The Cryptography, Data Protection and Identity Security Center of Excellence
How Accutive Security partnered with a large enterprise to advance a sophisticated PKI practice from on-premises Venafi TPP to a cloud-hosted, automated certificate management platform, training 130+ operators and maintaining full operational continuity throughout.
The migration path for enterprise PKI is well established in principle. Organizations running on-premises certificate management platforms are moving to cloud-hosted machine identity platforms, extending coverage for cloud workloads in multi-CA environments, and advancing toward containerized certificate automation. What that migration looks like in practice, particularly for organizations that already operate a sophisticated, production-grade PKI environment, is less frequently documented.
The client, a large financial services organization, was not starting its PKI journey. It was operating Venafi Trust Protection Platform (TPP) across a multi-CA environment, with Microsoft ADCS and DigiCert as active CAs, AWS workloads issuing internally-trusted certificates, and over 130 trained operators managing the platform. Over time, however, the mature TPP operation had drifted out of currency and needed to modernize without disruption.
Given the client’s existing sophistication, the goal of Accutive Security’s engagement was not the typical remediation or rescue operation. Rather, it was to accelerate a mature PKI practice past the limits of its existing platform and into a cloud-delivered, multi-CA, container-aware architecture, without disrupting existing operations.
Accutive Security engaged across four sequential stages to deliver that outcome.
Mapping Platform Currency Against Infrastructure Demand
When Accutive Security began its engagement with the client, their PKI environment was already matured enough, reflecting years of deliberate investment. However, the TPP instance had fallen behind its supported version path, a gap with cascading operational consequences such as:
An assigned Accutive Security engineer conducted a structured technical review spanning CA configurations, discovery job coverage, certificate validation policies, AWS certificate integration status, license utilization, and platform resilience. This analysis produced a sequenced remediation roadmap, prioritizing immediate stabilization actions first and automation maturity improvements later.
The client executed against this sequence. The stabilization work that followed created the clean operational baseline on which the TLSPC migration was built.
Transitioning 130+ Users to a Cloud-Hosted Platform
With the health check findings addressed and a stable platform baseline established, Accutive Security led the full migration from on-premises Venafi TPP to TLS Protect Cloud (TLSPC). The client had already licensed TLSPC but had not yet deployed it. Two engineers managed the implementation end-to-end, covering architecture design, platform configuration, CA integration, and go-live transition.
The migration moved the platform off a more maintenance-intensive on-premises footprint and onto a cloud-delivered platform, with enhanced visibility and automation potential.
At the conclusion of the implementation, Accutive Security delivered formal handoff training to more than 130 users. The platform was now cloud-managed, fully supported, and positioned to support the integration and automation work that would follow.
AWS Certificate Manager Integration, ADCS Automation, and Machine Identity Visibility
With TLSPC operational as the centralized identity security platform, the next phase extended the platform's scope across the client's infrastructure. Two engineers led a set of integrations that materially deepened machine identity coverage.
The client retains and operates ADCS in-house; Accutive Security’s contribution was automating it through the SCEP layer and bringing it under consistent, policy-driven certificate management for the first time.
With the integrations in place, two automation capabilities were activated that directly reduce the operational burden on the client's PKI team.
TLSPC also provides outage reporting, surfacing certificates approaching expiry, validation failures, and installation errors before they cause service disruptions. With the full certificate inventory now visible and validation policies consistently enforced across the hierarchy, these alerts reflect the actual state of the environment, giving the team accurate, actionable intelligence for outage prevention rather than reactive incident response.
These integrations moved the client’s machine identity program from a certificate management deployment to a unified machine identity fabric, one control plane governing issuance, policy, and lifecycle across both cloud and on-premises infrastructure.
The architecture now spans the full scope of the client’s machine identity environment. The Venafi Control Plane (now known as Palo Alto Network’s Next Generation Trust Security) serves as the operational center, integrating across three cloud providers (AWS, Azure, and Google Cloud), three external CAs (Sectigo, DigiCert, and the internal Microsoft CA), and three SSO providers (Okta, Microsoft Entra, and Ping Identity). Service account and secrets platforms (CyberArk, HashiCorp Vault, and Akeyless) connect to the control plane for coordinated machine identity governance. DevOps tooling integrations span vCert, Terraform and Ansible.
Two VSatellites and a VSatellite Worker bridge the control plane into Active Directory Certificate Services (ADCS). The coverage is extended to two AEP infrastructure instances, Intune, JAMF, and Citrix FAS.
Endpoint and platform integrations include NGINX, IIS, Apache, Citrix, Fortinet, VMware NSX, F5, Imperva, and Cloudflare.
The result is an enterprise-scale machine identity fabric, not a point deployment.
Bringing Certificate Automation into Kubernetes Environments
The fourth phase undertook the development of a custom solution, a containerized vCert proof-of-concept, that extends certificate lifecycle management natively into Kubernetes environments. The solution uses sidecar containers to automate certificate provisioning, renewal, and rotation at the workload level, eliminating manual coordination from certificate processes in environments where containers are ephemeral and deployment cycles are continuous.
The on-premises cloud containerized PKI arc is the path that mature enterprises across every sector are now beginning to walk. While most are still at the planning stage, this organization is already at the leading edge.
The PKI modernization program produced crucial outcomes that directly improve how the organization manages machine identity at enterprise scale.