Skip to content
CORPORATE TRUST SERVICES

Cryptography-based trust services to protect your digital identities, data and business secrets.

QUALIFIED TRUST SERVICES

Legally compliant digital signatures (eIDAS) to drive forward the digitalization of your business processes.

TRUST COMPONENTS

Everything to do with smartcards, tokens, readers, certificates and signatures.

INNOVATIVE AND SECURE PERSPECTIVES FOR A DIGITAL WORLD.

PKI & CRYPTOGRAPHY SOLUTIONS

STRONG AUTHENTICATION
Phishing-resistant with certificates or FIDO

ENTERPRISE PKI
for Zero-Trust & IoT

ENCRYPTION & KEY MANAGEMENT
for on-premise & Cloud

PKI & CRYPTOGRAPHY PRODUCTS

egofy CARD
Smart Cards & Token

primeID VSC
Virtual Smard Card

primeID ONDEMAND
Remote VSC platform

primeID SELF SERVICE
Self Service for Smart Cards

primeID AUTOMATE
Certificate Lifecycle Management

primeID CERTIFY
Enterprise PKI

primeID DISCOVER
Certificate monitoring

primeID VALIDATE
Enterprise OCSP

SIGNATURES & SEALS

Signatures & seals for your employees
with primesign as an enterprise solution

Sign a document online & instantly
for individuals and as an entry point for companies

SUPPORT

Simply integrate our experts into your ITSM structure / remote support up to 24/7

MANAGED SERVICES

We take care of the complete operation of your trust services in our data centers, you take care of your business.

THE USABILITY OF OUR SOLUTIONS ENSURES HIGH ACCEPTANCE.

Everything to do with smartcards, tokens, readers, certificates and signatures.
GENERAL

We are happy
to help.
T +43 1 35553 - 0

SALES

We are happy to support you.
T +43 1 35553 - 200

SHOP

You are a store customer and have a question or need support.
T +43 1 35553 - 300

STANDARD SUPPORT

You have a standard support contract and need assistance.
T +43 1 35553 - 800

SUPPORT PORTAL PREMIUM

You have a Premium Support contract and need assistance.

LOCATIONS
Back to all questions

What happens if a root CA's private key is compromised?

Because every certificate issued within a PKI ultimately traces back to a root CA, the compromise of that root's private key is one of the most severe events that can occur in a PKI's lifetime. An attacker holding the private key could sign fraudulent certificates that appear entirely legitimate to any system trusting that root, effectively allowing impersonation of any identity within the hierarchy until the compromise is detected and the root is revoked.

How organizations reduce this risk:

  • Hardware protection: Root CA private keys are generated and stored inside hardware security modules (HSMs) rather than on general-purpose servers.
  • Offline operation: Root CAs are frequently kept offline entirely, brought online only for scheduled operations such as signing a subordinate CA.
  • Restricted signing scope: A root CA is used to sign subordinate, issuing CAs rather than end-entity certificates directly, limiting its exposure.
  • Strict access control: Multi-person authorization and audited access procedures govern any operation involving the root key.

This layered approach is why enterprise PKI platforms like primeID CERTIFY are designed around hardware-backed key protection from the root down, rather than relying on procedural safeguards alone.

Why Root Key Protection Matters

  • A compromised root key can undermine an entire trust chain
  • Hardware security modules and offline storage limit exposure
  • Restricting root use to signing subordinate CAs reduces risk

Still have questions?

Our PKI and trust services team can walk you through what this looks like for your environment.

Talk to us