Skip to content

Conversation

@trond-snekvik
Copy link
Contributor

Splits the PKI documentation out into multiple pages, adding documentation for how to set up AWS as an external PKI provider.

The local PKI guide is also split into a separate page, which gets linked to from the main PKI page, alongside a link to the AWS page.

Splits the PKI documentation out into multiple pages, adding documentation for
how to set up AWS as an external PKI provider.

The local PKI guide is also split into a separate page, which gets linked to
from the main PKI page, alongside a link to the AWS page.

Signed-off-by: Trond Snekvik <trond@golioth.io>
@github-actions
Copy link

github-actions bot commented Dec 4, 2025

Visit the preview URL for this PR (updated for commit ccc343a):

https://golioth-docs-dev--pr482-pki-providers-fvkbbyae.web.app

(expires Sat, 03 Jan 2026 11:13:55 GMT)

🔥 via Firebase Hosting GitHub Action 🌎

Sign: f53b02bdc98ce6f5593931ec4c339aa96bac84df

Copy link
Contributor

@beriberikix beriberikix left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Small comments, excited for this!

Comment on lines +24 to +27
To verify the certificate the device presented, Golioth goes through a list of
known CAs for your project. If the device's certificate was signed by one of the
known CAs, Golioth can trust the information within it, and the device can
start sending and receiving data.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit. could be a good place to mention ZTP and link to the subsection below.

Comment on lines +49 to +51
If you do not have a PKI provider service set up, but still want to leverage
certificate authentication in your development process, you can also [establish
local PKI](./2-local-pki.md) with [`openssl`](https://github.com/openssl/openssl).
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

and CFSSL? Or are we removing examples of it?

the certificate. The sole purpose of this identifier is to associate the
physical device with a device on the Golioth platform. While a device's
certificate ID may match other device attributes, such as the device name, it
does not specifically connotate any other meaning. Using a dedicated identifier
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

any other meaning on the Golioth platform?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants