Skip to main content

Sectigo IoT Security & Identity Management

Formerly IoT PKI Manager

Give every connected device an identity of its own, so a device and the service it talks to can each prove what they are to the other.

LeaderTelecom is an Interested Party of the CA/Browser Forum.

Why device identity matters

Connected devices ship in volume, and many arrive with security settings that were never meant to hold up on a production network — missing, weak, or left at a factory default such as a shared password. That is the gap device identity closes:

  • Botnet recruitment and DDoS traffic
  • Remote control of the device
  • Spam relaying
  • Advanced persistent threats
  • Ransomware
  • Theft of personal and corporate data

A device that cannot prove what it is has to be taken at its word. A certificate replaces that word with something a service can check.

What the platform does

Sectigo issues the certificates and runs the management platform; how they reach your devices stays your decision.

  • An identity per device

    Each device carries its own certificate and private key, so the service can authenticate the device and the device can authenticate the service.

  • Issue, renew, revoke

    Certificates are requested, renewed and revoked from one place, which is what keeps a fleet manageable once it outgrows a spreadsheet.

  • Enrolment without a person in the loop

    Devices and build systems can request certificates programmatically, so issuance keeps up with production rather than waiting on someone to click.

Platform capabilities as described by Sectigo.

Who does what

Sectigo runs the PKI and the management platform. LeaderSSL handles your order, invoicing and renewals, and works out the scope with you before anything is committed.

Questions about device certificates

Is this the same as an SSL certificate for a website?

No. A website certificate proves a domain name to a browser. These certificates identify devices to the services they connect to, and the services back to the devices, which is why they are issued in volume and managed as a fleet rather than one at a time.

Who is it for?

Organisations that build or operate connected devices — manufacturers putting an identity into a product on the production line, and operators who have to keep a deployed fleet authenticated for years afterwards.

What happens after I send the request?

We come back to you to work out the scope: how many devices, how they enrol, and how long their certificates should live. Nothing is charged before that conversation.