2025 / Infrastructure / ADCS-PKI

2-Tier PKI Hierarchy with AD CS

Two-tier Microsoft AD CS PKI hierarchy for enterprise certificate issuance and operational control.

Project profile

  • Engagement: Two-tier Microsoft AD CS PKI design and implementation
  • Focus: Root trust, certificate issuance, templates, revocation, protection, and operations
  • Output: PKI hierarchy, build evidence, certificate policy decisions, and recovery procedures

Trust built for operation

Internal systems and devices required a certificate foundation with clearer separation between long-lived trust and day-to-day issuance. The hierarchy had to protect root material while keeping enrollment, revocation, renewal, backup, and support practical.

An offline root CA and enterprise issuing tier were designed with documented roles and controlled administrative procedures. Trust lifecycle was considered from issuance through revocation and recovery.

Foundation coverage

  • Offline root CA protection and controlled use
  • Enterprise issuing CA configuration and permissions
  • Certificate templates, enrollment, renewal, and ownership
  • CRL and authority-information publication paths
  • Key protection, backup, recovery, monitoring, and handover

Decisions recorded

Validity periods, template scope, enrollment rights, publication intervals, administrative roles, and recovery conditions were documented. Root operations used a recorded ceremony so sensitive actions could be repeated and reviewed.

What to be aware of

  • PKI failure can affect many services even when CA servers appear healthy.
  • Revocation paths must remain reachable for relying systems.
  • Template permissions can grant more capability than their names suggest.
  • Backup without protected keys and tested recovery is incomplete.

Outcome

The organization received a documented certificate hierarchy with separated trust roles and clearer operational ownership. Future certificate use could build on a controlled foundation rather than ad hoc issuance.

Evidence of delivery

  • PKI hierarchy and trust design
  • CA build and configuration records
  • Template and permission inventory
  • Revocation-publication validation
  • Backup, recovery, and operations runbooks