Lamassu IoT Docs

Certificates

Inspect, download and revoke the certificates issued by Lamassu.

The certificate inventory offers a global view of the identities issued by all authorities. You can also open Issued Certificates inside a CA to limit the view to that issuer.

Find a certificate

Open Certificates and filter by:

  • Subject's Common Name.
  • Serial number.
  • Status.
  • Issuing authority.

Use Quick Inspect for a quick check or View Details to see the subject, SANs, usages, chain, validity period and full metadata.

Download the certificate

The download action delivers the certificate in PEM format. If the certificate was issued from an external CSR, the private key stays on the system that generated that CSR. If it was generated in the browser, the key was only available when the issuance finished.

Revoke a certificate

Revoke an identity when the key has been compromised, the subject is no longer authorized or the certificate must stop being accepted before it expires.

Open the action

In the inventory or detail view, select Revoke Certificate.

Choose a reason

Select the reason that represents the incident. This information is published in OCSP and in the CRL.

Confirm and verify

Confirm the operation and check that the status is Revoked. If the CA regenerates the CRL upon revocation, also verify that a new version exists.

Only CertificateHold is reversible

A revocation with the reason CertificateHold can be reactivated. All other reasons produce a final revocation.

Continue

On this page