Certificate Authority Design Blueprint
Budget / Salary$30–250
TypeFreelance project
LocationRemote
Posted15 hours ago
I’m planning to stand up an internal public-key infrastructure and need a clear, implementation-ready design for the certificate authority that will sit at its core. The authority must be able to issue two certificate types—SSL/TLS (Domain-Validated) and Client Certificates—and the design has to account for automated certificate management from day one.
Scope
Please translate my high-level requirements into a detailed blueprint that covers:
• A two-tier CA hierarchy with an offline root and online issuing CA(s).
• Policies and procedures for issuing DV SSL/TLS certificates as well as client authentication certificates, including enrollment, approval, revocation, and re-issuance flows.
• Integration points for automated lifecycle management (ACME or an equivalent protocol) so web servers and client devices can request, renew, and revoke certificates without manual intervention.
• Key protection strategies (HSM usage, key sizes, cryptographic algorithms, rotation schedules).
• Availability, backup, and disaster-recovery considerations.
• Compliance artifacts—Certificate Policy (CP), Certification Practice Statement (CPS), and sample subscriber agreements.
• OCSP/CRL design, logging, and audit requirements.
Deliverables
1. Architecture diagram(s) in PDF/PNG plus the editable source (Visio, Draw.io, or similar).
2. A written specification (≈15-25 pages) outlining all components and processes listed above.
3. Example configuration snippets or scripts (OpenSSL, EJBCA, Smallstep, or another suggested CA software) demonstrating automated issuance via ACME.
4. Acceptance checklist so I can validate the build against the design.
Acceptance Criteria
• All functional requirements for DV SSL/TLS and client certificates are covered.
• Automated enrollment and renewal flows are clearly documented and testable.
• Security controls align with current PKI best practices (NIST SP 800-57, CAB Forum baseline).
If anything is unclear, let me know early so we can keep this blueprint precise and actionable.
Scope
Please translate my high-level requirements into a detailed blueprint that covers:
• A two-tier CA hierarchy with an offline root and online issuing CA(s).
• Policies and procedures for issuing DV SSL/TLS certificates as well as client authentication certificates, including enrollment, approval, revocation, and re-issuance flows.
• Integration points for automated lifecycle management (ACME or an equivalent protocol) so web servers and client devices can request, renew, and revoke certificates without manual intervention.
• Key protection strategies (HSM usage, key sizes, cryptographic algorithms, rotation schedules).
• Availability, backup, and disaster-recovery considerations.
• Compliance artifacts—Certificate Policy (CP), Certification Practice Statement (CPS), and sample subscriber agreements.
• OCSP/CRL design, logging, and audit requirements.
Deliverables
1. Architecture diagram(s) in PDF/PNG plus the editable source (Visio, Draw.io, or similar).
2. A written specification (≈15-25 pages) outlining all components and processes listed above.
3. Example configuration snippets or scripts (OpenSSL, EJBCA, Smallstep, or another suggested CA software) demonstrating automated issuance via ACME.
4. Acceptance checklist so I can validate the build against the design.
Acceptance Criteria
• All functional requirements for DV SSL/TLS and client certificates are covered.
• Automated enrollment and renewal flows are clearly documented and testable.
• Security controls align with current PKI best practices (NIST SP 800-57, CAB Forum baseline).
If anything is unclear, let me know early so we can keep this blueprint precise and actionable.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.