Configure certificates for extended offline periods
In scenarios where an Avassa-managed site is expected to be offline for extended periods, such as 6 months, the system's certificates must be configured accordingly to ensure seamless reconnection when the site returns online. Typically, setting the disconnected-grace-period is sufficient, as default values for certificates are automatically derived from it.
Device certificate enrollment
Why devices need certificates of their own, how automated certificate enrollment works in Avassa, and how SCEP and EST each serve a different part of the fleet.
Enroll devices with EST
How to let devices enroll and renew certificates with EST (RFC 7030): enable EST on a Strongbox TLS CA, choose between a shared secret and per-device birth certificates, renew automatically, and enroll post-quantum ML-DSA credentials.
Keep a CA's key in AWS KMS
Keep a root CA's private key in AWS KMS: configure a key-store CA, adopt an existing KMS key, issue intermediates for site-side issuance, and plan for disaster recovery.
Post-quantum cryptography
Avassa's approach to post-quantum cryptography: ML-KEM key exchange and ML-DSA certificates, why key exchange is the urgent half, and how the platform is designed to make the migration routine.
Public key infrastructure
How the pieces of the Avassa PKI fit together: certificate authorities, issuance and enrollment, revocation, expiry monitoring, rollover, and where each part runs.
SCEP Certificate Enrollment
Learn how to enable SCEP certificate enrollment for TLS CAs so that network devices and MDM-managed endpoints can automatically obtain certificates.
Set up ACME Certificate Provisioning
This guide explains how to configure automatic certificate
SPIFFE support
Overview of SPIFFE support in Avassa. Learn about SPIFFE IDs, SVIDs, trust domains, and how Avassa uses them for authentication and mTLS.
SSH Certificates
Learn how to manage SSH certificates in Avassa for secure access and authentication. Follow step-by-step instructions to configure and use SSH certificates.
SSL/TLS CA
Learn how to configure SSL CA in Avassa with this step-by-step guide. Secure your connections and manage certificates effectively.
Strongbox: Secrets management
Understand how Avassa Strongbox protects secrets across distributed edge sites: sealing, distribution, vaults, crypto functions, and certificate management.