Certificate tools

Hardware & Attestation

What Is Key Ceremony & CPS?

A key ceremony is the formal, scripted and witnessed procedure in which a certificate authority’s root or issuing keys are generated inside an HSM — with named roles, split knowledge and signed evidence for every step. Its paper counterpart is the CP/CPS: the Certificate Policy and Certification Practice Statement that document what the CA promises and how it operates. Together they are what makes a CA’s trust verifiable rather than asserted.

Why the ceremony is formal

Everything the CA ever issues inherits trust from the moment its key is created. Auditors (WebTrust, ETSI) must be able to verify that the key was generated in certified hardware, that no individual could extract or use it alone (dual control, split knowledge across key custodians), and that the script was followed exactly — hence witnesses, recordings, sign-off sheets and HSM attestation as cryptographic evidence.

CP and CPS: the trust paperwork

The Certificate Policy (CP) states what the CA certifies and for whom; the Certification Practice Statement (CPS) states how — identity validation, key protection, revocation service levels, ceremony procedures. RFC 3647 defines the standard structure both follow. For private CAs the same documents, right-sized, are what turn "we have an internal CA" into something an auditor, customer or acquirer can actually assess.

Right-sizing for internal PKI

An internal root ceremony does not need a webcast — but it does need the same skeleton: a pre-approved script, at least two custodians, an offline machine, documented key backup to separate safes, and an attestation file proving hardware generation. Half a day of ceremony discipline buys years of auditability.

Try it yourself — free tools

How MI Support IT can help

MI Support IT plans and conducts key ceremonies — script authoring, custodian roles, HSM handling and the CP/CPS documentation that goes with them. Read about our PKI services or get in touch.

PKI Glossary