
PKI Design & Build
Why
At Unsung, PKI is all we do. We design and build end-to-end public key infrastructure shaped around your business requirements, not just your infrastructure.
With experience across both public and private sectors, we recognise that successful implementation means addressing people, processes and governance alongside the technology. We offer vendor-agnostic advice and deliver scalable, standards-based architectures using appropriate tools rather than preferred ones.
Architecture design that balances security and operability
We help organisations navigate the architectural decisions that determine security posture, operational complexity and long-term flexibility.
CA hierarchy design
We design hierarchy structures based on your security requirements and your operational capacity to run them:
- Two-tier architecture combining an offline root CA with online issuing CAs, balancing security through air-gapped root authorities with operational efficiency for day-to-day issuance.
- Three-tier architecture introducing intermediate CA layers between root and issuing authorities, enabling role segregation and compartmentalisation for large enterprises.
- Hybrid models combining private PKI for internal infrastructure with public certificate authorities for external-facing services requiring universal browser trust.
Our delivery of a highly assured PKI root and greenfield PKI design and discovery case studies show how these decisions play out in practice.
Root CA and issuing CA configuration
We establish hierarchies where the root CA operates permanently offline with tamper-evident safety mechanisms, while issuing CAs handle day-to-day certificate operations. That separation keeps root certificates protected without compromising operational efficiency.
Deployment models
We assess the trade-offs between private CA deployment, public certificate authorities and managed services:
- Private PKI providing complete control over certificate policy, validation procedures and security policy.
- Public CA integration for external services requiring browser trust.
- PKI as a service reducing operational overhead while maintaining policy customisation.
- Internal PKI secured through hardware security module protection and comprehensive access controls.
Robust private key protection
We implement defence-in-depth strategies protecting the private key at every certificate authority level.
Hardware security module implementation
We deploy hardware security modules providing validated, tamper-resistant storage for CA private keys. These dedicated cryptographic appliances ensure private keys never exist in plaintext outside secure hardware boundaries, with tamper-evident mechanisms destroying key material if physical intrusion is detected.
Offline root CA security
We establish offline root authorities with air-gapped systems, strict physical access controls and multi-person authorisation. The root CA activates only for signing intermediate CA certificates or revocation lists, minimising exposure while maintaining certification path integrity across the whole PKI.
Key management procedures
We develop key management protocols covering:
- Key ceremony procedures for root CA private key generation.
- Private key protection throughout the certificate lifecycle.
- Key escrow and recovery for business continuity.
- Role separation ensuring no single administrator can compromise certificate operations.
Complete certificate lifecycle management
We design and implement automated certificate lifecycle management spanning request through revocation. The capabilities that matter are set out in our article on the four pillars of CLM.
Enrolment automation
We implement appropriate enrolment mechanisms for diverse environments. Which certificate management protocol suits which system is one of the more consequential design decisions:
- Auto-enrolment through Active Directory for Windows domain environments.
- SCEP for network devices.
- ACME for cloud-native applications.
- RESTful APIs for microservices and container platforms.
- Manual processes where human validation is required.
Issuance and distribution
We establish issuance workflows using certificate templates that enforce security policy while enabling operational efficiency. Templates define key usage restrictions, validity periods and subject name formats, ensuring certificates are issued with appropriate security characteristics regardless of who requested them.
Renewal and expiration management
We implement monitoring and automation preventing the service outages that expired certificates cause. Layered alerting, automated renewal workflows and discovery across hybrid environments keep certificates current without manual intervention.
This matters more each year. Public TLS lifetimes are falling to 47 days, taking renewal volume up roughly eightfold.
Distribution infrastructure
We configure Authority Information Access and CRL distribution points so certificate validation functions across network boundaries. Load-balanced, highly available infrastructure supports chain validation from any location — including the segmented networks where validation most often fails in practice.
Comprehensive revocation infrastructure
We implement mechanisms ensuring revoked certificates cannot be used for unauthorised purposes.
Certificate revocation list management
We configure CRL publication at a frequency balancing security against operational load. Delta CRLs reduce bandwidth while providing incremental updates between full publications.
OCSP deployment
We deploy OCSP responders providing real-time revocation checking, with OCSP stapling configured on web servers to improve TLS handshake performance and remove client-side validation delays.
Validation infrastructure optimisation
We size and optimise revocation infrastructure to handle peak validation loads well above steady-state volumes, with caching strategies that maintain performance without compromising security.
Security policy and governance
We develop the documentation establishing operational procedures and security controls for your certification authority infrastructure.
Certificate policy
We create certificate policies defining usage standards, naming conventions, validation requirements and trust levels — establishing which authorities may issue certificates for which purposes, and what identity verification requesters must complete.
Certification practice statement
We document the operational procedures implementing those policy requirements in your specific environment, covering lifecycle procedures, key management practices, physical security controls and incident response.
Certificate requirements analysis
We work with stakeholders to define requirements across:
- User certificates for email encryption, authentication and digital signatures.
- Server certificates for TLS and application authentication.
- Device certificates for IoT and network infrastructure.
- Code signing certificates for application and firmware integrity.
Identity verification
We establish verification procedures aligned to certificate type and intended use, from domain validation through to extended validation for public certificates, and Active Directory integration for internal operations.
Compliance and standards alignment
We ensure infrastructure meets regulatory requirements and industry standards.
Regulatory compliance
We design PKI satisfying the frameworks that apply to you, including FIPS 140-3 for government and defence, PCI DSS for financial services, data protection requirements in healthcare, and eIDAS for European entities.
Standards-based architecture
We implement following RFC standards for certificate formats and protocols, CA/Browser Forum baseline requirements where applicable, vendor security guidelines, and sector-specific policy.
Audit preparation
We develop the documentation and evidence collection that supports compliance audits, with continuous monitoring tracking configuration compliance, access controls and operational procedures.
Why organisations choose Unsung
- PKI specialists. PKI is our sole focus. Our engineers maintain deep expertise across certificate authorities, HSMs, certificate management platforms and integration, with proven experience from complex deployments.
- Vendor-agnostic guidance. We select technologies based on your requirements, not vendor relationships. Our experience spans commercial platforms, open-source solutions and hybrid approaches.
- Business-focused design. We design PKI that solves business problems rather than implementing technology for its own sake, addressing compliance requirements and operational constraints alongside architecture.
- End-to-end delivery. From requirements analysis through operational handover, you receive functioning infrastructure with documented procedures, trained staff and ongoing support options.
- Future-ready architecture. We design for evolution, including crypto agility and migration to post-quantum cryptography.
What
How Unsung solves PKI challenges
At Unsung, PKI is all we do. We design and build end-to-end public key infrastructure shaped around your business requirements, not just your infrastructure.
With experience across both public and private sectors, we recognise that successful implementation means addressing people, processes and governance alongside the technology. We offer vendor-agnostic advice and deliver scalable, standards-based architectures using appropriate tools rather than preferred ones.
Architecture design that balances security and operability
We help organisations navigate the architectural decisions that determine security posture, operational complexity and long-term flexibility.
CA hierarchy design
We design hierarchy structures based on your security requirements and your operational capacity to run them:
- Two-tier architecture combining an offline root CA with online issuing CAs, balancing security through air-gapped root authorities with operational efficiency for day-to-day issuance.
- Three-tier architecture introducing intermediate CA layers between root and issuing authorities, enabling role segregation and compartmentalisation for large enterprises.
- Hybrid models combining private PKI for internal infrastructure with public certificate authorities for external-facing services requiring universal browser trust.
Our delivery of a highly assured PKI root and greenfield PKI design and discovery case studies show how these decisions play out in practice.
Root CA and issuing CA configuration
We establish hierarchies where the root CA operates permanently offline with tamper-evident safety mechanisms, while issuing CAs handle day-to-day certificate operations. That separation keeps root certificates protected without compromising operational efficiency.
Deployment models
We assess the trade-offs between private CA deployment, public certificate authorities and managed services:
- Private PKI providing complete control over certificate policy, validation procedures and security policy.
- Public CA integration for external services requiring browser trust.
- PKI as a service reducing operational overhead while maintaining policy customisation.
- Internal PKI secured through hardware security module protection and comprehensive access controls.
Robust private key protection
We implement defence-in-depth strategies protecting the private key at every certificate authority level.
Hardware security module implementation
We deploy hardware security modules providing validated, tamper-resistant storage for CA private keys. These dedicated cryptographic appliances ensure private keys never exist in plaintext outside secure hardware boundaries, with tamper-evident mechanisms destroying key material if physical intrusion is detected.
Offline root CA security
We establish offline root authorities with air-gapped systems, strict physical access controls and multi-person authorisation. The root CA activates only for signing intermediate CA certificates or revocation lists, minimising exposure while maintaining certification path integrity across the whole PKI.
Key management procedures
We develop key management protocols covering:
- Key ceremony procedures for root CA private key generation.
- Private key protection throughout the certificate lifecycle.
- Key escrow and recovery for business continuity.
- Role separation ensuring no single administrator can compromise certificate operations.
Complete certificate lifecycle management
We design and implement automated certificate lifecycle management spanning request through revocation. The capabilities that matter are set out in our article on the four pillars of CLM.
Enrolment automation
We implement appropriate enrolment mechanisms for diverse environments. Which certificate management protocol suits which system is one of the more consequential design decisions:
- Auto-enrolment through Active Directory for Windows domain environments.
- SCEP for network devices.
- ACME for cloud-native applications.
- RESTful APIs for microservices and container platforms.
- Manual processes where human validation is required.
Issuance and distribution
We establish issuance workflows using certificate templates that enforce security policy while enabling operational efficiency. Templates define key usage restrictions, validity periods and subject name formats, ensuring certificates are issued with appropriate security characteristics regardless of who requested them.
Renewal and expiration management
We implement monitoring and automation preventing the service outages that expired certificates cause. Layered alerting, automated renewal workflows and discovery across hybrid environments keep certificates current without manual intervention.
This matters more each year. Public TLS lifetimes are falling to 47 days, taking renewal volume up roughly eightfold.
Distribution infrastructure
We configure Authority Information Access and CRL distribution points so certificate validation functions across network boundaries. Load-balanced, highly available infrastructure supports chain validation from any location — including the segmented networks where validation most often fails in practice.
Comprehensive revocation infrastructure
We implement mechanisms ensuring revoked certificates cannot be used for unauthorised purposes.
Certificate revocation list management
We configure CRL publication at a frequency balancing security against operational load. Delta CRLs reduce bandwidth while providing incremental updates between full publications.
OCSP deployment
We deploy OCSP responders providing real-time revocation checking, with OCSP stapling configured on web servers to improve TLS handshake performance and remove client-side validation delays.
Validation infrastructure optimisation
We size and optimise revocation infrastructure to handle peak validation loads well above steady-state volumes, with caching strategies that maintain performance without compromising security.
Security policy and governance
We develop the documentation establishing operational procedures and security controls for your certification authority infrastructure.
Certificate policy
We create certificate policies defining usage standards, naming conventions, validation requirements and trust levels — establishing which authorities may issue certificates for which purposes, and what identity verification requesters must complete.
Certification practice statement
We document the operational procedures implementing those policy requirements in your specific environment, covering lifecycle procedures, key management practices, physical security controls and incident response.
Certificate requirements analysis
We work with stakeholders to define requirements across:
- User certificates for email encryption, authentication and digital signatures.
- Server certificates for TLS and application authentication.
- Device certificates for IoT and network infrastructure.
- Code signing certificates for application and firmware integrity.
Identity verification
We establish verification procedures aligned to certificate type and intended use, from domain validation through to extended validation for public certificates, and Active Directory integration for internal operations.
Compliance and standards alignment
We ensure infrastructure meets regulatory requirements and industry standards.
Regulatory compliance
We design PKI satisfying the frameworks that apply to you, including FIPS 140-3 for government and defence, PCI DSS for financial services, data protection requirements in healthcare, and eIDAS for European entities.
Standards-based architecture
We implement following RFC standards for certificate formats and protocols, CA/Browser Forum baseline requirements where applicable, vendor security guidelines, and sector-specific policy.
Audit preparation
We develop the documentation and evidence collection that supports compliance audits, with continuous monitoring tracking configuration compliance, access controls and operational procedures.
Why organisations choose Unsung
- PKI specialists. PKI is our sole focus. Our engineers maintain deep expertise across certificate authorities, HSMs, certificate management platforms and integration, with proven experience from complex deployments.
- Vendor-agnostic guidance. We select technologies based on your requirements, not vendor relationships. Our experience spans commercial platforms, open-source solutions and hybrid approaches.
- Business-focused design. We design PKI that solves business problems rather than implementing technology for its own sake, addressing compliance requirements and operational constraints alongside architecture.
- End-to-end delivery. From requirements analysis through operational handover, you receive functioning infrastructure with documented procedures, trained staff and ongoing support options.
- Future-ready architecture. We design for evolution, including crypto agility and migration to post-quantum cryptography.
How
The Unsung approach
Requirements definition
We work with stakeholders to define business, compliance and technical certificate requirements, cataloguing certificate holders across users, devices and applications while anticipating future growth.
Where an existing estate is in scope, a PKI health check establishes the real starting position before design begins.
Architecture and solution design
We create vendor-agnostic hierarchy designs aligned with best practice. Decisions cover trust models, validity periods, policy frameworks and integration with existing security infrastructure.
Security policy framework
We develop the certificate policy and certification practice statement documentation providing the operational and legal foundation for your certification authority.
Platform integration and implementation
We deploy and configure complete PKI infrastructure integrated with your existing security and identity systems.
Certificate authority setup
We implement certificate authorities using the appropriate platform for your environment:
- Windows Server Active Directory Certificate Services for Microsoft environments.
- EJBCA and other Linux-based certificate services for open-source deployments.
- Cloud-hosted certificate authorities for hybrid architectures.
- Hardware security module integration at every CA tier.
Active Directory integration
We configure integration with AD CS, using existing domain infrastructure for automated enrolment while maintaining security through centralised templates and Group Policy enforcement.
Certificate store management
We establish appropriate certificate stores across user systems, servers and devices, ensuring distribution, chain validation and automated renewal all function correctly.
Application and service integration
We integrate PKI with the applications that depend on it:
- Web servers and load balancers for TLS.
- VPN concentrators and network access control.
- Email systems for S/MIME encryption and digital signatures.
- Code signing workflows for software integrity.
- IoT device authentication frameworks.
Deployment strategy and migration
We implement carefully orchestrated rollout phases, validating functionality before organisation-wide deployment. Our migration de-risking and Entrust to EJBCA migration case studies illustrate the approach.
Pilot deployment
We establish limited-scope pilots with representative use cases validating core functionality, covering diverse certificate types: user authentication, web server certificates and device certificates.
Root certificate distribution
We deploy root certificates establishing trust across all client systems, using Group Policy for domain-joined machines, mobile device management for mobile, and documented manual procedures for anything outside centralised management.
Legacy system integration
We develop integration strategies for applications lacking modern enrolment support, including manual installation procedures, format conversions and intermediate chain modifications. This is usually where deployments stall, and it is worth scoping honestly at the outset.
Operations handover
We transfer operational responsibility to your teams with knowledge transfer, training on certificate management platforms and documented procedures for routine operations. Where you would rather not run it in-house, PKI management and hosting is available as an alternative.
Monitoring and operational excellence
Certificate discovery and inventory
We implement automated discovery identifying certificates across on-premises infrastructure, public cloud and edge locations. In most estates we assess, the number found exceeds the number the organisation had on record. A cryptographic bill of materials extends this to algorithms and key lengths, and our guide to building a cryptographic inventory covers where to start.
Expiration monitoring
We configure layered alerting at appropriate intervals before expiry, escalating through management channels while triggering automated renewal where the system supports it. Our guide to overcoming resistance to automation covers the objections that typically surface here.
Security auditing
We establish logging and monitoring of all certificate operations, enabling compliance reporting and security investigation. Regular access reviews verify that only authorised personnel retain administrative access to certificate authorities.
Performance optimisation
We tune infrastructure for high-volume issuance, addressing the common bottlenecks: CA processing capacity, network bandwidth for distribution, and validation infrastructure sizing.
Governance, documentation and knowledge transfer
We create operational documentation supporting secure management of the infrastructure, including runbooks for certificate operations, incident response procedures and compliance reporting frameworks.
We upskill internal teams through targeted training on certificate lifecycle management, certificate authority administration, troubleshooting issuance problems and maintaining security controls.
Technical capabilities
Certificate authority technologies
- Windows Server Certificate Services
- EJBCA and Linux-based open-source certificate authorities
- Cloud-native certificate authority services
- Hardware security module integration from leading providers
Certificate management platforms
We work with all major certificate management platforms and recommend the most appropriate for your requirements. Our CLM vendor and licensing evaluation guide sets out how we approach that comparison.
Enrolment protocols
Auto-enrolment via Group Policy, SCEP, ACME, EST and RESTful APIs for modern applications. Our protocol comparison guide explains which suits which environment.
Validation infrastructure
CRL services, delta CRL optimisation, OCSP responders, OCSP stapling configuration and certificate chain validation optimisation.
Building digital trust infrastructure
Successful PKI implementation establishes the foundation of digital trust for your organisation. The architectural decisions made during initial design affect security, operations and business capability for years afterwards.
We make sure your public key infrastructure works as an enabler for secure communications, identity assurance and digital signatures — now, and when the cryptography underneath it needs to change.
Contact our team to discuss your PKI requirements.
