Passbeam

Can an appliance get and renew its own certificate?

Yes, if it supports EST. EST is the standard way for a device to ask for a certificate and renew it before it expires. Axis cameras on AXIS OS 12.10 or newer support it, and so do Aruba AOS-CX switches, Cisco IOS XE and FortiGate.

Add the device in Passbeam first. Passbeam > Clients > your client > Certificates > Appliances > Add an appliance > The device enrols itself (EST). Nothing can enrol unless it has been added.

Choose how it proves which device it is. A device with a manufacturer certificate, such as an Axis camera's device ID, uses the serial number on its label. Anything else gets a username and a one-time password, which works once and lasts 7 days.

Certificates → Appliances → Add an appliance. A camera with a manufacturer certificate needs only its name and the serial on its label.

Then on the device, add an EST server with the URL Passbeam shows you. It starts https://est.passbeam.co.uk/.well-known/est/ and ends with your client's ID. If the device asks for a CA certificate for the EST server, upload ISRG Root X1 from letsencrypt.org. For 802.1X it also needs your client's root CA, which you can download from the same page.

What to enter on the device. The one-time password is shown once.

On an Axis camera the EST settings are URL, Services (choose IEEE 802.1X), Client certificate (choose the Axis device ID) and CA certificates.

After that the device renews on its own, using the certificate it was given. The Appliances list shows when it enrolled, when it last renewed, and why if it was refused.

Certificates → Appliances. Each device shows when it enrolled or last renewed, or why it was refused.

To stop a device renewing, remove it from that list. Its current certificate keeps working until it expires or you revoke it.

The device needs to reach est.passbeam.co.uk on TCP 443.

Related questions

Still stuck? Ask us, or read the rest of the knowledge base.