TechTarget.com/searchsecurity

https://www.techtarget.com/searchsecurity/tip/The-benefits-and-challenges-of-managed-PKIs

The benefits and challenges of managed PKIs

By Karen Scarfone

Public key infrastructure is critical to enabling users, devices, software and other digital assets to securely exchange data. But deploying, operating and maintaining an organization's PKI is a difficult task. A single mistake can cause disastrous consequences.

To maintain security but simplify the task, organizations are increasingly turning to PKI as a service (PKIaaS).

Let's look at the benefits and challenges of managed PKI offerings to determine if they're the best fit for your organization.

On-premises PKIs and PKIaaS

A PKI establishes certificate authorities (CAs) and uses them to issue and revoke digital certificates to confirm the identities of users, devices, services, software and other digital entities. Each certificate is based on the public key of a public and private key pair, and it is signed first by the certificate owner's private key and then the CA's private key.

When creating a PKI, security teams must start with a root CA, which is usually stored offline in a hardware security module (HSM) at a physically secure facility. The root CA is used to create a hierarchy of CAs and certificates, with each additional CA stored in its own HSM. A security incident could put the entire hierarchy at risk, so the root CA is only placed online when needed.

PKIaaS moves a PKI's hardware, software and service components -- including all the stored CAs -- from on premises to the cloud. The PKIaaS provider then becomes largely responsible for operating and maintaining the PKI. Most PKIaaS offerings are subscription-based and provide APIs to integrate the service into an organization's system.

The benefits of PKIaaS

PKIaaS offers the following benefits typically associated with cloud-based services:

Additional benefits specific to PKIaaS include the following:

The challenges of PKIaaS

The most common challenges with PKIaaS are generally the same as other cloud-based offerings:

For most organizations -- whether large, small or somewhere in between -- the benefits of PKIaaS greatly outweigh the challenges. Organizations can avoid these challenges altogether by doing thorough research when evaluating PKIaaS providers and offerings.

14 Apr 2022

All Rights Reserved, Copyright 2000 - 2025, TechTarget | Read our Privacy Statement