Skip to content
All services
Identity, PKI & domainsBuild

Private PKI and certificate automation

A private CA hierarchy on one platform, with automated enrolment and renewal, working revocation and expiry alerts, built as code in 3–4 weeks.

When you need it

Internal services use certificates from an old Windows CA, self-signed scripts or a spreadsheet of renewal dates. Renewal depends on someone remembering, revocation has never been tested, and every missed expiry becomes an outage.

What sets the quote

  • One platform: AWS Private CA, Google Cloud Certificate Authority Service, AD CS, Microsoft Cloud PKI for Intune or HashiCorp Vault.
  • A root CA plus up to 2 issuing CAs.
  • Up to 2 enrolment methods, such as ACME, SCEP through Intune or AWS Private CA Connector for Active Directory.
  • Automated renewal and TLS hardening for up to 20 endpoints.
  • More CAs, enrolment methods or endpoints are quoted after sizing.

What changes

  • Internal services and devices get certificates from one CA hierarchy that you own and understand.
  • Certificates renew automatically, and your team is alerted before any certificate that failed to renew expires.
  • Revocation works. CRLs are published, with OCSP where the platform supports it, and a revoked certificate is refused in testing.
  • The root CA key stays offline or inside a managed CA service, with access limited to named people.

What you get

  • CA hierarchy design covering validity periods, key algorithms, naming, certificate profiles and who may issue
  • Root and up to 2 issuing CAs, built as code where the platform allows it (Terraform or PowerShell)
  • Up to 2 enrolment methods, set up and tested end to end
  • CRL publication, plus OCSP where the platform supports it, tested with a revoked certificate
  • Automated renewal and hardened TLS settings on up to 20 endpoints
  • Expiry monitoring with alerts to your ticket system or chat
  • Runbooks for issuing, revoking and renewing certificates and for recovering a CA, and a handover session

What we cover on each platform

PlatformTypical useEnrolment optionsRevocation
AWS Private CAWorkloads on AWS, including EKSACM private certificates, cert-manager with the AWS Private CA issuer, AWS Private CA Connector for Active Directory or for SCEPCRL in Amazon S3, OCSP
Google Cloud Certificate Authority ServiceWorkloads on Google Cloud, including GKEcert-manager with the Google CAS issuer, the CA Service APICRL in Cloud Storage
AD CSWindows estates with on-premises Active DirectoryAutoenrolment through Group Policy, SCEP through Intune with NDESCRL, OCSP through the Online Responder
Microsoft Cloud PKICertificates for Intune-managed devices, such as Wi-Fi and VPNSCEP through IntuneCRL hosted by Microsoft
HashiCorp VaultServices across clouds and KubernetesACME, cert-manager with the Vault issuer, Vault AgentCRL, OCSP

Not included

  • Hardware security modules (HSMs)
  • The CA service fees your cloud provider bills
  • Public certificates from public CAs, quoted separately
  • Moving services beyond the 20 endpoints to the new CA, and retiring the old CA, quoted after sizing

What we need from you

  • Time-limited admin access on the chosen platform, for example an IAM role that can manage AWS Private CA, CA Service Admin in Google Cloud, Intune Administrator for Cloud PKI, Enterprise Admins for AD CS or a Vault policy for the PKI mounts.
  • Owners of the endpoints in scope, who can change their certificate and TLS settings or give us access to do so.
  • A decision-maker for naming, validity periods and who may issue certificates.
  • The servers or VMs the design needs, such as an offline root CA VM for AD CS.

How it works

  1. Free 30-minute call, then a written fixed quote once the platform, enrolment methods and endpoints are agreed.

  2. Design workshop on the hierarchy, validity periods, certificate profiles, revocation and who may issue.

  3. Build as code where the platform allows it, then test issuance, renewal and revocation end to end.

  4. Move the agreed endpoints to automated renewal, switch on expiry monitoring and hand over the runbooks.

At a glance

Duration
3–4 weeks
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect and a cloud engineer
Assess

PKI review

A one-week review of your PKI and certificates, covering the CA hierarchy, certificate inventory, TLS settings and revocation, rated red, amber or green, with an expiry risk list and a roadmap.

Duration:1 week
Assess Popular

Domain and external attack surface check

A one-week, non-intrusive check of your domains, DNS, email authentication and internet-facing endpoints, with every finding tied to evidence and a fix. It is not a penetration test.

Duration:1 week
Build Popular

Microsoft 365 security baseline

Conditional Access, phishing-resistant MFA and just-in-time admin rights for Microsoft 365, plus Intune policies, Defender for Endpoint and disk encryption for Windows and macOS, designed and rolled out in 1–3 weeks.

Duration:1–3 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.