Lamassu IoT Docs

Certification authorities

Create, import and operate the authorities that establish your PKI's trust.

A certification authority (CA) binds identities to public keys through signed certificates. In Lamassu you can create a new hierarchy, use a key already in the KMS or incorporate an external CA.

To design a full chain or replace an authority in production, see CA hierarchy and rotation. If you need to standardize what each authority can sign, use Certificate profiles.

Choose a flow

  • New CA with a new key: create a root of trust from scratch. Lamassu generates and keeps the key pair.
  • New CA from the KMS: reuse a key already registered in the platform.
  • Import a CA with its private key: incorporate an external authority that Lamassu can issue with.
  • Import only the certificate: add an authority for building chains and validating, but not for issuing.

First time here? Follow Create your first CA to complete the minimal journey.

Create a new authority

Before you begin

  • Decide whether the CA will be a root or an intermediate.
  • Choose the engine that will keep the key.
  • Define a validity longer than that of the certificates it will issue.
  • For an intermediate CA, make sure the parent CA is active.

Open the wizard

In Certification Authorities, select Create New CA and choose to generate a new key pair.

Configure the key

Select the cryptographic engine, the algorithm and the size or curve. Lamassu supports RSA and EC keys according to the engine's capabilities.

For RSA you can choose 1024, 2048, 3072 or 4096 bits. For EC, the P-256, P-384 and P-521 curves are available.

Choose the CA type

Select Root CA for a self-signed authority or Intermediate CA for an authority signed by another CA. In the latter case, choose the issuing CA.

Define the identity

Enter a unique CA Name. This name becomes the certificate's Common Name. Complete the Distinguished Name fields your policy requires:

  • C: two-letter ISO 3166-1 country code.
  • ST: state or province.
  • L: locality.
  • O: organization.
  • OU: organizational unit.

The CA's internal identifier is generated automatically and cannot be changed.

Configure validity and uses

Define CA Certificate Expiration and Default End-Entity Certificate Issuance Expiration. You can express a duration (5y 8w 4d), pick a date or use the maximum allowed date.

Select an existing issuance profile or configure the Key Usage and Extended Key Usage in the form. If you don't choose a profile, Lamassu applies the default basic usages.

Create and verify

Confirm the form. The CA should appear in the inventory with its PEM certificate, status, expiration date and list of issued certificates.

Plan validity as a hierarchy

A CA cannot issue certificates that outlive its own expiration date. Leave enough margin to renew or replace the authority without interrupting consumers.

Use a key from the KMS

Select Create New CA (Existing Key) when the key is already registered in Lamassu. The wizard first asks for the backing key and then shows the same configuration of type, identity, validity and profile.

This flow is useful when the key was previously created in an HSM, imported through BYOK or must be reused under a specific custody policy.

Import an external CA

Importing preserves an authority created outside Lamassu.

Select the engine

Choose the engine that will keep the imported key.

Load the material

Provide the CA certificate and the private key in PEM format. For a subordinate CA, optionally add the validation chain.

Define the default issuance

Configure the validity that end-entity certificates will receive when a request does not specify another duration.

Verify the import

Lamassu checks that the certificate belongs to a CA and that the material is coherent before registering it.

If you don't have the private key, import only the certificate. The authority can take part in chains of trust and validation processes, but it cannot issue certificates from Lamassu.

Inspect an authority

Open a CA from the inventory to review:

  • Status and validity period.
  • Certificate and chain in PEM format.
  • Number of active, expired and revoked certificates.
  • Certificates issued in Issued Certificates.
  • The CRL linked to the authority.
  • Metadata and the associated cryptographic engine.

You can filter the inventory by name, status and CA type.

Issue certificates

You can start an issuance from Issued Certificates, from a CA's action menu or from the global certificate inventory.

Generate Key & CSR in Browser is useful for a manual operation or a quick test. The browser generates the key and you must download it at the end.

Upload Existing CSR is the right option when the key must remain on the target system. Lamassu receives the request but never the private key.

Follow Issue your first certificate for the guided flow. Certificate management explains the inventory, inspection and revocation.

Revoke a CA

Revocation affects the entire dependent chain

Revoking a CA invalidates trust in the certificates it issued and can interrupt devices and services. The action is irreversible.

Assess the impact

Identify the certificates, devices and consumers that depend on the CA. Prepare a replacement authority and chain when necessary.

Start the revocation

Open the authority and select Revoke CA. Choose the reason that describes the incident, for example KeyCompromise, CACompromise, Superseded or CessationOfOperation.

Confirm the identity

Type the CA's name exactly to enable Confirm Revocation.

Check the publication

The status should change to REVOKED and the CRL should reflect the new information. The CA can no longer issue certificates.

Permanent deletion is only available after revoking. Delete the record only when your retention and audit policy allows it.

On this page