Request certificates for managed devices
Managed devices
A managed device is a physical device that has a device record in Device Trust Manager. Certificates issued to a managed device are associated with that device record, allowing organizations to track the device in a central inventory and manage it throughout its operational lifecycle.
A device that is manged by Device Trust Manager supports capabilities such as bootstrap certificates for initial onboarding, operational certificates for ongoing authentication, automated certificate workflows, multiple certificates per device, and over-the-air software updates.
Every managed device must belong to a Device group, through which policies, configurations, and updates can be applied consistently.
Registering a managed device consumes one Advanced device license; additional certificates can then be issued to that device without consuming additional licenses.
Registered devices appear under Device management > Devices.
To perform this action, you must have a user role that contains the Device administrator permission.
Use this workflow to request a certificate for a specific device. This certificate is linked to a device record in Device Trust Manager, allowing you to manage the device throughout its lifecycle.
This is intended for organizations that need full device management capabilities, such as:
Tracking devices in a central inventory
Managing device lifecycles
Issuing bootstrap certificates for onboarding
Issuing operational certificates for ongoing device authentication
Anmerkung
Requesting a device certificate for managed devices consumes an Advanced license.
Before you begin
Make sure your account has the
Device administratorpermission.Also verify that your
Solution Administratorhas already completed the following setup tasks:Created a device group
Created a certificate management policy
Prepared a CSV file containing device information, such as Device name, Description, and Subject Common Name (CN).
In the Device Trust Manager menu, go to Certificate management > Certificates.
Select Certificate actions > Request certificate.
From the Certificate request page, select Request certificate for > Managed device.
From the Device group list, select the device group that contains the device.
From the Certificate management policy list, select the policy associated with the device group.
On the Key generation type step, choose one of the available options:
I have the keypair and will provide the CSR or public key in the request:
Choose this option if you already have a key pair. You must upload a
CSV fileor aZIP filecontaining the device data.If needed, download the provided template to ensure the file is formatted correctly.
Key pairs will be generated on the server side by this application, and the private key and certificate will be included in response:
Choose this option if you want Device Trust Manager to generate the key pair for you.
Tipp
Key generation type behavior
The Key generation type option is dynamically displayed based on the selected Device group and the associated Certificate management policy. Only the key generation methods that are supported by the chosen combination are presented to you.
Provide a Common name for the certificate.
Optionally, provide an Organization name.
Optionally, select Add Value to add one or more Organizational Unit values.
Optionally, enter a Description.
Select Submit certificate request.
What happens next
The certificate is issued and is associated with the device record.
You can download the certificate from Device Trust Manager.
If server-side key generation was selected (Key pairs will be generated on the server side by this application, and the private key and certificate will be included in response), the response also includes the generated private key.
Example scenario
A manufacturer needs to issue a bootstrap certificate to a newly produced IoT gateway before deployment. By requesting a certificate for managed devices, the manufacturer can create or associate a device record, issue the certificate, and manage the device throughout its operational lifecycle from a single platform.
To perform this action, you must have a user role that contains the Device administrator permission.
Use this workflow to request a batch of certificates for multiple managed devices in a single operation. Each certificate will be associated with a device record in Device Trust Manager, allowing you to register and manage devices at scale.
This is intended for organizations that need full device management capabilities across large device fleets, such as:
Bulk onboarding of devices into a central inventory
Managing device lifecycles at scale
Issuing bootstrap certificates during manufacturing or provisioning
Issuing operational certificates for ongoing device authentication
Enabling automated certificate renewal, secure firmware updates, and device monitoring
When you request a batch of certificates for multiple managed devices, Device Trust Manager issues the certificates and creates or associates device records for each device in the batch.
Anmerkung
Requesting a batch of certificates for multiple managed devices consume an Advanced license.
Before you begin
Make sure your account has the
Device administratorpermission.Also verify that your
Solution Administratorhas already completed the following setup tasks:Created a device group
Created a certificate management policy
While creating the certificate management policy, you have selected the following options:
Under the Select the certificate management model, Policy will be used for secure device lifecycle management. Requires an Advanced license.
Under the Certificate management methods, Batch certificate request through portal and REST API.
Prepared a CSV file containing device information, such as Device name, Description, and Subject Common Name (CN).
In the Device Trust Manager menu, go to Certificate management > Certificates.
Select Certificate actions > Batch certificate request.
On the Batch certificate request page, select Request batch of certificate for > Managed devices.
Under the General settings section, provide a name for the batch job, and optionally, a Job description.
From the Device group list, select the device group that contains the devices.
Select Next.
Under the Certificate request options, select the Certificate management policy associated with the device group.
On the Key generation type step, choose one of the available options:
I have generated the key pairs and will provide CSRs or public keys in this batch request.
Choose this option if you already have the key pairs. You must upload a CSV file or a ZIP file containing the device data.
If needed, download the provided template to ensure the file is formatted correctly.
Tipp
Key generation type behavior
The Key generation type option is dynamically displayed based on the selected Device group and the associated Certificate management policy. Only the key generation methods that are supported by the chosen combination are presented to you.
Key pairs will be generated as part of the batch job, and the private keys and certificates will be included in the batch response.
From the Private key encryption in batch response step, perform one of the following:
Select Encrypt using an authentication certificate from my Account Manager user profile - chose an appropriate certificate from the list.
Select Provide a certificate for encryption - provide your own certificate.
Select Generate a new certificate within your profile - specify the required fields and generate a new certificate profile.
Select Next.
Select Submit batch job request to begin the batch certificate request.