Issue your first certificate
Issue an X.509 identity from the console and verify the result.
In this quickstart Lamassu will generate the key and the CSR in the browser, and the CA will issue the certificate. When you finish you will download the certificate and its private key.
Before you begin
- An active CA with permission to issue certificates.
- A name for the identity, for example
device-001.example.internal. - A safe place to keep the downloaded private key.
The private key is delivered only once
In this flow the key is generated in the browser and Lamassu does not store it. Download it and protect it before closing the operation result.
Start the issuance
Open the CA created in the previous quickstart, go to Issued Certificates and select Issue New.
Choose the method
Select Generate Key & CSR in Browser. Use Upload Existing CSR when the private key must be generated and kept on the target system.
Identify the certificate
Enter the Common Name and, if applicable, the organization, organizational unit and location. Add SANs for each DNS name, IP address, email or URI the identity will be validated with.
Configure key and uses
Choose RSA or ECDSA, define the validity and select the key usages. For a device identity that uses mTLS, enable Digital Signature and Client Authentication.
The validity cannot exceed the expiration date of the issuing CA.
Issue and download
Confirm the issuance and immediately download the certificate and the private key in PEM format.
Verify the result
The certificate should appear in Issued Certificates with an active status. Check its subject, SANs, issuer, usages and validity period.
Next step
Register your first device to associate the identity with a managed entity, or see certificate management.