\> [!caution] This page contained a drawing which was not converted. CA will be Windows 2019 Servers, hosted on existing virtual infrastructure Version: ESXi 6.7U3   All VMs are on Dell XC6320-6 hardware. **Root CA CBP-NPE-CA1** **TNWG01A-V1650** **Data Center: NDC** **NPE cert Specs:** **Key lengths: RSA 2048** **Signatures: RSA, SHA256** **Encryption: AES256** **Crypto Module** **Validation: FIPS 140-2** **Web CRL services** **CBP-EDME-NPE-WES /TNWG01A-V1652** **CBP-EDME-NPE-WES2 /TNWG01A-V3454** **ldap:///CN=CBP-EDME-NPE-CA[1-9],CN= TNWG01A-V????,CN=CDP,CN=Public Key Services,CN=Services,CN=Configuration,DC=ad,DC=cbp,DC=dhs,DC=gov** CBP-EDME-NPE-CA[2-9] Sub CA's Location NDC **(8) subordinate Ca's** - **Issue certs to NPEs for device network Authentication** - **Certificate Database from Sub CA's will be backed up to server in NDC** - **CA will host and publish CRL's** - **CA will provide auto-renewal and auto-enrollment where possible** (1) Online Enterprise Root CA - Issues Self-Signed Root Certificate - No DHS/FPKI Trust Anchor - Issues Subordinate CA Certs for (8) Subordinate CA's - Defines certificate issuance policy for Subordinate CA's - Member of AD,CBP.DHS.GOV domain, limiting administrative access **Two Tier Hierarchy:** Root CA Subordinate CA Web CRL Service ![CBP Internal NPE CA Architecture](Exported%20image%2020250808202551-0.png) ![CBP Internal NPE CA FaultDisaster Mitigation](Exported%20image%2020250808202551-1.png) Scenario1: CA and CRL loses connectivity (Power Failure, Natural Disaster Hardware Failure Scenario2: Corruption of CA database Scenario3: O/S Software Update or Other OS level fault - Site could be down for up to CRL validity period without negative effect on network authentication - Request for new certs will be answered by CA. This is a feature of auto-enrollment - Evert sub CA database is backed up to a server at NDC - New VN can be created and CA database restored - If unavailable CRL request will be handled by LDAP or 2 Web CRL servers - VM snap shot will be taken prior to installing updates. If any issues are Detected the server can be restored to its original state - If corruption of CA server occurs, the server can be rebuilt and the CA can be restore from backups