31 ms·
Awesome book. Just started reading it a week ago A more specific IoT question. For an IoT gateway, I look for a way to safely generate and revoke certificates
by gq0 5y ago
Awesome book. Just started reading it a week ago
A more specific IoT question. For an IoT gateway, I look for a way to safely generate and revoke certificates for different protocols and mTLS (certificate to be be installed on the counterpart of the gateway). Any tips on best practices or companies?
- ivanr 5y agoPersonally I'd go with a third-party service that will manage the PKI side of things, possibly two. That would relieve you of a big burden, leaving you to only invoke their APIs as needed. Most big CAs have specific IoT products. On the do-it-yourself side, take a look at Google's Certificate Authority Service https://cloud.google.com/certificate-authority-service https://cloud.google.com/certificate-authority-service and the AWS Certificate Manager Private Certificate Authority https://aws.amazon.com/certificate-manager/private-certificate-authority/ https://aws.amazon.com/certificate-manager/private-certifica... Another choice is EJBCA, and here's their documentation for the IoT use case: https://doc.primekey.com/ejbca/solution-areas/iot-and-device-identities https://doc.primekey.com/ejbca/solution-areas/iot-and-device... EJBCA is open source, but at least some of the IoT features (specifically those that deal with device enrolment) are enterprise-only.
- gq0 5y agoAwesome, many thanks for the recommendations. I will check it out.