Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments.

MITAuto-check passedSecurity

Install Pki Design

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill pki-design -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills pki-design --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pki-design .claude/skills/pki-design && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pki-design
GitHub stars
175
Token cost
~2.1k tokens
SKILL.md length
936 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments.

  • Works in 7 steps: Design the CA hierarchy — Offline root… → Protect the keys with HSM — Root CA… → Storage and lifecycle in Key Vault — Use… → …
  • Entra ID identity model (use entra-id)
  • SKILL.md covers When to use, Pick the CA strategy by use case, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Pki Design is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments. Covers CA strategy (offline root + issuing CAs, AD CS vs managed/third-party vs public CA), Azure Key Vault certificates, HSM key protection, Entra certificate-based authentication (CBA), certificate lifecycle (issuance, renewal, rotation, revocation), and Intune SCEP/PKCS distribution. WHEN: PKI design, certificate authority, root CA offline, issuing CA, certificate management, Key Vault…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Cryptography, Secrets management and App store release. It works with Microsoft Entra ID, Azure Key Vault and Microsoft Azure. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • Entra ID identity model (use entra-id)
  • Key Vault secrets/keys only (use azure-key-vault)

Example prompts

  • “/pki-design”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Design the CA hierarchy — Offline root CA + one or more online issuing CAs.
  2. Protect the keys with HSM — Root CA private key in an HSM (FIPS 140-2 Level 2+).
  3. Storage and lifecycle in Key Vault — Use Azure Key Vault certificates for all
  4. Auto-enrollment for device and user certs — AD CS auto-enrollment via GPO for domain
  5. Plan revocation — CRL (Certificate Revocation List) published to HTTP endpoint;
  6. Monitor expiry — Key Vault sends events for upcoming expiry. Stream to a dashboard.
  7. Rotation discipline — Plan rotation before issuance, not when expiry approaches.

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pki Design loads about 2.1k tokens when it runs. Until then it costs about 211 tokens; SKILL.md has 936 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~211
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 936 words, ~2,086 tokens.

Download SKILL.mdSave it as .claude/skills/pki-design/SKILL.md (or your agent's skills folder).
name
pki-design
description
Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments. Covers CA strategy (offline root + issuing CAs, AD CS vs managed/third-party vs public CA), Azure Key Vault certificates, HSM key protection, Entra certificate-based authentication (CBA), certificate lifecycle (issuance, renewal, rotation, revocation), and Intune SCEP/PKCS distribution. WHEN: PKI design, certificate authority, root CA offline, issuing CA, certificate management, Key Vault certificates, certificate-based authentication, CBA, certificate lifecycle, issue and rotate certificates, mTLS certificates, code signing, CRL OCSP, certificate expiry, certificate rotation, AD CS, HSM, Managed HSM. DO NOT USE for Entra ID identity model (use entra-id) or Key Vault secrets/keys only (use azure-key-vault).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

PKI Design

Public Key Infrastructure (PKI) issues and manages the digital certificates that underpin authentication, encryption, and signing. In Azure-centric and hybrid environments this means combining a trusted CA hierarchy, Key Vault storage, automated lifecycle, and certificate-based authentication.

When to use

Designing certificate issuance, distribution, and lifecycle for: Entra phishing-resistant CBA, TLS / mTLS for services, device identity (Wi-Fi 802.1x, VPN), code signing, and S/MIME. Use this skill when the question is "where do certificates come from and how do they renew", not "how do I store one secret".

Do not use this skill for Key Vault secrets/keys (azure-key-vault) or Entra ID model (entra-id).

Pick the CA strategy by use case

If the use case is...CA choiceNotes
Internet-facing TLS (websites, APIs)Public CA (DigiCert, GlobalSign, Let's Encrypt)Always; private CAs aren't trusted by browsers
Internal app TLS, mTLS, service-to-serviceInternal issuing CA (AD CS or managed)Private CA chain trusted internally
Entra certificate-based authenticationInternal CA published to Entra trust storePair with strong binding policy
Device identity (Wi-Fi 802.1x, VPN)AD CS or third-party PKI + Intune SCEP/PKCSAuto-enrollment essential
Code signingEV code signing cert from a public CAHardware token; protect aggressively
S/MIME email signing/encryptionThird-party public CA (DigiCert, Sectigo)Internal CAs not trusted by external recipients
Short-lived workload certs (Kubernetes)cert-manager with ACME or internal issuerMinutes-to-hours TTL

Rule of thumb: never use a private CA for internet-facing services and never use a public CA for internal certificates at scale (cost + agility). Two distinct chains.

Approach

  1. Design the CA hierarchy — Offline root CA + one or more online issuing CAs. Root signs issuing CA certs (long validity, e.g. 10-20 years), issuing CAs sign end-entity certs (1-2 year validity). Verify: root CA host is powered off or air-gapped except for CRL signing and issuing CA renewal.

  2. Protect the keys with HSM — Root CA private key in an HSM (FIPS 140-2 Level 2+). Azure Managed HSM for cloud-native; on-prem HSM for AD CS. Never an unprotected filesystem. Verify: certutil -getreg ca\CSP\Provider shows the HSM provider, not "Microsoft Software Key Storage Provider".

  3. Storage and lifecycle in Key Vault — Use Azure Key Vault certificates for all service certificates. Integrate with supported issuer CAs (DigiCert, GlobalSign, internal via Key Vault Acmebot or partner connector) for automatic renewal. Verify: cert objects have lifetime_actions configured for auto-renewal at 75% of lifetime; manual touch required only for new issuance.

  4. Auto-enrollment for device and user certs — AD CS auto-enrollment via GPO for domain members; Intune SCEP or PKCS connector for cloud-managed devices. Never email a PFX file. Verify: Intune cert profile reports > 95% deployment success; user/device cert visible in personal store.

  5. Plan revocation — CRL (Certificate Revocation List) published to HTTP endpoint; OCSP responder for real-time. Both must be highly available - if CRL is unreachable, modern clients fail closed for high-assurance certs. Use a CDN for the CRL HTTP endpoint. Verify: CRL endpoint reachable from public internet (if external certs) and from all internal clients; OCSP responder uptime > 99.9%.

  6. Monitor expiry — Key Vault sends events for upcoming expiry. Stream to a dashboard. For AD CS, use a script (certutil -view) on a schedule. Track 90/60/30/7 days out. Verify: no cert in production expires unmonitored; alerts fire 60 days before expiry.

  7. Rotation discipline — Plan rotation before issuance, not when expiry approaches. Service teams own renewal automation; PKI team owns CA + alerting infrastructure.

Show full SKILL.md (375 more words)Show less

Guardrails

  • Root CA offline, full stop. A compromised root undermines every cert it ever signed or will sign. Power-off > air-gap > network-isolated VM.
  • HSM for the issuing CA key. Software-stored issuing CA keys are the single point of total trust failure.
  • Never let production certificates silently expire. Outage at the worst moment. Auto-renew or alert 60 days out.
  • Plan revocation before relying on certs. A cert system without working CRL/OCSP can't actually revoke - which means a compromised cert stays valid until expiry.
  • Public CA for internet-facing TLS, always. Browsers won't trust a private chain.
  • Don't use a wildcard cert across security domains. One compromise = all subdomains compromised. Issue per-service certs and automate the renewal.
  • Hardware token for code signing keys. Software-signed code signing keys regularly appear in malware once stolen.

Common anti-patterns

  • "We just emailed the PFX to the developer" - Key exposure. Use Key Vault + managed identity / SCEP.
  • "Our root CA is online so we can renew issuing certs easily" - Convenience that compromises the entire trust chain. Offline root.
  • "Software CSP for the issuing CA - HSM is expensive" - Hardware costs less than the incident response when the CA key is stolen.
  • "5-year validity on end-entity certs because renewal is painful" - Long-lived certs are a liability when compromised. Shorten + automate.
  • "CRL is on a single server inside the corp network" - External users can't validate; CRL outage breaks auth. CDN it.
  • "We'll set up monitoring after we issue the certs" - Cert expiry incidents always happen before monitoring is in place.
  • "Use the same cert across all environments (dev/test/prod)" - Dev cert compromise affects production. Per-environment certs.

Example prompts

  • Design a PKI hierarchy with offline root + two issuing CAs and HSM key protection.
  • Issue and auto-rotate certificates from Azure Key Vault for our App Service workloads.
  • Set up Entra certificate-based authentication with our internal CA and strong binding.
  • Plan SCEP/PKCS certificate deployment via Intune for Wi-Fi 802.1x.
  • Configure CRL and OCSP for our internal CA with a CDN-backed CRL endpoint.
  • Monitor and auto-alert on certificate expiry across Key Vault and AD CS.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/pki-design of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Pki Design next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pki Design compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pki Design this skillvinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT
Azure Key VaultKilo-Org/kilo-marketplace1901 repos~1.9kAutomated safety check: PassMIT
Azure Keyvault Pymicrosoft/skills3.1k—~2.4kAutomated safety check: PassMIT
Azure Compliancemicrosoft/GitHub-Copilot-for-Azure2552 repos~997Automated safety check: PassMIT
Entra App Registrationmicrosoft/GitHub-Copilot-for-Azure2552 repos~2.1kAutomated safety check: PassMIT
Apex Azure Compliancejonathan-vella/apex217—~1.6kAutomated safety check: PassMIT

Similar skills

  • Azure Key Vault

    Kilo-Org/kilo-marketplace

    Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.

    190 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • Azure Keyvault Py

    microsoft/skills

    Official

    Azure Key Vault SDK for Python. An agent skill from microsoft/skills.

    3.1k GitHub stars~2.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Azure Compliance

    microsoft/GitHub-Copilot-for-Azure

    Official

    Run Azure compliance and security audits with azqr plus Key Vault expiration checks.

    255 GitHub starsUsed in 2 repos~997 tokens
    SecurityAuto-check passed
  • Entra App Registration

    microsoft/GitHub-Copilot-for-Azure

    Official

    Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    255 GitHub starsUsed in 2 repos~2.1k tokens
    Backend & APIsAuto-check passed
  • Apex Azure Compliance

    jonathan-vella/apex

    ANALYSIS SKILL — Azure compliance and security auditing: best practices, Key Vault expiration monitoring, resource validation.

    217 GitHub stars~1.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Managing Workflow Secrets

    bitwarden/ai-plugins

    Official

    Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…

    155 GitHub stars~4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Pki Design

What does Pki Design do?

Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments. Pki Design is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments.

When should I use Pki Design?

Pki Design fits situations like: entra ID identity model (use entra-id); key Vault secrets/keys only (use azure-key-vault).

How do I install Pki Design in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill pki-design -a claude-code`. Or copy the skill folder (skills/pki-design in vinayaklatthe/microsoft-security-skills) into .claude/skills/pki-design in your project. Claude Code loads it when a task matches its description.

How do I install Pki Design in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill pki-design -a codex`. Or copy the skill folder (skills/pki-design in vinayaklatthe/microsoft-security-skills) into .agents/skills/pki-design in your project. Codex loads it when a task matches its description.

Can I use Pki Design in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill pki-design -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pki-design, .gemini/skills/pki-design, .github/skills/pki-design and .opencode/skills/pki-design in your project.

What does Pki Design need to run?

SKILL.md names no scripts, command-line tools or credentials: Pki Design is instructions for the agent only.

Does Pki Design access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Pki Design safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pki Design use?

Pki Design is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pki Design use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pki Design?

Skills that share tags, products or a category with Pki Design: Azure Key Vault (Kilo-Org/kilo-marketplace, 190 stars), Azure Keyvault Py (microsoft/skills, 3.1k stars), Azure Compliance (microsoft/GitHub-Copilot-for-Azure, 255 stars) and Entra App Registration (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pki Design?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.