Skip to content

PKI ceremony

Establish trust anchors for Edge device mTLS (Devices CA) and signed RAUC update bundles (Updates CA).

Full ceremony steps: pki-ceremony.md at monorepo root.

CAUseDistribution
Root CAOffline trust anchorCold storage; never in runtime env
Devices CAEdge client certificates at claim-completeKey Vault → Backend/Ingestor; chain to devices
Updates CARAUC bundle signingADO secret variable group only

Backend/testdata/pki/ — OpenSSL-generated, test-only. Do not use in production.