Use any other PKI

Firezone does not integrate with a particular PKI product. It validates whatever your certificate authority issues, so a provider without a guide here works exactly as well as one with a guide, provided it can meet the CA requirements and issue certificates meeting the certificate requirements.

The guides for Microsoft Cloud PKI, SCEPman, DigiCert and SecureW2 exist because those products name their settings differently, not because Firezone treats them differently.

What to check in an unfamiliar PKI

Three things vary between products, and each one can stop Device Trust working while every screen still looks correct.

Can the subject be a fixed literal? Firezone selects an identity by its subject, which must be exactly CN=dev.firezone.device-trust on every device. Many certificate templates assume the common name identifies the device or the user, and either force a variable or append to what you enter. A template that cannot hold a constant common name cannot issue a Firezone device identity.

Can it issue the URI SAN? The device identifier travels as a typed URI SAN, such as firezone://serial/C02ABC123, and your MDM supplies the per-device value at enrollment. The CA has to carry that through from the signing request rather than discarding it. This is the most common blocker: some PKI products support only email and DNS SANs, which cannot express a device identifier.

Does it set Client Authentication? The certificate needs the TLS Web Client Authentication EKU (1.3.6.1.5.5.7.3.2). Some products apply it by default, some take it from the request, and some need it set on the CA or the template.

Verify before deploying broadly

Inspect an issued certificate rather than trusting the profile configuration. A profile can look correct while the CA rewrites the subject or drops the requested SANs, and that is not visible anywhere except in the certificate itself.

Check that the issued certificate carries the fixed common name, the URI SAN with a real per-device value rather than an unresolved variable, and the client authentication EKU. Then deploy to a test device and confirm the Client reports all four conditions under Settings → Device Trust, as described in step 3 of Set up Device Trust.

If something does not line up, the troubleshooting guide is organized by symptom.

Linux and other non-MDM provisioning

An MDM is not required. Device Trust works with any certificate provisioning method, including a Linux deployment using PKCS#11 with a TPM. See the universal setup.

Next step

Add your CA's public certificates to Firezone as trust anchors, in step 2 of Set up Device Trust.


Need help? See all support options.