Articles

[P 11.1] Build Sheet: Decommissioning an Enterprise CA

By the end of this you have an inventory of everything the old authority issued, its replacements deployed, its ability to authenticate removed, its objects out of the directory, its key accounted for, and a document saying when its revocation list can finally stop. In the order that does not break anything.

[P 11] Retiring a Certificate Authority Without Taking the Estate With It

Uninstalling the role is the fifth of nine steps and the least consequential one. The dangerous part is that certificates outlive the authority that signed them, the directory objects outlive the uninstall on purpose, and the documented procedure is written in an order that will take you down if you follow it literally.

[P 10] Private PKI and the Public Web PKI Are Different Systems

Public certificate lifetimes are collapsing toward 47 days and the question arrives every week: does this mean our certificate authority has to reissue everything monthly. It does not, and the test for which certificates are affected is not the one most people apply.

[P 8] Post-Quantum Signing in AD CS: What ML-DSA Changes and What It Does Not

Your certificate authority can sign with a post-quantum algorithm now. That is a real capability and it is not a migration you can perform, because an authority cannot be converted in place. Here is what ML-DSA actually protects, what it costs in bytes, and why the work is trust distribution rather than cryptography.

[P 7.1] Build Sheet: Signing the Cloud PKI CSR

By the end of this you have a cloud issuing CA anchored to your own hierarchy, trust and SCEP profiles delivered to managed devices, and the subordinate CA template removed again. Plus the step people skip, which fails on the devices you did not test.

[P 7] Where the On-Prem Estate Meets Cloud PKI

Everyone wants to know whether Intune Cloud PKI lets them delete the hierarchy they just built. It deletes NDES. It does not delete the PKI, and if you anchor it to your own root you have just made your annual revocation appointment matter to every managed device you own.