Digi-Sign, The Certificate Corporation
Published on Digi-Sign, The Certificate Corporation (https://www.digi-sign.com)

Home > Installations Time Lines

By Digi-Sign
Created Jun 12 2008 - 11:16

Installations Time Lines

Sample Digi-CA™ Installations

PDF [1] The flexibility of the Digi-CA™ [2] Certificate Authority [CA] system design means that each installation is unique and customised to the precise needs of the customer. Once the Digi-CAST™ [3] Team have agreed and documented your requirements, your Managed CA [4], Digi-CA™ Service or CA Software [5], Digi-CA™ Server, is configured and activated. In certain projects, your specific needs may require a combination of CA Software and a Managed CA, to achieve the best results. Uniquely and unlike any other Traditional CA [6] system on the market, Digi-CA™ can offer the Shared CA [7] option.

The following are samples of different CA projects that use the different Digi-CA™ options and also combine other valuable services like the Digi-CAST™ Methodology [3] and consulting advice; the Total Trust Management™ [8] [TTM™] CA Management service; and the Digi-TaSC [9] on line system for CA Management and compliance.

Certificate Authority [CA] Implementation Plan

Sample Digi-CA™ Implementation Plan

The most substantial difference between Digi-CA™ and other Traditional CA [6]s is the flexibility and capabilities that are central to the design of the Public Key Infrastructure [PKI] system. This means that virtually any type of PKI design can be implemented using Digi-CA™ and because Digi-CA™ is probably the most modern CA available on the market, your specific design requirements can be delivered easily and cost effectively.

The following sub sections provide details of a typical project implementation and its stages. The Preliminary Analysis & Requirement Measurement stage of the project (stage I) is the first stage and this sets the project parameters and requirements from the very beginning of your project:

        • 1. Preliminary Analysis & Requirement Measurement
        • 2. Trust Centre Setup
        • 3. Configuring Multi-Site LDAP Directory Services & LDAP Replication
        • 4. CA Hierarchy & PKI Logical Infrastructure Setup
        • 5. System Integration & Integration Testing
        • 6. Disaster Recovery Setup
        • 7. Functional, Operational & User Acceptability Testing [UAT]
        • 8. Training
        • 9. Production Launch


  • Preliminary Analysis & Requirement Measurement
    • 1. In depth analysis and understanding of the concepts, functional and business requirements
    • 2. In depth Digi-CAST™ analysis of existing application functional layers and associated data flow models and diagrams and understanding the concepts, functional and business requirements
    • 3. Digi-CAST™ - understanding architectural and functional model for the certificate enrolment and installation processes
    • 4. Digi-CAST™ establishing the requirements for Key Ceremony
    • 5. Digi-CAST™ reviewing and defining the Certification Practice Statement (if required) and associated Certificate Policy
    • 6. Digi-CAST™ establishing whether Digi-CA™ PKI System requires any related customisations to support specific functional and business requirements through the use of application APIs and custom policy controls
    • 7. Providing detailed information on performed analysis, measurements and discoveries in a form of a Digi-CAST™ report


  • Trust Centre Setup
    • 1. Setup of a dedicated Digi-CA™ PKI system hardware and software infrastructure in a secure hosting data centre
    • 2. General testing of new hardware, software and network setup
    • 3. High availability testing of new hardware, software and network setup
    • 4. Backup and recovery tests of new software and network setup
    • 5. Performance testing of new hardware, software and network setup
    • 6. Finalising the setup and providing with detailed information on performed activities and test results in the form of a Digi-CAST™ report


  • Configuring Multi-Site LDAP Directory Services & LDAP Replication
    • 1. Establishing a dedicated secure network channel between the new Trust Centre and local computer centres at two locations
    • 2. Testing the performance and security of the network communication channel between the Trust Centre and each office location
    • 3. Installing and configuring LDAP directory service hardware and software for high availability in the local computer centres
    • 4. Setting up directory replication service [shadow: single-master/multiple-slave replication scheme] between the master LDAP directory service located in the Trust Centre and each slave local LDAP directory service located in each of the computer centres
    • 5. Testing the directory live replication service and high availability mechanisms
    • 6. Performance testing for directory replication service and high availability setup
    • 7. Finalising the setup and providing detailed information on performed activities and test results in the form of a Digi-CAST™ report


  • CA Hierarchy & PKI Logical Infrastructure Setup
    • 1. Performing a dry-run for Key Ceremony (if required) for CA and Sub-CA
    • 2. Performing a Key Ceremony (if required) for CA and Sub-CA and establishing new CA hierarchy
    • 3. Creating test instances of CA and Sub-CA private key and public key certificate data (for the period of test use only)
    • 4. Finalizing the new CA setup and providing with detailed information on performed activities and verification results in the form of a Digi-CAST™ report


  • System Integration & Integration Testing
    • 1. Providing the necessary API integration services for application integration with Digi-CA™ PKI System Registration Authority and Certificate Distribution services
    • 2. Providing the necessary API integration services for application integration for certificate enrolment and installation
    • 3. Providing the necessary API integration services for X.500 directory service integration
    • 4. Providing the necessary API integration services for CRL and OCSP service integration
    • 5. Finalizing the integration and providing with detailed information on performed activities and integration results in the form of a Digi-CAST™ report


s

  • Disaster Recovery Setup
    • 1. Setup of basic and supplemental PKI services with software and hardware for disaster recovery in computer centres
    • 2. Testing disaster recovery features and performing disaster recovery simulation tests
    • 3. Finalising the setup and providing detailed information on performed activities, setup and tests results in the form of a Digi-CAST™ report


  • Functional, Operational & User Acceptability Testing [UAT]
    • 1. End user key generation, certificate enrolment and installation tests
    • 2. Integration testing for application and Digi-CA™ PKI System Registration Authority Service
    • 3. Integration testing for application and Digi-CA™ PKI System X.500 directory services
    • 4. End user private key and public key certificate usability tests with applications
    • 5. End user public key certificate standard life cycle tests including certificate renewal after certificate expiration
    • 6. End user public key certificate custom life cycle tests including certificate revocation, suspension and de-suspension
    • 7. End user public key certificate life cycle test including certificate re-issuance after certificate revocation
    • 8. Integration testing for application and Digi-CA™ PKI System CRL and OCSP services
    • 9. Finalizing the test phase and providing with detailed information on performed activities and test results in a form of Digi-CAST™ report


  • Training
    • 1. Provision of comprehensive Digi-CA™ PKI System documentation in digital and paper format
    • 2. CA Administration staff training
    • 3. CA Security Administration staff training
    • 4. RA Administration staff training
    • 5. RA Operation staff training
    • 6. Finalizing the training phase and providing with detailed information on performed activities and test results in the form of a Digi-CAST™ report;


  • Production Launch
    • 1. Switching CA hierarchy from test to production environment
    • 2. Finalizing production launch and providing detailed information on performed activities along with a summarized report for each phase of the project implementation in the form of a Digi-CAST™ report


Existing CA Transition Plan

Sample Digi-CA™ Transition Plan

The most substantial difference between Digi-CA™ [2] and other Traditional CA [6]s is the flexibility and capabilities that are central to the design of the PKI system. This capability of transferring from a different service provider is a powerful capability that is simply not available from alternative vendor.

Digi-CA™ allows for easy migration from one data centre, or system, in an almost seamless manner. The transfer can be accomplished either physically through hardware transportation or by secure software and data migration whereby all software and database data is securely migrated in an encrypted format from one location to another.

The following sub sections provide details of the suggested project implementation stages for the transition plan. The plan is subject to decision on the re-use of existing HSMs, or the export/import of existing CA private keys and other project implementation considerations that will emerge during the Preliminary Analysis & Requirement Measurement stage of the project (stage I):

        • 1. Preliminary Analysis & Requirement Measurement
        • 2. Trust Centre Setup
        • 3. Configuring Multi-Site LDAP Directory Services & LDAP Replication
        • 4. CA Hierarchy & PKI Logical Infrastructure Setup
        • 5. PKI Data Transfer & Existing Information Migration
        • 6. System Integration & Integration Testing
        • 7. Disaster Recovery Setup
        • 8. Functional, Operational & User Acceptability Testing [UAT]
        • 9. Training
        • 10. Production Launch


  • Preliminary Analysis & Requirement Measurement
    • 1. In depth Digi-CAST™ [3] analysis of existing software and hardware architecture - understanding the concepts, the functional and the business requirements
    • 2. In depth Digi-CAST™ analysis of existing application functional layers and associated data flow models and diagrams – understanding the concepts, functional and business requirements
    • 3. In depth Digi-CAST™ analysis of existing application communication layers and associated data flow models and diagrams – understanding the concepts, functional and business requirements
    • 4. Digi-CAST™ - understanding architectural and functional model for the use of the current PKI system along with current certificate enrolment and installation processes
    • 5. Digi-CAST™ - establishing the requirements for Key Ceremony
    • 6. Digi-CAST™ - establishing whether existing software, hardware and PKI architecture in combination with existing application functional and communication layers has any weaknesses and whether requires updates, modifications or improvements in respect to current commercial IT and PKI standards in common use
    • 7. Digi-CAST™ - reviewing and re-defining existing Certification Practice Statement [CPS] (if required) and associated Certificate Policy [CP]
    • 8. Digi-CAST™ - defining the methodology and procedural mechanism for PKI data transfer from the existing PKI system to the new Digi-CA™ PKI System
    • 9. Digi-CAST™ - establishing whether Digi-CA™ PKI System requires any related customisations to support specific functional and business requirements through the use of application APIs and custom policy controls
    • 10. Providing with detailed information on performed analysis, measurements and discoveries in a form of a Digi-CAST™ report


  • Trust Centre Setup
    • 1. Setup of a dedicated Digi-CA™ PKI system hardware and software infrastructure in a secure hosting data centre
    • 2. General testing of new hardware, software and network setup
    • 3. High availability testing of new hardware, software and network setup
    • 4. Backup and recovery tests of new software and network setup
    • 5. Performance testing of new hardware, software and network setup
    • 6. Finalising the setup and providing with detailed information on performed activities and test results in a form of Digi-CAST™ report


  • Configuring Multi-Site LDAP Directory Services & LDAP Replication
    • 1. Establishing a dedicated secure network channel between Trust Centre and local computer centres at two locations
    • 2. Testing the performance and security of the network communication channel between the Trust Centre [10] and each office location
    • 3. Installing and configuring LDAP directory service hardware and software for high availability in the local computer centres
    • 4. Setting up directory replication service [shadow: single-master/multiple-slave replication scheme] between the master LDAP directory service located in the Trust Centre and each slave local LDAP directory service located in each of the computer centres
    • 5. Testing the directory live replication service and high availability mechanisms
    • 6. Performance testing for directory replication service and high availability setup
    • 7. Finalizing the setup and providing with detailed information on performed activities and test results in a form of Digi-CAST™ report


  • CA Hierarchy & PKI Logical Infrastructure Setup
    • 1. Performing a dry-run for Key Ceremony (if required) for CA and CA
    • 2. Performing a Key Ceremony (if required) for CA and CA and establishing new CA hierarchy
    • 3. Creating test instances of CA and CA private key and public key certificate data (for the period of test use only)
    • 4. Finalising the new CA setup and providing with detailed information on performed activities and verification results in a form of Digi-CAST™ report


  • PKI Data Transfer & Existing Information Migration
    • 1. PKI Data Testing
    • 2. Testing existing data
    • 3. Finalising the transfer and providing with detailed information on performed activities and verification results in a form of Digi-CAST™ report


  • System Integration & Integration Testing
    • 1. Providing with necessary API integration services for application integration with Digi-CA™ PKI System Registration Authority and Certificate Distribution services
    • 2. Providing with necessary API integration services for application integration for certificate enrolment and installation
    • 3. Providing with necessary API integration services for X.500 directory service integration
    • 4. Providing with necessary API integration services for CRL and OCSP service integration
    • 5. Finalising the integration and providing with detailed information on performed activities and integration results in a form of Digi-CAST™ report


  • Disaster Recovery Setup
    • 1. Setup of basic and supplemental PKI services with software and hardware for disaster recovery in computer centres
    • 2. Testing disaster recovery features and performing a disaster recovery simulation tests
    • 3. Finalising the setup and providing with detailed information on performed activities, setup and tests results in a form of Digi-CAST™ report


  • Functional, Operational & User Acceptability Testing [UAT]
    • 1. End user key generation, certificate enrolment and installation tests
    • 2. Integration testing for application and Digi-CA™ PKI System Registration Authority Service
    • 3. Integration testing for application and Digi-CA™ PKI System X.500 directory services
    • 4. End user private key and public key certificate usability tests with applications
    • 5. End user public key certificate standard life cycle tests including certificate renewal after certificate expiration
    • 6. End user public key certificate custom life cycle tests including certificate revocation, suspension and de-suspension
    • 7. End user public key certificate life cycle test including certificate re-issuance after certificate revocation
    • 8. Integration testing for application and Digi-CA™ PKI System CRL and OCSP services
    • 9. Finalising the test phase and providing with detailed information on performed activities and test results in a form of Digi-CAST™ report


  • Training
    • 1. Provision of comprehensive Digi-CA™ PKI System documentation [11] in digital and paper format
    • 2. CA Administration staff training
    • 3. CA Security Administration staff training
    • 4. RA Administration staff training
    • 5. RA Operation staff training
    • 6. Finalizing the training phase and providing with detailed information on performed activities and test results in a form of Digi-CAST™ report;


  • Production Launch
    • 1. Switching CA hierarchy from test to production environment; Estimated time: 1 day
    • 2. Finalizing production launch and providing with detailed information on performed activities along with a summarized report for each phase of the project implementation in a form of Digi-CAST™ report


Certificate Authority [CA] Implementation Plan

Sample Digi-CA™ Implementation Plan

The most substantial difference between Digi-CA™ [2] and other Traditional CA [6]s is the flexibility and capabilities that are central to the design of the PKI system. This capability of transferring from a different service provider is a powerful capability that is simply not available from alternative vendor.

Digi-CA™ allows for easy migration from one data centre, or system, in an almost seamless manner. The transfer can be accomplished either physically through hardware transportation or by secure software and data migration whereby all software and database data is securely migrated in an encrypted format from one location to another.

The following sub sections provide details of the suggested project implementation stages for the transition plan. The plan is subject to decision on the re-use of existing HSMs, or the export/import of existing CA private keys and other project implementation considerations that will emerge during the Preliminary Analysis & Requirement Measurement stage of the project (stage I):

        • 1. Preliminary Analysis & Requirement Measurement
        • 2. Trust Centre Setup
        • 3. Configuring Multi-Site LDAP Directory Services & LDAP Replication
        • 4. CA Hierarchy & PKI Logical Infrastructure Setup
        • 5. PKI Data Transfer & Existing Information Migration
        • 6. System Integration & Integration Testing
        • 7. Disaster Recovery Setup
        • 8. Functional, Operational & User Acceptability Testing [UAT]
        • 9. Training
        • 10. Production Launch


  • Preliminary Analysis & Requirement Measurement
    • 1. In depth Digi-CAST™ [3] analysis of existing software and hardware architecture – understanding the concepts, functional and business requirements
    • 2. In depth Digi-CAST™ analysis of existing application functional layers and associated data flow models and diagrams – understanding the concepts, functional and business requirements
    • 3. In depth Digi-CAST™ analysis of existing application communication layers and associated data flow models and diagrams – understanding the concepts, functional and business requirements
    • 4. Digi-CAST™ - understanding architectural and functional model for the use of the current PKI system along with current certificate enrolment and installation processes
    • 5. Digi-CAST™ - establishing the requirements for Key Ceremony
    • 6. Digi-CAST™ - establishing whether existing software, hardware and PKI architecture in combination with existing application functional and communication layers has any weaknesses and whether requires updates, modifications or improvements in respect to current commercial IT and PKI standards in common use
    • 7. Digi-CAST™ - reviewing and re-defining existing Certification Practice Statement (if required) and associated Certificate Policies
    • 8. Digi-CAST™ - defining the methodology and procedural mechanism for PKI data transfer from the existing PKI system to the new Digi-CA™ PKI System
    • 9. Digi-CAST™ - establishing whether Digi-CA™ PKI System requires any related customizations to support specific functional and business requirements through the use of application APIs and custom policy controls
    • 10. Providing with detailed information on performed analysis, measurements and discoveries in a form of a Digi-CAST™ report


  • Trust Centre Setup
    • 1. Setup of a dedicated Digi-CA™ PKI system hardware and software infrastructure in a secure hosting data centre
    • 2. General testing of new hardware, software and network setup
    • 3. High availability testing of new hardware, software and network setup
    • 4. Backup and recovery tests of new software and network setup
    • 5. Performance testing of new hardware, software and network setup
    • 6. Finalizing the setup and providing with detailed information on performed activities and test results in a form of Digi-CAST™ report


  • Configuring Multi-Site LDAP Directory Services & LDAP Replication
    • 1. Establishing a dedicated secure network channel between Trust Centre and local computer centres at two locations
    • 2. Testing the performance and security of the network communication channel between the Trust Centre [10] and each office location
    • 3. Installing and configuring LDAP directory service hardware and software for high availability in the local computer centres
    • 4. Setting up directory replication service [shadow: single-master/multiple-slave replication scheme] between the master LDAP directory service located in the Trust Centre and each slave local LDAP directory service located in each of the computer centres
    • 5. Testing the directory live replication service and high availability mechanisms
    • 6. Performance testing for directory replication service and high availability setup
    • 7. Finalizing the setup and providing with detailed information on performed activities and test results in a form of Digi-CAST™ report


  • CA Hierarchy & PKI Logical Infrastructure Setup
    • 1. Performing a dry-run for Key Ceremony (if required) for CA and CA
    • 2. Performing a Key Ceremony (if required) for CA and CA and establishing new CA hierarchy
    • 3. Creating test instances of CA and CA private key and public key certificate data (for the period of test use only)
    • 4. Finalizing the new CA setup and providing with detailed information on performed activities and verification results in a form of Digi-CAST™ report


  • PKI Data Transfer & Existing Information Migration
    • 1. PKI Data Testing
    • 2. Testing existing data
    • 3. Finalizing the transfer and providing with detailed information on performed activities and verification results in a form of Digi-CAST™ report


  • System Integration & Integration Testing
    • 1. Providing with necessary API integration services for application integration with Digi-CA™ PKI System Registration Authority and Certificate Distribution services
    • 2. Providing with necessary API integration services for application integration for certificate enrolment and installation
    • 3. Providing with necessary API integration services for X.500 directory service integration
    • 4. Providing with necessary API integration services for CRL and OCSP service integration
    • 5. Finalizing the integration and providing with detailed information on performed activities and integration results in a form of Digi-CAST™ report


  • Disaster Recovery Setup
    • 1. Setup of basic and supplemental PKI services with software and hardware for disaster recovery in computer centres
    • 2. Testing disaster recovery features and performing a disaster recovery simulation tests
    • 3. Finalizing the setup and providing with detailed information on performed activities, setup and tests results in a form of Digi-CAST™ report


  • Functional, Operational & User Acceptability Testing [UAT]
    • 1. End user key generation, certificate enrolment and installation tests
    • 2. Integration testing for application and Digi-CA™ PKI System Registration Authority Service
    • 3. Integration testing for application and Digi-CA™ PKI System X.500 directory services
    • 4. End user private key and public key certificate usability tests with applications
    • 5. End user public key certificate standard life cycle tests including certificate renewal after certificate expiration
    • 6. End user public key certificate custom life cycle tests including certificate revocation, suspension and de-suspension
    • 7. End user public key certificate life cycle test including certificate re-issuance after certificate revocation
    • 8. Integration testing for application and Digi-CA™ PKI System CRL and OCSP services
    • 9. Finalizing the test phase and providing with detailed information on performed activities and test results in a form of Digi-CAST™ report


  • Training
    • 1. Provision of comprehensive Digi-CA™ PKI System documentation [11] in digital and paper format
    • 2. CA Administration staff training
    • 3. CA Security Administration staff training
    • 4. RA Administration staff training
    • 5. RA Operation staff training
    • 6. Finalizing the training phase and providing with detailed information on performed activities and test results in a form of Digi-CAST™ report


  • Production Launch
    • 1. Switching CA hierarchy from test to production environment
    • 2. Finalizing production launch and providing with detailed information on performed activities along with a summarized report for each phase of the project implementation in a form of Digi-CAST™ report


Certificate Authority [CA] Implementation Schedule

Sample Digi-CA™ Timetable

Digi-CA™ [2] is probably the most modern Certificate Authority [CA] system currently available in the market. It is modern because it leverages the many advances in open source technology including Linux, SQL and PHP.

Unlike Traditional CA [6]s, the Digi-CA™ system can create multiple instances of unique CAs in a single Digi-CAtrade; system. The Digi-CAtrade; model imposes delegation of trust downwards from CAs to their Subordinate Certification Authorities [Sub-CAs].

The same Digi-CAtrade; system also enables any CA or Sub-CA to be signed or cross signed by an external third party CA. And any number of CAs can have any number of cross signed Sub-CAs. As a result of this design principal, the Digi-CAtrade; model for trust levels increases towards the highest authority. This type of arrangement facilitates easy deployment and scalability of any PKI requirement from the smallest to the largest.

The following provides a high level overview of a typical Digi-CAtrade; Server installation at a Trust Centre [10]:

The Digi-CAST2™ [3] Team will install the Digi-CA™ PKI software and to do this the first data centre must be constructed 100%. This must include all power, cabling, fire detection, fire depressant and that the air conditioning is installed and fully tested. The air conditioning system testing is very important, as it can cause water issues if not fully tested.

The Trust Centre must then be cleaned to medical/hospital standards before any hardware is installed. The construction on the second disaster recovery data centre (if required) should start at the same time, or no more than two weeks after the first data centre. It is not required that this Disaster Recovery data centre is completed before the Digi-CAST2™ Team arrive at the Trust Centre, however it must be finished no later than one week after the Digi-CAST2™ Team arrive on site and again must be 100% finished and cleaned in that time.

Nothing will happen with the Digi-CA™ PKI software installation until the Trust Centre completion and cleaning date is confirmed. Once this date is confirmed and the hardwre is ordered, the Partner [12] should be capable fo getting all the servers, switches, network and server software, HSMs, etc delivered within 2-3 weeks of the contract being signed.

After the contract is signed the Trust Centre should be ready so that the installation of the IT infrastructure can be completed within 1 week. By the beginnning of week 4, the entire of the main Trust Centre is active and ready for the installation of the Digi-CA™ software.

Week 5 the Disaster Recovery data centre should be completed and the the Digi-CAST2 Installations Team will then arrive to begin work on the Trust Centre whilst the Digi-Trust™ Partner [12] to complete the second data centre IT infrastructutre totally and ready in one week so that by week 6, the second week for the the Digi-CAST2 Installations Team on site, they can begin the configuration of this Disaster Recovery Digi-CA™.

In week 7, after the contract is signed, the Digi-CAST2 Installations Team will be finished and can seek to have the User Acceptance Testing [UAT] sign off, to officially complete the installation process.


Source URL: https://www.digi-sign.com/digi-ca/administrator/projects

Links:
[1] https://www.digi-sign.com/downloads/download.php?id=digi-ca-pdf
[2] https://www.digi-sign.com/digi-ca
[3] https://www.digi-sign.com/service/digi-cast
[4] https://www.digi-sign.com/digi-ca/service
[5] https://www.digi-sign.com/digi-ca/server
[6] https://www.digi-sign.com/certificate+authority/traditional+ca
[7] https://www.digi-sign.com/digi-ca/shared
[8] https://www.digi-sign.com/digi-ca/total+trust+management
[9] https://www.digi-sign.com/digi-tasc
[10] https://www.digi-sign.com/en/digi-trust/trusted+services+provider
[11] https://www.digi-sign.com/books
[12] https://www.digi-sign.com/en/about/third+party