PKI Design & Implementation

We design PKI that lasts 20 years

Offline root CA, online issuing CA, OCSP, CRL, AIA — built on EJBCA Community or Enterprise with ECDSA P-384 / SHA3-512 as the baseline. HSM integration via PKCS#11. RFC 5280 from the ground up. NIS2 and eIDAS as a side effect, not an afterthought.

How we work

From whiteboard to certificate authority — in five phases

A structured engagement that gets you from "we should probably modernise our CA" to a production-grade PKI you can audit, automate and operate for two decades.

Architecture review & threat model

Map your current trust anchors, certificate profiles and consuming services. Decide offline-vs-online root posture, tier depth, key algorithms and HSM requirements. Output: an architecture document signed off before any keys are generated.

Root CA ceremony

Air-gapped root CA generation under controlled conditions. ECDSA P-384 keys on a FIPS 140-2 Level 3 HSM (or SoftHSM2 for non-regulated tiers). Multi-person integrity controls. Witnessed and recorded.

Issuing CA deployment

EJBCA cluster behind HAProxy, MariaDB Galera for the CA database, OCSP responder, CRL publication over HTTP per RFC 5280. End-entity profiles, certificate profiles and approval workflows configured to your business need.

Integration & automation

ACME for TLS server certs, EJBCA REST for service-account mTLS, Salt-managed cert distribution. CRL/OCSP propagation tested under load. Vault holds enrolment credentials. Renewal happens before anyone notices.

Handover & operations runbook

Your CA team gets a runbook covering daily operations, incident response, key rotation and disaster recovery. Quarterly health checks. SkyQon stays on retainer or hands you the keys — your choice.

Tech we deploy

A stack we run ourselves

Not vendor-pitched. Every component below runs in the SkyQon production lab and has been validated against real workloads — not just product brochures.

🔐

Certificate Authority

EJBCA CommunityEJBCA EnterpriseRFC 5280

EJBCA cluster (active/active behind HAProxy) with MariaDB Galera for the CA database. Sub-second OCSP. Stable for years.

🔑

Cryptography

ECDSA P-384SHA3-512RSA-4096

ECDSA P-384 / SHA3-512 as the modern baseline. RSA only when legacy clients require it. A roadmap for post-quantum hybrid.

🛡️

Hardware security

PKCS#11SoftHSM2ThalesEntrust nShield

HSM integration for any tier where keys must never be extractable. SoftHSM2 for development tiers and labs.

📡

Validation authority

OCSPCRLAIA

OCSP responder co-located or peered. CRL published over HTTP (RFC 5280 — a signed artefact, not transport). AIA chase-up paths verified.

🔁

Enrolment protocols

ACMEEJBCA RESTCMPSCEP

ACME for web-server certs, REST for service accounts, CMP/SCEP for legacy clients (printers, network gear).

📋

Compliance & audit

NIS2eIDASCA/B BRETSI

Audit-ready logging, retention policy and evidence collection. Designed for NIS2 Article 21 from day one.

What you get

The deliverables

  • Architecture documentTrust hierarchy, profiles, key-ceremony plan, naming convention, lifecycle policy.
  • Working CAProduction-grade EJBCA cluster with HSM-backed keys, OCSP, CRL, AIA and configured profiles.
  • Integration codeACME automation, REST clients, Salt formulas — all in your Git repo, not ours.
  • RunbookDaily ops, incident response, key rotation, DR — written as you'd write it for a junior CA admin.
  • Audit artefactsKey-ceremony recording, signed acceptance-test report, baseline configuration audit log.
  • Quarterly health checkFor 12 months — we make sure the design is still right as your environment evolves.

Ready for an architecture review?

Free 60-minute discovery call. We assess your current PKI posture and tell you honestly whether you need a redesign or a tune-up.