migrate
This commit is contained in:
@@ -0,0 +1,85 @@
|
||||
\> [!caution] This page contained a drawing which was not converted.
|
||||
|
||||
CA will be Windows 2019
|
||||
Servers, hosted on
|
||||
existing virtual infrastructure
|
||||
|
||||
Version:
|
||||
ESXi 6.7U3
|
||||
|
||||
All VMs are on Dell XC6320-6 hardware.
|
||||
|
||||
**Root CA CBP-NPE-CA1**
|
||||
**TNWG01A-V1650**
|
||||
**Data Center: NDC**
|
||||
|
||||
**NPE cert Specs:**
|
||||
**Key lengths: RSA 2048**
|
||||
**Signatures: RSA, SHA256**
|
||||
**Encryption: AES256**
|
||||
**Crypto Module**
|
||||
**Validation: FIPS 140-2**
|
||||
|
||||
**Web CRL services**
|
||||
**CBP-EDME-NPE-WES /TNWG01A-V1652**
|
||||
**CBP-EDME-NPE-WES2 /TNWG01A-V3454**
|
||||
**ldap:///CN=CBP-EDME-NPE-CA[1-9],CN= TNWG01A-V????,CN=CDP,CN=Public Key Services,CN=Services,CN=Configuration,DC=ad,DC=cbp,DC=dhs,DC=gov**
|
||||
|
||||
CBP-EDME-NPE-CA[2-9]
|
||||
Sub CA's Location NDC
|
||||
|
||||
**(8) subordinate Ca's**
|
||||
|
||||
- **Issue certs to NPEs for device network Authentication**
|
||||
- **Certificate Database from Sub CA's will be backed up to server in NDC**
|
||||
- **CA will host and publish CRL's**
|
||||
- **CA will provide auto-renewal and auto-enrollment where possible**
|
||||
|
||||
(1) Online Enterprise Root CA
|
||||
|
||||
- Issues Self-Signed Root Certificate - No DHS/FPKI Trust Anchor
|
||||
- Issues Subordinate CA Certs for (8) Subordinate CA's
|
||||
- Defines certificate issuance policy for Subordinate CA's
|
||||
- Member of AD,CBP.DHS.GOV domain, limiting administrative access
|
||||
**Two Tier Hierarchy:**
|
||||
|
||||
Root CA
|
||||
|
||||
Subordinate CA
|
||||
|
||||
Web CRL Service
|
||||
|
||||
 
|
||||
|
||||
Scenario1:
|
||||
|
||||
CA and CRL loses connectivity
|
||||
(Power Failure, Natural Disaster
|
||||
Hardware Failure
|
||||
|
||||
Scenario2:
|
||||
|
||||
Corruption of CA database
|
||||
|
||||
Scenario3:
|
||||
|
||||
O/S Software Update or
|
||||
Other OS level fault
|
||||
|
||||
- Site could be down for up to CRL validity period without negative
|
||||
|
||||
effect on network authentication
|
||||
|
||||
- Request for new certs will be answered by CA. This is a feature of auto-enrollment
|
||||
|
||||
- Evert sub CA database is backed up to a server at NDC
|
||||
- New VN can be created and CA database restored
|
||||
- If unavailable CRL request will be handled by LDAP or 2 Web CRL servers
|
||||
|
||||
- VM snap shot will be taken prior to installing updates. If any issues are
|
||||
|
||||
Detected the server can be restored to its original state
|
||||
|
||||
- If corruption of CA server occurs, the server can be rebuilt and the
|
||||
|
||||
CA can be restore from backups
|
||||
Reference in New Issue
Block a user