Documentation

Guides and references for certificate authorities, certificate lifecycle management, ACME automation, revocation, storage, BYOK, Satellites, device deployment, workspaces, credentials, and API automation with SecuriTLS.

Quickstart

Start with your first CA, issue a certificate, and understand the main platform workflow.

CAs and certificate hierarchy

Create Root, Intermediate, and Leaf X.509 certificates for internal PKI and managed deployment flows.

ACME server

Use a SecuriTLS private CA with compatible ACME clients to automate certificate enrollment and renewal through a standard ACME directory.

Certificate lifecycle

Renew, rekey, reissue, revoke, and monitor certificates with hourly expiry detection and lifecycle controls.

Revocation endpoints

Understand CRL publishing, OCSP endpoints, Authority Information Access, and CRL Distribution Points.

Certificate extensions

Use Authority Key Identifier, Subject Key Identifier, AIA, and CRL extensions to validate issuer relationships.

Storage providers

Store and migrate certificates across Sia and AWS using provider managed or self managed storage modes.

Sia storage

Use decentralized storage by default with fragmented, encrypted storage distributed across Sia hosts.

AWS storage

Configure AWS S3 self managed storage using access keys or cross account role based access.

Key management and sensitive material flow

See how the Local Master Key, Storage Master Key, Platform DEK, Customer Storage DEK, and Satellite keys protect credentials, storage secrets, private keys, signing, and deployments.

BYOK and encryption

Protect private keys with AES 256 GCM, use Business or Enterprise storage BYOK to wrap SecuriTLS generated DEKs with AWS KMS, and use Satellites for true private key self custody.

AWS KMS setup

Configure Business or Enterprise storage BYOK with a customer managed KMS key, delegated role access, and wrapped DEKs.

Satellites

Run a lightweight SecuriTLS agent inside your environment for local deployments, private key self custody workflows, and certificate delivery without opening inbound firewall access.

Devices

Connect directly over SSH or use a Satellite to deploy certificate attachments, keys, chain files, and CRLs to target paths.

Deployment formats

Choose leaf only, full chain, combined PEM, separate key files, or encrypted PKCS#8 private key deployment.

CRL deployment

Deploy no CRL, a bundled CRL file, or per CA CRLs in a directory, with optional reload commands after updates.

Device status

Understand device status states such as Valid, Modified, No deployment attempted, and Unable to connect.

Credentials

Store Secret and RSA credentials securely for device access and decrypt them only when deployment requires it.

Workspaces and teams

Create shared workspaces, invite users by email or account ID, and separate ownership from operator access.

Permissions and RBAC

Define least privilege access for workspace members while keeping subscription control restricted to owners.

API

Authenticate with an API key, exchange it for a JWT, and browse supported endpoints through the Swagger reference.

Subscription tiers

Compare Free, Solo, Team, Business, and Enterprise availability for API access, workspaces, Satellites, BYOK, audits, storage, and support.

Deployments

Learn how attachments are pushed to devices directly or through Satellites, when deployments are needed, and how updates propagate.

Troubleshooting

Resolve common issues involving storage setup, device connectivity, Satellites, revocation behavior, and encryption configuration.