Category PKI

On-premises public key infrastructure with Active Directory Certificate Services: hierarchy design, revocation, templates, and operations.

[P 2.1] Build Sheet: The Offline Root CA

By the end of this you have a standalone offline root certificate authority built, its policy file and distribution points fixed before anything is signed, its first revocation list published with a year of margin, and its certificate and CRL exported ready for the web servers.

[P 2] The Offline Root: Designing for a Machine That Is Almost Never On

A root certificate authority spends its life switched off, which sounds like the end of its operational story and is actually the whole of it. What offline really means, why the root leaves the domain, and why its revocation list is the only deadline in your PKI that can take the estate down.

[P 1] Why You Still Run a Private CA, and What Two Tiers Actually Buy

A private PKI is an authority structure, not a server role, and a short list of its decisions are permanent from the moment the first certificate is signed. Here is what a two-tier hierarchy actually buys, what an offline root does not buy, and why AD CS is not going anywhere in 2026.