PKI Operations and Usage

PKI Operations refer to the capability of the organization to Deploy, Sustain and Expand PKI services. In other words, it’s a potentiality of an organization to utilize the PKI services into their environment to keep the services up and running. It comprises of all the processes from designing of PKI system to testing it.
There are some risks involved if PKI Operations are not performed:
Below are the PKI Operations tasks that are performed at different stages and periodic execution of the services makes it robust, scalable, secured and a reduced risk infrastructure.
Stage | Tasks | Description |
---|---|---|
Architectural |
| All the changes that are to be done to an existing PKI system. |
Maintenance |
| All the operations that need to be done to keep a check on service (like updation) and therefore get un-interupted services from CA. |
Testing |
| Check for Certificate status in CDP containers, AIA container, etc. |
Below are the tasks that are performed under the PKI operation processes at different stages:
Task | Description | Schedule (How oftenFrequency) | Estimated Task Execution Duration |
---|---|---|---|
Backup & Recovery of CA’s. |
| As Needed
| 4 Hours
(May vary with organization) |
CRL & AIA Publications of Root & Issuing CA | As one of the best practices for PKI operations, the CRLs of Root CA needs to be published every 6 months manually so that the updated CRL gets pushed in the environment. | Every Half Yearly
(manually) | 1 Hour
(May vary with organization) |
Renewal of Root CA and Issuing CA. | Root CA: Renewal of Root CA Key pair.
SubCA: Renewal of Issuing CA Key Pair. | Suggested – Root CA – Once every 9 Years and 10 months. For example, generally a Root CA certificate is valid for 20 years. So, it should be renewed once every 9 years and 10 months. This is because Root CA issues 10 years long certificates to its issuing CA and when the Issuing CA certificate will be renewed, Root CA should be able to renew it for another 10 years. SubCA – Every 2 year and 3 months. It actually depends on the validity of CA certificate which may vary system-to-system. | Root CA – 1 hour
SubCA – 1 hour (May vary with organization) |
Uninstall a CA | By uninstalling a CA we remove the ADCS roles and features from the CA Server. Make sure to take the backup of the CA before uninstalling it. So that when we want to add a new CA into our PKI system we can easily restore from the backup. | As Applicable | 1 hour
(May vary with organization) |
Add a New CA | Adding a new CA to your existing PKI system is required for high availability and load balancing on CA as well as to assign different roles intended for that particular CA. | As Needed | 1 hour
(May vary with organization) |
Add a new Certificate Template | When we have to implement some particular roles to the CA for signing and issuing the certificate we assign and add a template for the certificate.
For example, Workstation Authentication is a template which the CA uses to issue certificates to new users or machines connecting to the network so as to authenticate them. | As Applicable | ½ hour
(May vary with organization) |
PKI Health Check | After the PKI services are configured, expanded, updated and maintained it’s a best practice to check for PKI Health so that to be assured that PKI Operations on our system are well performed. | Recommended – After every PKI Operations. | ½ hour.
(May vary with organization) |
Recommendation– (may vary from organization to organization)
Architerural PKI Operations – They can be performed as needed or as applicable to the existing PKI requirements.
Maintenance PKI Operations – It is best practice to perform the maintenance task in a timely manner to receive a un-interrupted CA Services.
Testing PKI Operations – It should be performed in order to make our PKI services more informed and reliable one.
We recommended that every organization should maintain a PKI Operation Guide for detailed and step-by-step PKI operations to get an un-interrupted PKI Services. For more details on PKI Operation Guide, please contact us.
February 21, 2025
October 9, 2024