Skip to content

Product 01

Root CA System

Every certificate your business trusts should trace back to a key you control. The Root CA System gives you that key — generated inside a hardware security module, protected by physical tokens and dual control, and surrounded by the services that make its decisions verifiable to everyone else.

RSA 4096
and ECDSA P-384 root keys
PKCS#11
HSM key custody interface
RFC 6960
OCSP revocation checking
PAdES B-LT
long-term PDF signatures

Why own a root

A public CA rents you trust. A private root gives you sovereignty.

Public certificate authorities are excellent at one job: proving a domain name to a stranger. They are a poor fit for everything else — internal service identity, device fleets, signed invoices, partner file exchange — where you need control over policy, lifetime, naming and revocation, and where per-certificate pricing quietly becomes an architecture constraint.

Running your own root has always been possible. What made it hard was everything around the root: the ceremony, the offline media, the responder that has to answer in milliseconds, the revocation list nobody remembers to publish, the auditor who wants the witness statement. That surrounding apparatus is what this product actually is.

Keys that cannot leave

Root and SubCA keys are generated inside the HSM. There is no file to copy, no passphrase to leak, no backup tape to lose.

No single point of trust

Issuance from the root requires a quorum of operator tokens. One compromised laptop is not enough.

Policy you can defend

Certificate Policy and CPS written alongside the deployment, with the ceremony recorded and witnessed.

Answers at wire speed

Pre-signed OCSP responses and cached CRLs mean validation does not become your latency budget.

Architecture

How the pieces are arranged.

An air-gapped root that signs rarely, issuing SubCAs that sign constantly, and the validity services that let the rest of the world check both.

Architecture diagram. A YubiHSM 2 holds the keys for an offline root CA, with YubiKey PIV operator cards providing dual control. The root issues a TLS issuing SubCA, a signing SubCA and an identity SubCA. All three are backed by validity services: an OCSP responder, a CRL repository and an RFC 3161 timestamp authority. Relying parties are browsers and APIs, the PDF signer, and devices and workloads.
Private keys never leave the HSM. Every issuance is dual-controlled and written to an append-only audit trail.

Modules

Seven modules. Licence the ones you need.

Each module runs independently and speaks a published standard, so you can adopt them in stages rather than in one nervous weekend.

YubiKey Integration

Operator identity lives on a physical token instead of a shared password, and sensitive operations require a touch.

  • PIV slot provisioning, enrolment and revocation at scale
  • Touch-to-approve on every root and SubCA operation
  • Quorum enforcement so no single operator can issue alone
  • Lost-token workflow with witnessed re-enrolment

Yubi HSM Integration

A YubiHSM 2 becomes the only place your private keys have ever existed, exposed through the PKCS#11 interface your tooling already speaks.

  • Non-exportable key generation inside the device
  • PKCS#11 interface for standard CA and signing tooling
  • Wrapped backup to a second HSM for disaster recovery
  • Domain separation and per-key audit counters

OCSP Module

An RFC 6960 responder that answers the question every TLS handshake asks: is this certificate still good?

  • GET and POST support with nonce handling
  • Pre-signed responses cached at the edge for sub-second replies
  • Delegated responder certificate carrying the OCSP-signing EKU
  • Configurable response validity and stapling guidance

CRL Repository

Revocation lists published on a schedule you set, reachable at the exact URLs your certificates advertise.

  • Full and delta CRLs with configurable intervals
  • HTTP distribution at the exact CDP URLs your certificates carry
  • Emergency publication on demand after an incident
  • Archival and retention of historic lists

SubCA Module

Delegate issuance to a SubCA per purpose or business unit, so a mistake in one domain cannot contaminate another.

  • Independent policy, validity and key algorithm per SubCA
  • Name constraints and path-length limits enforced at issuance
  • Separate operator groups and approval rules
  • Cross-signing and re-parenting when the estate changes

TSA Module

An RFC 3161 timestamp authority, so a signature made today is still provably made today in five years.

  • RFC 3161 requests over HTTP with configurable policy OIDs
  • Dedicated timestamping key in its own HSM domain
  • Traceable, monitored time source with accuracy claims
  • Long-term validation data for archived signatures

Digital Signature Module

The PDF Signer: turns approved documents into signatures that hold up in front of a regulator.

  • PAdES B-B, B-T and B-LT profiles, plus detached CAdES
  • Batch signing over API or interactive signing with a YubiKey
  • Visible signature appearance with reason, location and image
  • Embedded revocation data and timestamps for long-term validity

Specification

Standards, not surprises.

If a relying party already implements the RFC, it already works with us.

Request the full datasheet
Key algorithms
RSA 2048 / 3072 / 4096 and ECDSA P-256 / P-384
Digest
SHA-256, SHA-384, SHA-512
Key custody
YubiHSM 2 over PKCS#11; software keystore for lab and staging
Enrolment
ACME, SCEP, EST, REST API and manual CSR upload
Revocation
OCSP per RFC 6960; full and delta CRLs per RFC 5280
Timestamping
RFC 3161 over HTTP with configurable policy OID
Signature formats
PAdES B-B / B-T / B-LT, CAdES detached, raw PKCS#7
Console access
OIDC single sign-on for the administration console
Audit
Append-only hash-chained event log with signed export
Deployment
On-premises or private cloud; Linux hosts or container images
High availability
Active-active issuing CAs and responders behind a load balancer
Interfaces
REST API, web console and command-line administration

In production

Where a private root earns its keep.

Internal TLS everywhere

Short-lived certificates for every internal service, renewed automatically over ACME instead of by calendar reminder.

Signed documents and invoices

Contracts, statements and e-invoices signed with PAdES B-LT so they remain verifiable years after issuance.

Device and workload identity

Factory-provisioned identities for hardware, and SPIFFE-style identity for containers and workloads.

Partner file exchange

Client certificates issued to counterparties, checked live by SftpS on every connection.

Workforce authentication

YubiKey PIV credentials for VPN, Wi-Fi, SSH and privileged access, all issued from one authority.

Evidence that survives

Timestamped audit records and archives that satisfy a regulator long after the signing certificate expired.

Own your root of trust.

We will walk your team through a live system, then scope what it takes to run one in your environment — ceremony, hardware and policy included.