Glossary
PKI, certificate and identity management terms used in Lamassu.
A–C
AKI (Authority Key Identifier)
Identifier of the public key of the authority that signed a certificate. It helps build the chain toward the correct issuer.
Anchor of trust
A certificate, usually from a root CA, that a consumer explicitly accepts as the endpoint of a chain.
CA (Certification Authority)
Authority that signs certificates and binds an identity to a public key.
Intermediate CA
A CA signed by another authority. Used to issue without exposing the root to daily operation.
Root CA
A self-signed CA that starts a hierarchy of trust.
X.509 certificate
A signed document containing a public key, a subject, an issuer, a validity period and extensions that constrain its use.
CRL (Certificate Revocation List)
Signed list of revoked certificates published by a CA.
CSR (Certificate Signing Request)
PKCS#10 request containing a public key and requested attributes. Signing the CSR proves possession of the corresponding private key.
D–K
DMS (Device Management Service)
Configuration that groups registration, enrollment, re-enrollment, issuance and CA distribution rules for a fleet.
Distinguished Name (DN)
Set of subject or issuer attributes, such as CN, O, OU, C, ST and L.
EST (Enrollment over Secure Transport)
Protocol defined in RFC 7030 to obtain CAs, enroll and re-enroll certificates over HTTPS.
Extended Key Usage (EKU)
Extension that constrains purposes such as client authentication, server authentication, code signing or OCSP.
Device identity
Relationship between a device and one of its certificates. A device can keep a history of identities.
Identity slot
Logical position on a device where Lamassu binds an active or historical identity.
JITP (Just-in-Time Provisioning)
Automatic registration of a device when it successfully completes its first enrollment.
KMS (Key Management Service)
Lamassu service that normalizes key generation, import and use across different cryptographic engines.
Key Usage
X.509 extension that allows basic operations such as digital signature, key encryption or certificate signing.
M–R
mTLS (Mutual TLS)
TLS where both client and server present certificates. A DMS can use the client certificate as an authentication method.
OCSP (Online Certificate Status Protocol)
Protocol for querying online whether a certificate is valid, revoked or unknown.
Issuance profile
Reusable policy that defines how Lamassu builds a certificate and which keys it accepts.
Principal
Operator or API client identity recognized by the authorization service. Lamassu supports OIDC and X.509 principals.
Policy
Set of permissions assignable to one or more principals.
RA (Registration Authority)
Component that verifies the requester before asking a CA to issue. The DMS plays this role in device enrollment flows.
Relying party
Consuming system that decides whether to accept a presented certificate.
Revocation
Invalidation of a certificate before its expiration date.
S–Z
SAN (Subject Alternative Name)
Extension that adds identities such as DNS names, IP addresses, emails or URIs.
SKI (Subject Key Identifier)
Identifier derived from the public key of the certificate itself.
VA (Validation Authority)
Lamassu service responsible for OCSP responses and the generation or publication of CRLs.
Renewal window
Period before expiration during which a device may or must request another identity.
Missing an operational term? Check How Lamassu works and the Trust model first, where these concepts appear connected.