2.3 KiB
> [!caution] This page contained a drawing which was not converted.
CA will be Windows 2019
Servers, hosted on
existing virtual infrastructure
Version:
ESXi 6.7U3
All VMs are on Dell XC6320-6 hardware.
Root CA CBP-NPE-CA1
TNWG01A-V1650
Data Center: NDC
NPE cert Specs:
Key lengths: RSA 2048
Signatures: RSA, SHA256
Encryption: AES256
Crypto Module
Validation: FIPS 140-2
Web CRL services
CBP-EDME-NPE-WES /TNWG01A-V1652
CBP-EDME-NPE-WES2 /TNWG01A-V3454
ldap:///CN=CBP-EDME-NPE-CA[1-9],CN= TNWG01A-V????,CN=CDP,CN=Public Key Services,CN=Services,CN=Configuration,DC=ad,DC=cbp,DC=dhs,DC=gov
CBP-EDME-NPE-CA[2-9]
Sub CA's Location NDC
(8) subordinate Ca's
- Issue certs to NPEs for device network Authentication
- Certificate Database from Sub CA's will be backed up to server in NDC
- CA will host and publish CRL's
- CA will provide auto-renewal and auto-enrollment where possible
(1) Online Enterprise Root CA
- Issues Self-Signed Root Certificate - No DHS/FPKI Trust Anchor
- Issues Subordinate CA Certs for (8) Subordinate CA's
- Defines certificate issuance policy for Subordinate CA's
- Member of AD,CBP.DHS.GOV domain, limiting administrative access
Two Tier Hierarchy:
Root CA
Subordinate CA
Web CRL Service
Scenario1:
CA and CRL loses connectivity
(Power Failure, Natural Disaster
Hardware Failure
Scenario2:
Corruption of CA database
Scenario3:
O/S Software Update or
Other OS level fault
- Site could be down for up to CRL validity period without negative
effect on network authentication
-
Request for new certs will be answered by CA. This is a feature of auto-enrollment
-
Evert sub CA database is backed up to a server at NDC
-
New VN can be created and CA database restored
-
If unavailable CRL request will be handled by LDAP or 2 Web CRL servers
-
VM snap shot will be taken prior to installing updates. If any issues are
Detected the server can be restored to its original state
- If corruption of CA server occurs, the server can be rebuilt and the
CA can be restore from backups

