Identity, trust and certificate infrastructure

PKI Demo Lab

Trust decisions made the way real certificate operations teams make them: deliberately, with the hierarchy in view.

Phase 3

PKI Architect Capstone

Weeks 17–24. Each student becomes the PKI Architect for an assigned fictional organization: analyze, design, operate, test, adapt, and defend.

Foundations

Trust Foundations

What a certificate asserts, and who is being believed.

  • Identity & AssertionPlanned

Phase 1

Certificate Authority Operations

Request review, issuance and the CA workspace.

  • Issuance OperationsPlanned

Phase 2

Key Management & HSMs

Protecting the material the whole hierarchy depends on.

  • Key CustodyPlanned

Phase 3

Revocation & Incident Response

When trust has to be withdrawn quickly and defensibly.

  • Revocation ResponsePlanned

Operating environments

  • PKI Operations Center

    Certificate lifecycle operations floor with issuance dashboards.

  • Certificate Authority Workspace

    Controlled workspace for CA request review and issuance.

  • HSM / Key Management Room

    Access-controlled room housing hardware security modules.

  • Trust Architecture Room

    Design room with a wall-sized trust hierarchy diagram.

  • PKI Incident Room

    Response room for revocation and compromise handling.

  • PKI Briefing Room

    Stakeholder briefing space for trust decisions.