Strengthening business security. Update PKI in a high-traffic environment
Customer situation
The company is listed on Poland's WIG30 index. Its main activities include oil production and refining. It also holds a significant position in the Polish lubricants market. Products offered by the company include unleaded gasoline, diesel fuel, heating oils, aviation fuels, engine and industrial lubricants, asphalts and waxes.
The PKI infrastructure for the ISCG customer was created and supported from the Windows 2003 version of CA. During this stage of the system life cycle, the big challenge was, to update the entire public key infrastructure without disrupting business processes in a high load environment.
Proposed solution
To meet the client's requirements, ISCG conducted a detailed load analysis of the current PKI infrastructure. The partner proposed a comprehensive solution based on Microsoft ADCS 2016 to replace ISCG's old PKI project. The plan included migrating HSM to the latest version, renewing Root CA and ICA keys, validating existing certificate templates and creating new ones. Remote access to the HSM was enabled, and operational procedures and CP and CPS (Certificate Policy and Certification Practice Rules) were updated. The PKI monitoring solution has also been improved, providing better visibility and management of the system.
Key factors
- Maintain smooth business processes in a heavily loaded infrastructure with limited maintenance windows and multiple dependencies.
- Adapt to new security policy requirements.
- Making sure the PKI (Public Key Infrastructure) system is up-to-date and secure.
- Support for advanced cryptographic mechanisms.
- Update the SLA (Service Level Agreement) for the PKI system.
Benefit provided
The partner's solution provided the customer with an up-to-date and secure PKI system. PKI management became more efficient with remote access to HSM. The new PKI service based on Microsoft ADCS 2016 offered better capabilities and performance. Updating Root CA and ICA keys provided credibility to the PKI system. Validation and creation of certificate templates met current and future requirements for digital certificates. Improvements in operational procedures and CP/CPS have increased system management and compliance. Overall, the improved PKI system has enabled the client to continue business operations , providing secure communications, data protection and authentication.

Added value
- Up-to-date and secure PKI system
- A simple way to manage PKI with remote access to HSM (Hardware Security Module).
- Enabling support for cryptographic mechanisms.
- Updated SLA (Service Level Agreement) for the PKI system.
Conclusions of the project
During this project, the client gained valuable experience on how to effectively manage their PKI infrastructure in a demanding environment with limited maintenance windows. They realized the critical importance of staying on top of the latest technologies and best practices, as evidenced by their decision to move to Microsoft ADCS 2016. The project clearly demonstrated the importance of performing proactive maintenance and regular renewals to avoid potential issues related to expired certificates or unsupported hardware. Effective change management communication played a key role in the overall success of the project, enabling the client to benefit from a modern and secure PKI system and ensuring business continuity in critical areas of the business.
Ursula Gorska
- Support and development of Microsoft and Nintex based applications
- Application design and development including digital processes
- Invoice management
- Requisition management
- Contract management
- Modern Intranet
ISCG sp. z o.o.
Al. Jerozolimskie 178, 02-486 Warsaw
NIP: 5262798378
KRS: 0000220621
Phone