-
Notifications
You must be signed in to change notification settings - Fork 13
Add external PKI provider documentation #482
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
Splits the PKI documentation out into multiple pages, adding documentation for how to set up AWS as an external PKI provider. The local PKI guide is also split into a separate page, which gets linked to from the main PKI page, alongside a link to the AWS page. Signed-off-by: Trond Snekvik <trond@golioth.io>
|
Visit the preview URL for this PR (updated for commit ccc343a): https://golioth-docs-dev--pr482-pki-providers-fvkbbyae.web.app (expires Sat, 03 Jan 2026 11:13:55 GMT) 🔥 via Firebase Hosting GitHub Action 🌎 Sign: f53b02bdc98ce6f5593931ec4c339aa96bac84df |
beriberikix
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Small comments, excited for this!
| To verify the certificate the device presented, Golioth goes through a list of | ||
| known CAs for your project. If the device's certificate was signed by one of the | ||
| known CAs, Golioth can trust the information within it, and the device can | ||
| start sending and receiving data. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nit. could be a good place to mention ZTP and link to the subsection below.
| If you do not have a PKI provider service set up, but still want to leverage | ||
| certificate authentication in your development process, you can also [establish | ||
| local PKI](./2-local-pki.md) with [`openssl`](https://github.com/openssl/openssl). |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
and CFSSL? Or are we removing examples of it?
| the certificate. The sole purpose of this identifier is to associate the | ||
| physical device with a device on the Golioth platform. While a device's | ||
| certificate ID may match other device attributes, such as the device name, it | ||
| does not specifically connotate any other meaning. Using a dedicated identifier |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
any other meaning on the Golioth platform?
Splits the PKI documentation out into multiple pages, adding documentation for how to set up AWS as an external PKI provider.
The local PKI guide is also split into a separate page, which gets linked to from the main PKI page, alongside a link to the AWS page.