Certificate Lifecycle Service · View 20 of 21 · Assurance
Zone rules
- The control plane may request a signature and may never produce one. Nothing in it can reach a signing module.
- The issuance plane has separate credentials, a separate audit path and no standing human access.
- The published surface — CRL, OCSP, trust bundle mirror, delegated DNS zone — is read-only and deliberately the most available tier in the design.
Key custody
- Signing keys are non-exportable in FIPS 140-2 Level 3 hardware; the root module is physically offline between ceremonies.
- Two-person control on root ceremonies, issuing-intermediate creation, any relaxation of a profile constraint, and any manual issuance outside a profile.
- Issuing intermediates carry name constraints where the technology permits, so a compromised private intermediate cannot mint an identity outside its scope.
Risk
- The platform's own administrative surface is the highest-value target in the estate. It gets separate credentials, no standing access and alerting on every privileged action — and it is the thing most likely to be under-protected because it looks like infrastructure.