When you need it
Internal services use certificates from an old Windows CA, self-signed scripts or a spreadsheet of renewal dates. Renewal depends on someone remembering, revocation has never been tested, and every missed expiry becomes an outage.
What sets the quote
- One platform: AWS Private CA, Google Cloud Certificate Authority Service, AD CS, Microsoft Cloud PKI for Intune or HashiCorp Vault.
- A root CA plus up to 2 issuing CAs.
- Up to 2 enrolment methods, such as ACME, SCEP through Intune or AWS Private CA Connector for Active Directory.
- Automated renewal and TLS hardening for up to 20 endpoints.
- More CAs, enrolment methods or endpoints are quoted after sizing.
What changes
- Internal services and devices get certificates from one CA hierarchy that you own and understand.
- Certificates renew automatically, and your team is alerted before any certificate that failed to renew expires.
- Revocation works. CRLs are published, with OCSP where the platform supports it, and a revoked certificate is refused in testing.
- The root CA key stays offline or inside a managed CA service, with access limited to named people.
What you get
- CA hierarchy design covering validity periods, key algorithms, naming, certificate profiles and who may issue
- Root and up to 2 issuing CAs, built as code where the platform allows it (Terraform or PowerShell)
- Up to 2 enrolment methods, set up and tested end to end
- CRL publication, plus OCSP where the platform supports it, tested with a revoked certificate
- Automated renewal and hardened TLS settings on up to 20 endpoints
- Expiry monitoring with alerts to your ticket system or chat
- Runbooks for issuing, revoking and renewing certificates and for recovering a CA, and a handover session
What we cover on each platform
| Platform | Typical use | Enrolment options | Revocation |
|---|---|---|---|
| AWS Private CA | Workloads on AWS, including EKS | ACM private certificates, cert-manager with the AWS Private CA issuer, AWS Private CA Connector for Active Directory or for SCEP | CRL in Amazon S3, OCSP |
| Google Cloud Certificate Authority Service | Workloads on Google Cloud, including GKE | cert-manager with the Google CAS issuer, the CA Service API | CRL in Cloud Storage |
| AD CS | Windows estates with on-premises Active Directory | Autoenrolment through Group Policy, SCEP through Intune with NDES | CRL, OCSP through the Online Responder |
| Microsoft Cloud PKI | Certificates for Intune-managed devices, such as Wi-Fi and VPN | SCEP through Intune | CRL hosted by Microsoft |
| HashiCorp Vault | Services across clouds and Kubernetes | ACME, cert-manager with the Vault issuer, Vault Agent | CRL, OCSP |
Not included
- Hardware security modules (HSMs)
- The CA service fees your cloud provider bills
- Public certificates from public CAs, quoted separately
- Moving services beyond the 20 endpoints to the new CA, and retiring the old CA, quoted after sizing
What we need from you
- Time-limited admin access on the chosen platform, for example an IAM role that can manage AWS Private CA, CA Service Admin in Google Cloud, Intune Administrator for Cloud PKI, Enterprise Admins for AD CS or a Vault policy for the PKI mounts.
- Owners of the endpoints in scope, who can change their certificate and TLS settings or give us access to do so.
- A decision-maker for naming, validity periods and who may issue certificates.
- The servers or VMs the design needs, such as an offline root CA VM for AD CS.
How it works
Free 30-minute call, then a written fixed quote once the platform, enrolment methods and endpoints are agreed.
Design workshop on the hierarchy, validity periods, certificate profiles, revocation and who may issue.
Build as code where the platform allows it, then test issuance, renewal and revocation end to end.
Move the agreed endpoints to automated renewal, switch on expiry monitoring and hand over the runbooks.
At a glance
- Duration
- 3–4 weeks
- Price
- Fixed quote after a free 30-minute call
- Delivered by
- Our lead architect and a cloud engineer
Related services
PKI review
A one-week review of your PKI and certificates, covering the CA hierarchy, certificate inventory, TLS settings and revocation, rated red, amber or green, with an expiry risk list and a roadmap.
Domain and external attack surface check
A one-week, non-intrusive check of your domains, DNS, email authentication and internet-facing endpoints, with every finding tied to evidence and a fix. It is not a penetration test.
Microsoft 365 security baseline
Conditional Access, phishing-resistant MFA and just-in-time admin rights for Microsoft 365, plus Intune policies, Defender for Endpoint and disk encryption for Windows and macOS, designed and rolled out in 1–3 weeks.