Lamassu IoT Docs

Certificate lifecycle

Issuance, use, renewal, revocation and retirement of certificates in Lamassu.

Issuing a certificate is only the beginning. During its useful life you must check its validity, renew it before it expires and retire it when it stops being trustworthy. Lamassu keeps the certificate, its issuing CA, its status and, when it belongs to a device, the identity it is linked to.

The full journey

Request

The requester generates a key and a CSR. In the recommended flows, the private key stays in the device, browser or cryptographic engine that created it.

Issuance

The CA signs the CSR. The issuance profile determines the validity, uses, subject, allowed extensions and cryptographic constraints.

Use and monitoring

The certificate enters the ACTIVE state. Lamassu monitors its Not After date; the cryptographic monitoring job marks certificates that have expired as EXPIRED.

Renewal or re-enrollment

A new certificate is issued before the previous one expires. In a DMS you can open preventive and critical windows so the device re-enrolls through EST.

Revocation or retirement

If the identity stops being trustworthy, Lamassu records the reason and time of revocation. OCSP and CRLs let consumers learn that status.

Certificate states

Lamassu persists four X.509 states:

  • ACTIVE: the certificate is enabled and within its validity period.
  • EXPIRED: it has passed its expiration date. The monitor detects this periodically; it is not a state that should be assigned manually.
  • REVOKED: it was invalidated before expiring, with a reason and a timestamp.
  • INACTIVE: it is disabled without representing a definitive revocation.

The device view may add operational states such as missing identity, pending renewal, expiring soon or decommissioned. These are an interpretation of the device's status and its certificates, not new X.509 states.

Renewal and revocation are not equivalent

Renewal creates a successor certificate for an identity that remains valid. Revocation communicates that the current certificate must no longer be accepted. Renew to maintain continuity; revoke in response to compromise, retirement or a change that invalidates the identity.

Only a revocation with the reason CertificateHold can be undone. A revocation with any other reason is final in Lamassu.

Reissuing a CA reuses its key

The Reissue CA operation generates another certificate for the same key and links both serial numbers through metadata. It is not a key rotation. To change the key, create a successor CA and perform a migration with an overlapping period.

Effect of revoking a CA

Revoking a CA is a cascading operation. Lamassu revokes its child CAs and the certificates it issued, with the reason CessationOfOperation. The propagation continues down the hierarchy.

Before confirming:

  1. Identify DMSs, devices and services that trust that chain.
  2. Distribute the new chain of trust.
  3. Reissue the necessary identities.
  4. Check OCSP and CRL from a real consumer.
  5. Revoke the old CA once no legitimate traffic remains.

Decommission is irreversible

Decommissioning a device revokes its certificates and prevents it from obtaining new identities. Use this action only when the device is being retired permanently.

What you should watch

  • Certificates entering the preventive or critical renewal window.
  • Repeated enrollment or re-enrollment failures.
  • Status changes and revocation reasons.
  • OCSP and CRL publication and validity.
  • Dependencies still presenting a replaced certificate.

The device history relates its previous and current identities. For administrative changes and mutation errors, see Audit logs.

On this page