Hardware & Attestation
What Is Key Ceremony & CPS?
A key ceremony is the formal, scripted and witnessed procedure in which a certificate authority’s root or issuing keys are generated inside an HSM — with named roles, split knowledge and signed evidence for every step. Its paper counterpart is the CP/CPS: the Certificate Policy and Certification Practice Statement that document what the CA promises and how it operates. Together they are what makes a CA’s trust verifiable rather than asserted.
Why the ceremony is formal
Everything the CA ever issues inherits trust from the moment its key is created. Auditors (WebTrust, ETSI) must be able to verify that the key was generated in certified hardware, that no individual could extract or use it alone (dual control, split knowledge across key custodians), and that the script was followed exactly — hence witnesses, recordings, sign-off sheets and HSM attestation as cryptographic evidence.
CP and CPS: the trust paperwork
The Certificate Policy (CP) states what the CA certifies and for whom; the Certification Practice Statement (CPS) states how — identity validation, key protection, revocation service levels, ceremony procedures. RFC 3647 defines the standard structure both follow. For private CAs the same documents, right-sized, are what turn "we have an internal CA" into something an auditor, customer or acquirer can actually assess.
Right-sizing for internal PKI
An internal root ceremony does not need a webcast — but it does need the same skeleton: a pre-approved script, at least two custodians, an offline machine, documented key backup to separate safes, and an attestation file proving hardware generation. Half a day of ceremony discipline buys years of auditability.
Try it yourself — free tools
- Key Ceremony Planner — generate a complete ceremony script with roles, steps and sign-off sheets
- CPS Builder — produce an RFC 3647-structured CPS for your CA
- HSM Attestation Checker — verify the attestation evidence from the ceremony
How MI Support IT can help
MI Support IT plans and conducts key ceremonies — script authoring, custodian roles, HSM handling and the CP/CPS documentation that goes with them. Read about our PKI services or get in touch.
PKI Glossary
- Hardware Security Module (HSM)Tamper-resistant hardware that generates and guards cryptographic keys so they can be used but never extracted.
- Certificate Authority (CA)The trusted organization that issues and signs digital certificates — and the root of every trust chain.
- TPM AttestationHow a Trusted Platform Module proves a key was generated in hardware — and how to verify the proof.
- Browse all terms →