Files
Compose-Files/Backups/Miker/.trash/Certificate Highlights Architecture Disaster Mitigation.md
T
2026-07-20 09:23:17 -04:00

2.3 KiB

> [!caution] This page contained a drawing which was not converted.

CA will be Windows 2019
Servers, hosted on
existing virtual infrastructure

Version:
ESXi 6.7U3
 
All VMs are on Dell XC6320-6 hardware.

Root CA CBP-NPE-CA1
TNWG01A-V1650
Data Center: NDC

NPE cert Specs:
Key lengths: RSA 2048
Signatures: RSA, SHA256
Encryption: AES256
Crypto Module
Validation: FIPS 140-2

Web CRL services
CBP-EDME-NPE-WES /TNWG01A-V1652
CBP-EDME-NPE-WES2 /TNWG01A-V3454
ldap:///CN=CBP-EDME-NPE-CA[1-9],CN= TNWG01A-V????,CN=CDP,CN=Public Key Services,CN=Services,CN=Configuration,DC=ad,DC=cbp,DC=dhs,DC=gov

CBP-EDME-NPE-CA[2-9]
Sub CA's Location NDC

(8) subordinate Ca's

  • Issue certs to NPEs for device network Authentication
  • Certificate Database from Sub CA's will be backed up to server in NDC
  • CA will host and publish CRL's
  • CA will provide auto-renewal and auto-enrollment where possible

(1) Online Enterprise Root CA

  • Issues Self-Signed Root Certificate - No DHS/FPKI Trust Anchor
  • Issues Subordinate CA Certs for (8) Subordinate CA's
  • Defines certificate issuance policy for Subordinate CA's
  • Member of AD,CBP.DHS.GOV domain, limiting administrative access
    Two Tier Hierarchy:

Root CA

Subordinate CA

Web CRL Service

CBP Internal NPE CA Architecture CBP Internal NPE CA FaultDisaster Mitigation

Scenario1:

CA and CRL loses connectivity
(Power Failure, Natural Disaster
Hardware Failure

Scenario2:

Corruption of CA database

Scenario3:

O/S Software Update or
Other OS level fault

  • Site could be down for up to CRL validity period without negative

effect on network authentication

  • Request for new certs will be answered by CA. This is a feature of auto-enrollment

  • Evert sub CA database is backed up to a server at NDC

  • New VN can be created and CA database restored

  • If unavailable CRL request will be handled by LDAP or 2 Web CRL servers

  • VM snap shot will be taken prior to installing updates. If any issues are

Detected the server can be restored to its original state

  • If corruption of CA server occurs, the server can be rebuilt and the

CA can be restore from backups