Files
Compose-Files/Backups/Miker/.trash/Certificate Highlights Architecture Disaster Mitigation.md
2026-07-20 09:23:17 -04:00

85 lines
2.3 KiB
Markdown
Raw Permalink Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
\> [!caution] This page contained a drawing which was not converted.
CA will be Windows 2019
Servers, hosted on
existing virtual infrastructure
Version:
ESXi 6.7U3
 
All VMs are on Dell XC6320-6 hardware.
**Root CA CBP-NPE-CA1**
**TNWG01A-V1650**
**Data Center: NDC**
**NPE cert Specs:**
**Key lengths: RSA 2048**
**Signatures: RSA, SHA256**
**Encryption: AES256**
**Crypto Module**
**Validation: FIPS 140-2**
**Web CRL services**
**CBP-EDME-NPE-WES /TNWG01A-V1652**
**CBP-EDME-NPE-WES2 /TNWG01A-V3454**
**ldap:///CN=CBP-EDME-NPE-CA[1-9],CN= TNWG01A-V????,CN=CDP,CN=Public Key Services,CN=Services,CN=Configuration,DC=ad,DC=cbp,DC=dhs,DC=gov**
CBP-EDME-NPE-CA[2-9]
Sub CA's Location NDC
**(8) subordinate Ca's**
- **Issue certs to NPEs for device network Authentication**
- **Certificate Database from Sub CA's will be backed up to server in NDC**
- **CA will host and publish CRL's**
- **CA will provide auto-renewal and auto-enrollment where possible**
(1) Online Enterprise Root CA
- Issues Self-Signed Root Certificate - No DHS/FPKI Trust Anchor
- Issues Subordinate CA Certs for (8) Subordinate CA's
- Defines certificate issuance policy for Subordinate CA's
- Member of AD,CBP.DHS.GOV domain, limiting administrative access
**Two Tier Hierarchy:**
Root CA
Subordinate CA
Web CRL Service
![CBP Internal NPE CA Architecture](Exported%20image%2020250808202551-0.png) ![CBP Internal NPE CA FaultDisaster Mitigation](Exported%20image%2020250808202551-1.png)
Scenario1:
CA and CRL loses connectivity
(Power Failure, Natural Disaster
Hardware Failure
Scenario2:
Corruption of CA database
Scenario3:
O/S Software Update or
Other OS level fault
- Site could be down for up to CRL validity period without negative
effect on network authentication
- Request for new certs will be answered by CA. This is a feature of auto-enrollment
- Evert sub CA database is backed up to a server at NDC
- New VN can be created and CA database restored
- If unavailable CRL request will be handled by LDAP or 2 Web CRL servers
- VM snap shot will be taken prior to installing updates. If any issues are
Detected the server can be restored to its original state
- If corruption of CA server occurs, the server can be rebuilt and the
CA can be restore from backups