BITSUMMIT upgraded an unsupported Windows Server 2008 PKI to 2022 with zero documentation and minimal downtime, restoring vendor support and cutting admin overhead.

The City of Kitchener's public-key infrastructure, the certificate authority that underpins authentication across Active Directory and critical city services, was running on Windows Server 2008. The platform had reached end of support, so it no longer received vendor patches, which left it exposed to unpatched vulnerabilities and out of step with modern security standards.
Two things made it worse. There was no documentation at all, so the architecture, certificate hierarchies, and configurations had to be understood from scratch, and that knowledge gap was one staffing change away from becoming a crisis. At the same time, the environment could not simply be taken offline: any PKI downtime would break authentication across Active Directory and disrupt city services, so the migration demanded meticulous planning. Outdated root and intermediate certificates cluttered the trust store on top of all that, and manual issuance and renewal made day-to-day certificate management slow and error-prone.
The City of Kitchener's PKI ran on Windows Server 2008, out of support, undocumented, and underpinning authentication across Active Directory and critical city services. BITSUMMIT had to reverse-engineer it, rebuild it on a modern and more secure design, and move every dependent service across without interrupting the city.

Reverse-engineer the existing PKI
With no documentation to work from, BITSUMMIT audited the live environment directly, analyzing the Certificate Authorities, certificate templates, issuance policies, and trust relationships to map every dependency before designing anything new.
Design a hardened two-tier hierarchy on Server 2022
The new PKI was built on Windows Server 2022 as a two-tier hierarchy: an offline Root CA, kept off the network so the trust anchor cannot be reached or forged, and an online Enterprise Subordinate CA to handle day-to-day issuance. Cryptography was brought up to current standards with SHA-256 and RSA 2048-bit keys.
Migrate the hierarchy without losing trust
BITSUMMIT backed up the entire PKI database, including the CA certificates, private keys, and configuration, then restored it onto the new Server 2022 CA servers, migrating the hierarchy intact so existing trust held. The migration was sequenced to keep downtime negligible while authentication stayed available.
Re-establish every dependent service
Applications and services were repointed to the new CA servers, and certificates were re-bound to the systems that depend on them, including IIS websites, VPN gateways, and wireless authentication servers, so authentication and encryption carried on uninterrupted.
Automate issuance and clean up the old trust
New certificates were issued to domain controllers, web servers, and network devices, and auto-enrollment was configured through Group Policy to remove the manual issuance and renewal that had caused errors. A custom PowerShell script, deployed network-wide through SCCM, stripped the obsolete root and intermediate certificates from every domain-joined machine, leaving a clean, trustworthy certificate store.
Document and train
BITSUMMIT created the documentation the environment never had, covering the architecture, configurations, operational procedures, and disaster recovery, and trained the city's IT staff to run the PKI for the long term.
Moving the city's PKI to Windows Server 2022 removed the vulnerabilities that came with running an unsupported platform and restored vendor support, while the stronger SHA-256 and RSA 2048-bit cryptography improved data protection and compliance. Clearing out the obsolete certificates also reduced the attack surface and the trust issues they could cause.
The migration itself ran with only minimal downtime and no significant impact on city operations. With issuance and renewal now automated and the environment finally documented, administrative overhead dropped by roughly 40% and troubleshooting time fell by 30%. The new PKI meets the city's security and compliance requirements, keeps it on a supported and patchable platform, and gives it the headroom to adopt newer security capabilities as needed.
Tell us what you're trying to modernize, secure or migrate. We'll bring a plan and a named senior engineer.
Schedule a call →