PKI Design & Implementation

We design PKI that lasts 20 years

Offline root CA, online issuing CA, OCSP, CRL, AIA — built on EJBCA Community or Enterprise with ECDSA P-384 / SHA3-512 as the baseline. HSM integration via PKCS#11. RFC 5280 from the ground up. NIS2 and eIDAS as a side effect, not an afterthought.

How we work

From whiteboard to certificate authority — in five phases

A structured engagement that gets you from "we should probably modernise our CA" to a production-grade PKI you can audit, automate and operate for two decades.

Architecture review & threat model

Map your current trust anchors, certificate profiles and consuming services. Decide offline-vs-online root posture, tier depth, key algorithms and HSM requirements. Output: an architecture document signed off before any keys are generated.

Root CA ceremony

Air-gapped root CA generation under controlled conditions. ECDSA P-384 keys on a FIPS 140-2 Level 3 HSM (or SoftHSM2 for non-regulated tiers). Multi-person integrity controls. Witnessed and recorded.

Issuing CA deployment

EJBCA cluster behind HAProxy, MariaDB Galera for the CA database, OCSP responder, CRL publication over HTTP per RFC 5280. End-entity profiles, certificate profiles and approval workflows configured to your business need.

Integration & automation

ACME for TLS server certs, EJBCA REST for service-account mTLS, Salt-managed cert distribution. CRL/OCSP propagation tested under load. Vault holds enrolment credentials. Renewal happens before anyone notices.

Handover & operations runbook

Your CA team gets a runbook covering daily operations, incident response, key rotation and disaster recovery. Quarterly health checks. SkyQon stays on retainer or hands you the keys — your choice.

Tech we deploy

A stack we run ourselves

Not vendor-pitched. Every component below runs in the SkyQon production lab and has been validated against real workloads — not just product brochures.

Certificate Authority

EJBCA CommunityEJBCA EnterpriseRFC 5280

EJBCA cluster (active/active behind HAProxy) with MariaDB Galera for the CA database. Sub-second OCSP. Stable for years.

Cryptography

ECDSA P-384SHA3-512RSA-4096

ECDSA P-384 / SHA3-512 as the modern baseline. RSA only when legacy clients require it. A roadmap for post-quantum hybrid.

Hardware security

PKCS#11SoftHSM2ThalesEntrust nShield

HSM integration for any tier where keys must never be extractable. SoftHSM2 for development tiers and labs.

Validation authority

OCSPCRLAIA

OCSP responder co-located or peered. CRL published over HTTP (RFC 5280 — a signed artefact, not transport). AIA chase-up paths verified.

Enrolment protocols

ACMEEJBCA RESTCMPSCEP

ACME for web-server certs, REST for service accounts, CMP/SCEP for legacy clients (printers, network gear).

Compliance & audit

NIS2eIDASCA/B BRETSI

Audit-ready logging, retention policy and evidence collection. Designed for NIS2 Article 21 from day one.

Single pane of glass

The PKI Ops Dashboard

The operations console we run on our own CA — and hand over with an engagement. A live view of the whole trust estate, with the two daily actions that matter (issue, revoke) one click away, gated by your identity provider instead of shared CA-console passwords.

Live CA trust tree

Root, intermediate and issuing CAs plus the separate management trust root — the two-trust-root model made visible, each CA with live status.

Certificate inventory

Every certificate with status, expiry horizon and renewal lineage — filter active, expiring or revoked, and see renewal coverage at a glance.

Issue & revoke in one click

CSR to signed certificate via EJBCA REST in seconds; revocation with reason codes, visible to OCSP in under a minute.

Service health

CA, OCSP responder, CRL freshness, Vault and the log sink — one live status row per dependency, so a quiet failure is never invisible.

Audit feed

Every issuance, revocation and admin action from the CA's audit log, streamed into the dashboard — the evidence trail your auditor asks for.

SSO-gated

OpenID Connect via Keycloak with AD-group-mapped roles. Operators never touch the CA console directly, and there are no shared passwords.

What you get

The deliverables

  • Architecture documentTrust hierarchy, profiles, key-ceremony plan, naming convention, lifecycle policy.
  • Working CAProduction-grade EJBCA cluster with HSM-backed keys, OCSP, CRL, AIA and configured profiles.
  • Integration codeACME automation, REST clients, Salt formulas — all in your Git repo, not ours.
  • RunbookDaily ops, incident response, key rotation, DR — written as you'd write it for a junior CA admin.
  • Audit artefactsKey-ceremony recording, signed acceptance-test report, baseline configuration audit log.
  • Quarterly health checkFor 12 months — we make sure the design is still right as your environment evolves.

Ready for an architecture review?

Free 60-minute discovery call. We assess your current PKI posture and tell you honestly whether you need a redesign or a tune-up.