Appearance
Certificate Authorities
Certificate authorities issue and establish trust for Ordyn endpoint, service-client, and Intel AMT certificates. Open Administration > Certificate Authorities to manage them.
The table shows each authority's purpose, scope, status, key profile, and expiry date. Use the search and purpose or status filters to find an authority.
Purposes
Each authority has one purpose:
Ordyn platformauthorities issue endpoint and service-client identity certificates. Their scope is global.Intel AMT operationalauthorities issue AMT firmware server certificates. Their scope is one tenant.Intel AMT activationauthorities establish the ACM provisioning trust seeded into Intel firmware and issue provisioning certificates. Their scope is one tenant and certificate profile.
Ordyn platform authorities use the platform certificate profile and are valid for 15 years. Intel AMT operational authorities use an RSA-2048 key with SHA-256 signatures for compatibility across supported firmware generations and are valid for 15 years. Intel AMT activation authorities use the selected ECC P-384 or RSA-2048 activation profile and are valid for 15 years.
Create an authority
Users with certificate authority creation permission can select Add Certificate Authority.
For an Ordyn platform authority, select Ordyn platform and provide a unique name. For an Intel AMT operational authority, select Intel AMT operational and choose the tenant. A tenant can have one active operational authority generation.
Ordyn creates an Intel AMT activation authority when the first activation credential for a tenant and certificate profile is created. Activation authorities cannot be created from the authority form. An active activation authority can be rotated from its detail page when firmware trust must move to a new root.
Authority details
Select an authority in the table to open its detail page.
The Overview tab shows the authority's scope, status, subject, serial number, key and signature profile, validity period, rotation state, and public certificate.
The Certificates tab contains a paginated history of certificates issued by that authority. The table identifies the certificate subject, usage, key and signature profile, serial number, status, issue time, and expiry time. Intel AMT activation credentials appear here with the Intel AMT provisioning usage. Retiring an activation credential retains its public certificate in this history.
Rotate an Intel AMT authority
Users with certificate authority management permission can select Rotate authority on an active Intel AMT operational authority. Confirming the action creates the next generation and starts an overlap period. The preceding generation remains available while Ordyn installs and verifies replacement device certificates.
The same action on an activation authority creates a replacement activation root. Create a replacement activation credential and apply a new setup.bin artifact to devices that must trust it. Existing managed connections continue to use their operational certificates.
The replacement generation opens after rotation. The authority list and detail pages show the active, rotating, retired, or expired state of each generation. See Intel AMT Certificates and Renewal for maintenance windows, overlap behavior, and expiry recovery.