We design PKI that lasts 20 years
Offline root CA, online issuing CA, OCSP, CRL, AIA — built on EJBCA Community or Enterprise with ECDSA P-384 / SHA3-512 as the baseline. HSM integration via PKCS#11. RFC 5280 from the ground up. NIS2 and eIDAS as a side effect, not an afterthought.
From whiteboard to certificate authority — in five phases
A structured engagement that gets you from "we should probably modernise our CA" to a production-grade PKI you can audit, automate and operate for two decades.
Architecture review & threat model
Map your current trust anchors, certificate profiles and consuming services. Decide offline-vs-online root posture, tier depth, key algorithms and HSM requirements. Output: an architecture document signed off before any keys are generated.
Root CA ceremony
Air-gapped root CA generation under controlled conditions. ECDSA P-384 keys on a FIPS 140-2 Level 3 HSM (or SoftHSM2 for non-regulated tiers). Multi-person integrity controls. Witnessed and recorded.
Issuing CA deployment
EJBCA cluster behind HAProxy, MariaDB Galera for the CA database, OCSP responder, CRL publication over HTTP per RFC 5280. End-entity profiles, certificate profiles and approval workflows configured to your business need.
Integration & automation
ACME for TLS server certs, EJBCA REST for service-account mTLS, Salt-managed cert distribution. CRL/OCSP propagation tested under load. Vault holds enrolment credentials. Renewal happens before anyone notices.
Handover & operations runbook
Your CA team gets a runbook covering daily operations, incident response, key rotation and disaster recovery. Quarterly health checks. SkyQon stays on retainer or hands you the keys — your choice.
A stack we run ourselves
Not vendor-pitched. Every component below runs in the SkyQon production lab and has been validated against real workloads — not just product brochures.
Certificate Authority
EJBCA cluster (active/active behind HAProxy) with MariaDB Galera for the CA database. Sub-second OCSP. Stable for years.
Cryptography
ECDSA P-384 / SHA3-512 as the modern baseline. RSA only when legacy clients require it. A roadmap for post-quantum hybrid.
Hardware security
HSM integration for any tier where keys must never be extractable. SoftHSM2 for development tiers and labs.
Validation authority
OCSP responder co-located or peered. CRL published over HTTP (RFC 5280 — a signed artefact, not transport). AIA chase-up paths verified.
Enrolment protocols
ACME for web-server certs, REST for service accounts, CMP/SCEP for legacy clients (printers, network gear).
Compliance & audit
Audit-ready logging, retention policy and evidence collection. Designed for NIS2 Article 21 from day one.
The deliverables
- Architecture documentTrust hierarchy, profiles, key-ceremony plan, naming convention, lifecycle policy.
- Working CAProduction-grade EJBCA cluster with HSM-backed keys, OCSP, CRL, AIA and configured profiles.
- Integration codeACME automation, REST clients, Salt formulas — all in your Git repo, not ours.
- RunbookDaily ops, incident response, key rotation, DR — written as you'd write it for a junior CA admin.
- Audit artefactsKey-ceremony recording, signed acceptance-test report, baseline configuration audit log.
- Quarterly health checkFor 12 months — we make sure the design is still right as your environment evolves.
Ready for an architecture review?
Free 60-minute discovery call. We assess your current PKI posture and tell you honestly whether you need a redesign or a tune-up.