Lamassu IoT Docs

Issue your first certificate

Issue an X.509 identity from the console and verify the result.

In this quickstart Lamassu will generate the key and the CSR in the browser, and the CA will issue the certificate. When you finish you will download the certificate and its private key.

Before you begin

  • An active CA with permission to issue certificates.
  • A name for the identity, for example device-001.example.internal.
  • A safe place to keep the downloaded private key.

The private key is delivered only once

In this flow the key is generated in the browser and Lamassu does not store it. Download it and protect it before closing the operation result.

Start the issuance

Open the CA created in the previous quickstart, go to Issued Certificates and select Issue New.

Choose the method

Select Generate Key & CSR in Browser. Use Upload Existing CSR when the private key must be generated and kept on the target system.

Identify the certificate

Enter the Common Name and, if applicable, the organization, organizational unit and location. Add SANs for each DNS name, IP address, email or URI the identity will be validated with.

Configure key and uses

Choose RSA or ECDSA, define the validity and select the key usages. For a device identity that uses mTLS, enable Digital Signature and Client Authentication.

The validity cannot exceed the expiration date of the issuing CA.

Issue and download

Confirm the issuance and immediately download the certificate and the private key in PEM format.

Verify the result

The certificate should appear in Issued Certificates with an active status. Check its subject, SANs, issuer, usages and validity period.

Next step

Register your first device to associate the identity with a managed entity, or see certificate management.

On this page