← Back to Projects
Business Systems House 2025
Public Key Infrastructure (PKI) & Internal Certificate Authority (CA)
Active Directory Certificate Services (ADCS) PKI X.509 Certificates CRL Auto-Enrollment
Public Key Infrastructure (PKI) & Internal Certificate Authority (CA)
Deployed an enterprise two-tier PKI architecture to issue, manage, and revoke internal X.509 digital certificates across domain devices.
Key Features & Implementation
- Two-Tier Hierarchy: Isolated offline Root Certificate Authority with an online subordinate Issuing CA joined to Active Directory.
- Automated Certificate Auto-Enrollment: Configured Group Policy auto-enrollment templates for workstation SSL, IPsec, and Wi-Fi authentication.
- CRL & OCSP Revocation Distribution: Published high-availability Certificate Revocation Lists (CRLs) and Online Responder endpoints.