This topic explains the considerations and requirements for implementing high availability (HA) in Public Key Infrastructure (PKI) environments, including clustering support and configuration guidance for Certificate Authority and related services.
Public Key Infrastructure (PKI) is a framework that manages digital certificates and public-key encryption to secure communications and authenticate identities within a network.
-
Supports high availability (HA) for Certificate Authority (CA) and Registration Authority (RA) servers, depending on vendor capabilities.
-
Clustering is supported for the Certificate Services role in Microsoft PKI solutions from Windows Server 2019 onwards.
-
Other role services such as Web Enrollment, Net Device Enrollment, and Online Responder require separate configuration for HA, typically using load balancers.
PKI HA and Design References
Consult PKI vendors for HA capabilities and implementation details for CA and RA servers. Microsoft PKI solutions support clustering for Certificate Services from Windows Server 2019 onwards.
-
For PKI design, see Microsoft PKI Architecture .
-
For more information on making other role services highly available, see Active Directory Certificate Services (AD CS) Public Key Infrastructure (PKI) Design Guide .