Choose a certificate authority

Device Trust requires a certificate authority that you control and that Firezone trusts. The CA issues each managed device its identity, and its public certificates become your trust anchors.

Firezone does not issue device certificates and does not require a particular PKI product. Any CA works as long as it meets the requirements below. In practice the enrollment protocol your MDM supports usually decides the choice for you.

What Firezone requires of a CA

  • Issue X.509 client certificates meeting the certificate requirements, including TLS Web Client Authentication.
  • Speak the enrollment protocol your provisioning system uses, typically SCEP or ACME.
  • Issue the custom URI SANs requested in the signing request. Many certificate templates discard requested SANs by default, which is the most common reason a correctly configured profile still produces an unusable certificate.
  • Renew a certificate while preserving both its subject common name and its device identifier.
  • Publish CRL or OCSP endpoints, if you want revocation to take effect.

Choose your provider

ProviderNotes
Microsoft Cloud PKICloud CA built into Intune Suite. A good default if you manage devices with Intune and have no existing PKI.
SCEPmanCertificate service for SCEP enrollment.
DigiCert Trust Lifecycle ManagerManaged PKI and certificate lifecycle platform.
SecureW2 JoinNowManaged cloud PKI service.
Any other PKINo guide needed. What to check when your provider is not listed.

If you already have a PKI

You do not need a new CA. Export the public certificates for your root and every intermediate in the chain, then confirm your certificate template can issue the values listed above. Pay particular attention to custom URI SANs, which many templates discard unless explicitly configured to copy them from the request.

Next step

Add your CA's public certificates to Firezone as trust anchors, in step 2 of Set up Device Trust.


Need help? See all support options.