Lamassu IoT Docs

Devices and identities

Register devices and control their identities throughout the lifecycle.

A managed device represents an entity in your fleet and keeps the history of the certificates it has used. Lamassu separates the device from its current identity so you can renew or replace certificates without losing traceability.

Device states

  • Active indicates the device has a valid identity.
  • No Identity appears when it is registered but does not yet have an associated certificate.
  • Renewal Pending signals that it has entered the renewal window.
  • Expiring Soon warns that the certificate is close to expiring.
  • Expired indicates the identity has passed its validity date.
  • Revoked identifies a certificate invalidated before its expiration.
  • Decommissioned corresponds to a device permanently retired.

The inventory lets you filter by Device ID, tags and status.

Inspect a device

The detail view separates two perspectives:

  • Certificate History keeps every certificate associated with the device, with its serial number, issuer, status and validity period.
  • Device Event Timeline orders registrations, enrollments, renewals and status changes chronologically.

Use the history for audit and the timeline to reconstruct an incident or diagnose an unexpected transition.

Register a device manually

Pre-registration is useful when policy requires the device to exist before requesting its first certificate.

Create the device

From Managed Devices, open the registration form.

Define its membership

Enter a unique Device ID and select the DMS that will apply the enrollment and renewal policies.

Classify the device

Add an icon and tags if you need to group devices by model, location, environment or another operational criterion.

Verify the registration

The device should appear with status No Identity until it completes enrollment or receives a manually assigned identity.

Assign an identity manually

The Assign Identity action is available while the device remains in No Identity.

  1. Open the device and select Assign Identity.
  2. Choose an active certificate whose Common Name matches the Device ID.
  3. If none exists, select Issue New Instead and choose a CA linked to the DMS.
  4. Confirm the assignment.

The device should change to Active and the certificate should appear in its history.

Revoke the current identity

In Device Event Timeline, locate the latest active certificate and select Revoke. Choose a reason consistent with your policy and confirm the operation.

Revocation invalidates the certificate but does not delete the device. You can restore its operation by assigning it a new identity. CertificateHold allows reactivating the retained certificate; all other reasons are final.

Decommission a device

Decommission is irreversible

This action revokes all the device's certificates and prevents it from obtaining an identity again.

Use Decommission only when the device has stopped operating or is no longer trustworthy. After confirming, Lamassu revokes the active identity with CessationOfOperation and changes the status to Decommissioned.

Automate enrollment

On this page