Skip to main content

Request certificates for unmanaged devices

Unmanaged devices

An unmanaged device is a physical device for which Device Trust Manager issues a certificate without creating or referencing a device record. Device Trust Manager manages the certificate, but it does not maintain the underlying device as part of its device inventory.

Consequently, users do not receive device-level tracking, lifecycle management, or ongoing device-management capabilities such as over-the-air updates through that certificate request.

This option is suitable when an organization needs only a certificate-based identity—for example, a Matter Device Attestation Certificate, C2PA claim-signing certificate, or a certificate used during manufacturing or provisioning.

Each issued certificate consumes one Essentials license, and renewing the certificate consumes another license. These certificates are found under Certificate management > Certificates, not under Device management > Devices.

To perform this action, you must have a user role that contains the Device administrator permission.

Use this workflow to request a certificate that isn't associated with a device record in Device Trust Manager.

Unlike certificate requests for managed devices, Unmanaged device certificates are issued without creating or referencing a device. This option is designed for organizations that need certificate-based device identities but don't require device inventory, lifecycle management, or device tracking.

This is designed for organizations that only need device identity certificates, such as:

  • CSA Matter Device Attestation Certificates (DACs)

  • C2PA claim signing certificates

  • Manufacturing and provisioning workflows

  • Device identity certificates that don't require ongoing device management

When you request an Unmanaged device certificate, Device Trust Manager issues only the certificate. No device record is created.

注意

Requesting a certificate for unmanaged devices consume an Essentials license.

Before you begin

  • Make sure your account has the Device administrator permission.

  • Also verify that your Solution Administrator has already completed the following setup tasks:

  1. In the Device Trust Manager menu, go to Certificate management > Certificates.

  2. Select Certificate actions > Request certificate.

  3. From the Certificate request page, select Request certificate for > Unmanaged device.

  4. From the Certificate management policy list, select the policy associated with the device group.

  5. On the Key generation type step, choose one of the available options:

    1. I have the keypair and will provide the CSR or public key in the request:

      • Choose this option if you already have a key pair. You must upload a CSV file or a ZIP file containing the device data.

      • If needed, download the provided template to ensure the file is formatted correctly.

    2. Key pairs will be generated on the server side by this application, and the private key and certificate will be included in response:

      Choose this option if you want Device Trust Manager to generate the key pair for you.

    提示

    Key generation type behavior

    The Key generation type option is dynamically displayed based on the selected Device group and the associated Certificate management policy. Only the key generation methods that are supported by the chosen combination are presented to you.

  6. Provide a Common name for the certificate.

  7. Optionally, provide an Organization name.

  8. Optionally, select Add Value to add one or more Organizational Unit values.

  9. Optionally, enter a Description.

  10. Select Submit certificate request.

What happens next

After the certificate request is successfully processed:

  • The certificate is issued

  • No device record is created or associated with the certificate

  • You can download the certificate from Device Trust Manager

  • If server-side key generation was selected (Key pairs will be generated on the server side by this application, and the private key and certificate will be included in response),the response also includes the generated private key.

Example scenario

A device manufacturer needs to issue CSA Matter Device Attestation Certificates (DACs) during production. Because the certificates are used only to establish device identity and don't require lifecycle management, certificate requests for unmanaged devices provide a simple way to issue certificates without creating device records.

To perform this action, you must have a user role that contains the Device administrator permission.

Use this workflow to request a batch of certificates for multiple unmanaged devices in a single operation without creating or associating device records in Device Trust Manager.

Unlike batch certificate request for managed devices, certificate requests for unmanaged devices in a batch focus only on certificate issuance. This option is designed for organizations that need certificates at scale but don't require device inventory, lifecycle management, or device tracking.

This is designed for organizations that need large-scale certificate issuance for use cases such as:

  • CSA Matter Device Attestation Certificates (DACs)

  • C2PA claim signing certificates

  • Manufacturing and provisioning workflows

  • Device identity certificates that don't require ongoing management

  • High-volume certificate issuance without device registration

When you request certificates for multiple unmanaged devices, Device Trust Manager issues only the certificates. No device records are created or associated with the certificates.

注意

Requesting certificates for multiple unmanaged devices consume an Essentials license.

Before you begin

  • Make sure your account has the Device administrator permission.

  • Also verify that your Solution Administrator has already completed the following setup tasks:

    • Created a certificate management policy

    • While creating the certificate management policy, you have selected the following options:

      • Under the Select the certificate management model, Policy will be used for certificate issuance only. Requires an Essentials license.

      • Under the Certificate management methods, Batch certificate request through portal and REST API.

  • Prepared a CSV file containing device information, such as Device name, Description, and Subject Common Name (CN).

  1. In the Device Trust Manager menu, go to Certificate management > Certificates.

  2. Select Certificate actions > Batch certificate request.

  3. On the Batch certificate request page, select Request batch of certificate for > Unmanaged devices.

  4. Under the General settings section, provide a name for the batch job, and optionally, a Job description.

  5. Select Next.

  6. Under the Certificate request options, select the Certificate management policy associated with the device group.

  7. On the Key generation type step, choose one of the available options:

    1. I have generated the key pairs and will provide CSRs or public keys in this batch request.

      • Choose this option if you already have the key pairs. You must upload a CSV file or a ZIP file containing the device data.

      • If needed, download the provided template to ensure the file is formatted correctly.

      提示

      Key generation type behavior

      The Key generation type option is dynamically displayed based on the selected Device group and the associated Certificate management policy. Only the key generation methods that are supported by the chosen combination are presented to you.

    2. Key pairs will be generated as part of the batch job, and the private keys and certificates will be included in the batch response.

      1. From the Private key encryption in batch response step, perform one of the following:

        • Select Encrypt using an authentication certificate from my Account Manager user profile - chose an appropriate certificate from the list.

        • Select Provide a certificate for encryption - provide your own certificate.

        • Select Generate a new certificate within your profile - specify the required fields and generate a new certificate profile.

  8. Select Next.

  9. Select Submit batch job request to begin the batch certificate request.

Example scenario

A manufacturer needs to issue thousands of CSA Matter Device Attestation Certificates (DACs) during production. Because the certificates are used only to establish device identity and don't require device lifecycle management, the manufacturer can request certificates in bulk without creating device records, simplifying the provisioning process while maintaining trusted device identities.