Lamassu IoT Docs

Create your first CA

Create a root authority and check that it is ready to issue certificates.

In this quickstart you will create a root certification authority with a new key pair. When you finish you will have an active CA that you can use in the next quickstart.

Before you begin

  • Console access with permissions to manage authorities.
  • At least one cryptographic engine available.
  • A name that identifies the purpose of the CA, for example Acme Device Root CA.

Root or intermediate

A root CA is self-signed and acts as the anchor of trust. For production it is usually preferable to keep the root more protected and issue from an intermediate CA.

Open the creation wizard

In the side menu, open Certification Authorities and select Create New CA.

Choose to create a CA with a new key pair. If you already have the key in the KMS, use Create New CA (Existing Key).

Select the key

Choose the cryptographic engine that will keep the key and configure the algorithm. For a first CA you can use EC P-384, as long as it is compatible with your consumers.

The private key will remain under the control of the selected engine.

Define the authority

Select Root CA and complete:

  • CA Name: a unique, recognizable name.
  • Subject: at least the organization and country that will identify the authority.
  • CA Certificate Expiration: a validity longer than that of the certificates it will issue.
  • Default End-Entity Certificate Issuance Expiration: the default validity of end-entity certificates.

The CA name will be used as the certificate's Common Name.

Review and create the CA

Check the algorithm, subject and dates before confirming. These values define the anchor of trust and should not be chosen as throwaway test data in a production environment.

Verify the result

Open the new CA from the list. It should appear active and show its PEM certificate, the expiration date and the Issued Certificates tab.

Next step

Use the authority to issue your first certificate, or see the full authorities guide to create an intermediate CA, import a CA or define advanced profiles.

On this page