2025 / Infrastructure / ADCS-PKI-001

2-Tier PKI Hierarchy with AD CS

Two-tier Microsoft AD CS PKI hierarchy for enterprise certificate issuance and operational control.

วัตถุประสงค์

Design and implement a two-tier PKI hierarchy that separates root trust from issuing certificate services.

บริบทลูกค้า

The customer needed certificate infrastructure for internal systems, device trust, and future security initiatives.

ขอบเขตงาน

  • Offline root CA design
  • Enterprise issuing CA configuration
  • Certificate templates and enrollment permissions
  • Revocation publication planning
  • Backup and recovery procedure notes

แนวทางส่งมอบ

The PKI was built with a controlled ceremony for root material and clear documentation for day-two operations.

ผลลัพธ์

The customer received a stronger certificate foundation with a documented hierarchy and operational ownership model.

หลักฐานการส่งมอบ

Build records, CA configuration exports, template inventory, and recovery notes were handed over.