How Lamassu works
The mental model of trust, keys, certificates and devices.
Lamassu connects three elements: a root of trust, an issuance policy and an entity that needs to prove its identity. The platform coordinates these elements throughout the certificate lifecycle.
The model in five pieces
Cryptographic engine. Generates or safeguards keys and executes private-key operations without exposing key material to the rest of the services.
Certification Authority (CA). Signs certificates and establishes the chain of trust.
Device Management Service (DMS). Defines how the devices of a fleet are registered, authenticated and renewed.
Device. Keeps its private key and presents the certificate to prove its identity.
Validation Authority (VA). Publishes the status of certificates through OCSP and CRL.
From onboarding to operation
- An administrator configures a cryptographic engine and creates or imports a CA.
- A DMS relates that CA to an enrollment policy.
- The device generates a key and requests a certificate through EST, or an operator assigns it an identity.
- Lamassu keeps the inventory, history and status of the identity.
- Consumers check the chain and query OCSP or a CRL when they need to know whether it is still valid.