Files
Compose-Files/Backups/Miker/.trash/Certificate Highlights Architecture Disaster Mitigation.md
T
2026-07-20 09:23:17 -04:00

85 lines
2.3 KiB
Markdown
Raw Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
\> [!caution] This page contained a drawing which was not converted.
CA will be Windows 2019
Servers, hosted on
existing virtual infrastructure
Version:
ESXi 6.7U3
 
All VMs are on Dell XC6320-6 hardware.
**Root CA CBP-NPE-CA1**
**TNWG01A-V1650**
**Data Center: NDC**
**NPE cert Specs:**
**Key lengths: RSA 2048**
**Signatures: RSA, SHA256**
**Encryption: AES256**
**Crypto Module**
**Validation: FIPS 140-2**
**Web CRL services**
**CBP-EDME-NPE-WES /TNWG01A-V1652**
**CBP-EDME-NPE-WES2 /TNWG01A-V3454**
**ldap:///CN=CBP-EDME-NPE-CA[1-9],CN= TNWG01A-V????,CN=CDP,CN=Public Key Services,CN=Services,CN=Configuration,DC=ad,DC=cbp,DC=dhs,DC=gov**
CBP-EDME-NPE-CA[2-9]
Sub CA's Location NDC
**(8) subordinate Ca's**
- **Issue certs to NPEs for device network Authentication**
- **Certificate Database from Sub CA's will be backed up to server in NDC**
- **CA will host and publish CRL's**
- **CA will provide auto-renewal and auto-enrollment where possible**
(1) Online Enterprise Root CA
- Issues Self-Signed Root Certificate - No DHS/FPKI Trust Anchor
- Issues Subordinate CA Certs for (8) Subordinate CA's
- Defines certificate issuance policy for Subordinate CA's
- Member of AD,CBP.DHS.GOV domain, limiting administrative access
**Two Tier Hierarchy:**
Root CA
Subordinate CA
Web CRL Service
![CBP Internal NPE CA Architecture](Exported%20image%2020250808202551-0.png) ![CBP Internal NPE CA FaultDisaster Mitigation](Exported%20image%2020250808202551-1.png)
Scenario1:
CA and CRL loses connectivity
(Power Failure, Natural Disaster
Hardware Failure
Scenario2:
Corruption of CA database
Scenario3:
O/S Software Update or
Other OS level fault
- Site could be down for up to CRL validity period without negative
effect on network authentication
- Request for new certs will be answered by CA. This is a feature of auto-enrollment
- Evert sub CA database is backed up to a server at NDC
- New VN can be created and CA database restored
- If unavailable CRL request will be handled by LDAP or 2 Web CRL servers
- VM snap shot will be taken prior to installing updates. If any issues are
Detected the server can be restored to its original state
- If corruption of CA server occurs, the server can be rebuilt and the
CA can be restore from backups