Browse Definitions :
Definition

private certificate authority (CA)

A private CA is an enterprise-specific certificate authority (CA) that functions like a publicly trusted CA but is exclusively run by -- or for -- the enterprise. With a private CA, an enterprise creates its own private root certificate which can issue private end-entity certificates for internal servers and users.  Certificates issued by a private CA are not publicly trusted and should not be used outside of the enterprise's trusted members and infrastructure.  

A certificate authority ultimately vouches for the identity of every machine, user or code process in the infrastructure. Without this kind of strong identity, attacks are possible whereby man-in-the-middle software programs steal information or issue false commands, potentially resulting in data loss, security breaches, theft of funds or other problems.  In the case of public trust mechanisms -- such as certificates used to secure web traffic, email and distributed code -- issued certificates follow a cryptographic "chain" up to public CAs.  In the case of a private CA, the enterprise sets itself up as the ultimate source of truth on which devices, users or processes are trusted inside the network.

In the past, enterprises commonly used the Microsoft CA tool for Windows machines or anything in the Microsoft technology stack. Microsoft CA was free and integrated with Active Directory, so it was well suited to much of this use. In recent years, however, trends like mobile device support (including BYOD), internet of things (IoT), cloud computing and DevOps have forced the use of non-Microsoft operating systems at large scale for business-critical applications. These architectures have required the adoption of other private CA offerings, including aftermarket private CA applications from IT security vendors.

Common uses of private CAs include:

  • Intranet sites
  • VPN or wireless authentication
  • Device identification
  • Internet of Things (IoT) projects
  • Secure communications between internal services
  • Interoperable communications between third parties including containerized or API-connected cloud environments.

Why are private CAs important?

The need for certificate-controlled identity inside the enterprise is vast.  Many of the use cases are inappropriate for common publicly trusted certificates, so enterprises must issue certificates from their own trust structure for these circumstances. Failure to implement strong identity practice for internal systems poses an unacceptable risk for data theft or other catastrophic breaches.

A commercial private CA offering can help an enterprise reduce risk and aid compliance by following the best practices of public key infrastructure (PKI), cryptography and IT security -- including tracking and automating the renewal of deployed certificates.  It can reduce time to market and increase business agility by allowing network administrators to manage certificates and practices rather than creating their own PKI from scratch.  And it can free up employee time for other tasks by automating the majority of the administrative tasks for internal certificates.

What else should the reader know about private CAs?

Many of the architectures driving the increased use of certificates are still in their early days.  Containers, multi-cloud, IoT and other contemporary computing architectures are driving up the number of certificates required by orders of magnitude, which in many cases reduce the lifespan of the average certificate accordingly.  In these architectures, automation is a requirement for certificate deployment and management.

This was last updated in July 2019

Continue Reading About private certificate authority (CA)

Networking
  • SD-WAN security

    SD-WAN security refers to the practices, protocols and technologies protecting data and resources transmitted across ...

  • net neutrality

    Net neutrality is the concept of an open, equal internet for everyone, regardless of content consumed or the device, application ...

  • network scanning

    Network scanning is a procedure for identifying active devices on a network by employing a feature or features in the network ...

Security
  • virtual firewall

    A virtual firewall is a firewall device or service that provides network traffic filtering and monitoring for virtual machines (...

  • cloud penetration testing

    Cloud penetration testing is a tactic an organization uses to assess its cloud security effectiveness by attempting to evade its ...

  • cloud workload protection platform (CWPP)

    A cloud workload protection platform (CWPP) is a security tool designed to protect workloads that run on premises, in the cloud ...

CIO
  • Regulation SCI (Regulation Systems Compliance and Integrity)

    Regulation SCI (Regulation Systems Compliance and Integrity) is a set of rules adopted by the U.S. Securities and Exchange ...

  • strategic management

    Strategic management is the ongoing planning, monitoring, analysis and assessment of all necessities an organization needs to ...

  • IT budget

    IT budget is the amount of money spent on an organization's information technology systems and services. It includes compensation...

HRSoftware
  • ADP Mobile Solutions

    ADP Mobile Solutions is a self-service mobile app that enables employees to access work records such as pay, schedules, timecards...

  • director of employee engagement

    Director of employee engagement is one of the job titles for a human resources (HR) manager who is responsible for an ...

  • digital HR

    Digital HR is the digital transformation of HR services and processes through the use of social, mobile, analytics and cloud (...

Customer Experience
  • chatbot

    A chatbot is a software or computer program that simulates human conversation or "chatter" through text or voice interactions.

  • martech (marketing technology)

    Martech (marketing technology) refers to the integration of software tools, platforms, and applications designed to streamline ...

  • transactional marketing

    Transactional marketing is a business strategy that focuses on single, point-of-sale transactions.

Close