throughout, informed by the UAT findings and targeted at each cohort ahead of its transition window. Support arrangements were established to respond during the transition itself, with escalation paths defined so that issues could be resolved without waiting on the wider programme. Risk was managed actively rather than reviewed periodically, which under a fixed deadline is the only approach that works: a risk identified with three weeks remaining is a manageable problem, and the same risk identified with three days remaining is not.

A tenfold increase in signing throughput

Beyond the core CA replacement, the new issuing CA combined with bespoke signing scripts increased signing throughput tenfold per hour. This was a genuine operational gain rather than a by-product of the migration. The scripting was developed to address the throughput required to move a large consumer base within the available window, and it remained available to the client afterwards, converting a constraint imposed by the deadline into a lasting improvement in the service.

Handover and operational ownership

The new issuing CA was handed to the client's operations function with the documentation required to run it: configuration records reflecting the platform as built, runbooks covering routine operational tasks, and the bespoke signing tooling with its usage documented. Handover under an accelerated programme carries a particular risk, in that the delivery team retains knowledge that was never written down because there was no time to write it. Treating handover as a defined activity with its own deliverables rather than as the tail end of the transition is what prevents that knowledge being lost when the engagement closes.

‍

Challenges

Compressed timelines against extensive requirements

Compressed timelines combined with extensive customer requirements necessitated rapid build and deployment. The difficulty was not the build in isolation, nor the requirements in isolation, but the two together against a date that could not move. Resolving it required sequencing work so that activities proceeded in parallel wherever dependencies permitted, and making trade-off decisions quickly and visibly rather than allowing them to sit unresolved while the deadline advanced.

Supporting a technically diverse user base

Supporting an expansive and technically diverse user base required providing assistance to multiple project teams across varied technology stacks.

Unsung addressed these support challenges through deployment of consultants with broad technical expertise and establishment of escalation procedures enabling rapid engagement of specialist expertise.

The model was deliberate. Consultants with broad expertise could resolve the majority of queries at first contact across a wide range of technologies, which kept the transition moving. Defined escalation meant the less common problems reached specialist expertise quickly rather than stalling a team's migration. Under a fixed deadline, an unresolved support query is not an inconvenience but a blocked cohort, and the support model was designed with that in mind.

Maintaining zero operational impact throughout

The requirement to maintain zero business or operational impact applied across the entire transition, not solely at cutover. Every cohort represented a potential point of disruption for a live service. Cohorting by risk and criticality, rehearsing the procedure through UAT, and resourcing support against observed demand were the means by which that requirement was met, and the absence of impact was a result of that planning rather than an incidental outcome.

Testing and service acceptance under compression

Testing was executed against documented test scripts under an agreed test plan defining scope, roles, defect categorisation and exit criteria, with defects tracked to resolution. Under a compressed timeline the exit criteria matter more, not less, because they are what prevents schedule pressure from quietly lowering the bar for acceptance. Agreeing them in advance meant the decision to proceed to transition was taken against a defined standard rather than against the calendar.

What the engagement left behind

The CSR analysis produced something of continuing value beyond the migration: an evidenced picture of how certificates are consumed across the enterprise, by which teams, at what volumes and for what purposes. That is the foundation of a usable certificate inventory, and it is the input a certificate lifecycle management capability requires to be effective. An organisation that has just completed a migration of this scale is also, usually, an organisation with a clear view of why it does not want to repeat the exercise unprepared.

Why the transition succeeded

Three decisions carried the engagement. Using user acceptance testing to generate the communications and support model meant both were built on observed behaviour rather than assumption. Cohorting by risk and criticality meant the procedure was proven on the least exposed consumers first. Resourcing support for breadth with defined escalation to specialists meant queries were resolved at the pace the deadline required. None is technically remarkable; together they are what allowed a diverse consumer base to move within three weeks of the platform becoming available, without operational impact.

The value of the throughput gain

The tenfold increase in signing throughput deserves separate mention because it outlasted the engagement. It was developed to meet a constraint imposed by the deadline, but the capability remained with the client once the transition completed. Work undertaken under time pressure often leaves nothing behind beyond the immediate result; here the tooling built to solve the schedule problem became a permanent improvement to the service.

‍

Technologies Used

Keyfactor EJBCA, Thales Key Protection, VMware, Dell, Cisco
Unsung is vendor-neutral. The platform selection here reflected the client's requirements, existing standards and the timescale available, and our role covered both the technical delivery and the orchestration of the transition around it.

Related Services