Hardware key custody
The key stays inside the boundary.
We help you choose the right HSM model, integrate it with ADCS, run a ceremony your auditors can follow and leave your operators ready to recover it.
Discuss your HSM projectCustody model
Signing crosses the boundary.
The private key does not.
Hardware protection matters because a stolen CA server should not automatically become a stolen CA identity. The design around the device — quorum, backup and recovery — is what makes that promise operational.
Selection criteria
Choose for the operating model — not the brochure.
Workload
Signing rate, key count, latency tolerance and the applications that must integrate.
Custody
Role separation, M-of-N quorum, operator geography and emergency access.
Resilience
High availability, backup model, recovery site and the failure modes the service must survive.
Platform
Network appliance or cloud service, supported CSP/KSP, firmware lifecycle and audit requirements.
Scripted ceremony
Nothing important is improvised in the room.
Approve the script
Commands, expected outputs, roles, rollback conditions and evidence are reviewed before the window.
Establish custody
Named participants authenticate, activate the required quorum and confirm device and partition identity.
Generate or import
The CA key is created inside hardware or migrated through a controlled, documented path.
Verify and recover
Signing, backup and restore paths are tested before the ceremony is closed.
Sign the record
Fingerprints, policy state, custody assignments and exceptions become the auditable handover.
Ceremony includes
What a witnessed ceremony leaves behind.
- ["Pre-approved commands and expected output","Named roles and M-of-N quorum","Witnessed evidence without exposed secrets","Tested backup and recovery","Signed operational handover"]
Integration and migration
Move the key without breaking trust.
We map the current provider, CA service behaviour, certificate chain and recovery path before any migration. Cutover gates prove that the CA can sign, publish and recover while existing certificates continue to validate.
- ["Engagements can cover network HSMs and cloud HSM services that expose supported Microsoft CSP/KSP integrations","Specific vendor and model fit is validated during discovery"]
No manufacturer partnership or endorsement is implied. Recommendations remain vendor-neutral.
Plan an HSM engagement.
Selection, integration, ceremony and handover — scoped to the operating model you actually have.