Lamassu IoT Docs

Device Management Service

Define how a fleet receives, renews and uses its identities.

A Device Management Service (DMS) acts as the registration authority facing a fleet. It receives requests, applies the authentication policy and delegates issuance to the configured CA.

Each DMS is an independent operational boundary: it can represent a product line, an environment or a device type with its own CA, authentication rules, distributed trust and renewal window.

Each DMS exposes a single enrollment protocol, selected when it is created or edited: EST (RFC 7030) or CMP (RFC 9483 Lightweight CMP Profile / RFC 4210). The two protocols are mutually exclusive: changing the protocol of an existing DMS replaces its enrollment configuration entirely, without automatic migration of settings. Each protocol's configuration and the device integration guide are documented in the EST and CMP pages.

Before you begin

  • Create or import at least one active CA.
  • Decide how devices will authenticate during initial enrollment.
  • Define which authorities the device should receive as anchors of trust.
  • Make sure you have permissions to administer DMSs.

Configure a DMS

Identify the fleet

Give the DMS a name that describes its scope, for example a device family or an environment.

Select the enrollment CA

Choose the authority that will issue the identities. Its policy and validity period constrain the certificates the fleet can obtain.

Configure ESTthe enrollment protocol

Define Select EST (RFC 7030) or CMP (RFC 9483) and define the authentication of enroll, the reenroll policy, the renewal window and, if needed, serverkeygenserver-side key generation.

Distribute trust

Configure CA Distribution to control the response of the cacerts endpointwhich authorities the device receives as anchors of trust, regardless of the enrollment protocol.

Verify the endpoints

From the DMS menu, open EST (RFC-7030) and check the base URL and the invocation examples before integrating the firmware.

Trust distribution

  • Include Lamassu System CA distributes the TLS certificate of the Lamassu server, useful for pinning. It does not represent an issuing CA.
  • Include Enrollment CA adds the authority configured to issue the DMS's identities.
  • Managed CAs lets you include additional authorities the device must consider trusted.

Operate the DMS inventory

  • Edit modifies the DMS policy.
  • Go to DMS owned devices opens only the devices of that fleet.
  • Show/Edit Metadata manages advanced configuration and integration data.
  • EST (RFC-7030) shows the endpoints and examples specific to the DMS.
  • Delete removes the DMS and its configuration. The action is irreversible.

Integrate the devices

On this page