Lamassu IoT Docs

Lamassu IoT Platform

Manage PKI and digital identities for your devices from a single platform.

Lamassu IoT centralizes the issuance, distribution, renewal and revocation of X.509 identities for connected devices. You can build a private PKI, protect its keys and automate the enrollment of a fleet without losing visibility into every certificate.

Start here

Core capabilities

Build your trust hierarchy

Create root and intermediate authorities or import an existing PKI. Define which authority can issue each identity and keep the full chain of trust.

Protect cryptographic keys

Generate and safeguard keys using software engines, PKCS#11 HSMs or cloud services. Lamassu decouples operations from the physical location of the key.

Issue and control certificates

Issue certificates from the console or from a CSR, check their status and revoke them when they stop being trustworthy.

Automate device identities

Define enrollment policies with a Device Management Service (DMS) and let devices request or renew their identity through EST or CMP.

Publish validation status

Offer online validation through OCSP and distribute CRLs for consumers that need to check certificates offline.

React to events

Subscribe to lifecycle changes and send notifications by email, Microsoft Teams or webhooks.

Choose your path

Operational reference

On this page