Skip to content

Intel AMT Certificates and Renewal

Ordyn uses separate certificate identities for firmware activation, managed device connections, and AMT service enrollment. Each identity has its own recovery path.

Certificate purposes

CertificatePurposeScopeValidityMaintenance starts
Activation authorityTrust anchor installed for ACM activationOne tenant and activation profile15 yearsRoot refresh is shown six years before expiry
Activation credentialAuthenticates ACM provisioning under an activation authorityOne AMT client and DNS suffix5 yearsOne year before expiry
Operational authorityTrust anchor for managed AMT TLSOne tenant15 yearsOverlap rotation six years before expiry
Device server certificateAuthenticates one AMT firmware endpointOne endpoint5 yearsOne year before expiry
AMT service enrollment certificateAuthenticates the AMT service client to EdgeOne AMT clientUses the normal service-client lifetimeOperator re-enrollment before expiry

The AMT service enrollment certificate follows the common service-client certificate renewal workflow. It is independent of the tenant AMT authorities and device certificates.

Key profiles

Activation authorities and credentials use the profile selected when the activation credential is created:

  • ECDSA P-384 with SHA-384
  • RSA-2048 with SHA-256 for firmware that requires RSA activation material

Ordyn uses RSA-2048 operational authorities with SHA-256 as a compatibility policy across supported firmware generations. Device server keys are generated by firmware. Preflight selects RSA-2048 for AMT 11–14 and AMT 15 versions before 15.0.30.1545. AMT 15 beginning with 15.0.30.1545 and supported newer firmware prefer ECDSA P-384 with RSA-2048 available as a fallback.

This retry applies only to the operational device server certificate. ACM activation uses one selected activation credential for the provisioning attempt and any recovery. It does not retry activation with a different credential profile.

A supported device already provisioned in ACM can be adopted using its current Intel AMT administrator password. Adoption preserves its activation trust and does not require an Ordyn activation root or matching firmware PKI DNS suffix. Ordyn installs and verifies a new operational device server certificate before management begins. An interrupted adoption reuses the exact installed certificate when recovery verification succeeds, avoiding another firmware key request.

Automatic renewal

Ordyn starts device certificate maintenance one year before expiry. Certificate continuity is maintained even when the assigned configuration profile is in Audit only mode. Disabling the effective Intel AMT configuration profile for an endpoint stops communication and certificate maintenance for that endpoint.

For a device server certificate, Ordyn:

  1. requests a fresh key from firmware
  2. issues a five-year certificate from the current operational authority
  3. installs the required operational trust and the replacement certificate
  4. verifies the endpoint FQDN, platform identity, and certificate chain
  5. retires the old Ordyn-managed certificate after the replacement is verified

External certificates and trust roots remain untouched. If firmware certificate storage is full, renewal fails without deleting an external entry.

Activation credential renewal

An activation credential renews automatically under the same activation authority. Firmware that already trusts that authority does not need another setup.bin for a leaf-only renewal.

When the activation authority reaches its root-refresh period, the Activation Credentials table shows Setup trust refresh required. To move to a new root:

  1. Open Administration > Certificate Authorities and open the activation authority.
  2. Select Rotate authority and confirm the rotation.
  3. Open Administration > Services > Intel AMT > Activation Credentials.
  4. Create a replacement activation credential with the required profile and DNS suffix.
  5. Generate a new setup artifact under Software > Intel AMT Setup.
  6. Apply the setup artifact to devices that must trust the replacement root.

The old root and credential can remain during the transition. An already managed endpoint uses its operational certificate for normal management; activation trust is needed when the endpoint is activated or provisioned again.

Operational authority rotation

Ordyn starts an operational-authority overlap six years before expiry. An administrator can also select Rotate authority on the authority detail page to begin the overlap immediately.

During the overlap, new and renewing endpoints receive certificates from the newest authority. The prior authority remains available while a live endpoint certificate still depends on it. It retires after certificate maintenance has moved the remaining managed identities away from it.

Use the Intel AMT configuration profile Check action to inspect current state. Use Remediate to force a fresh device certificate and apply the effective configuration. This is the manual renewal path; there is no separate certificate-renewal action in the endpoint Intel AMT menu.

An authority can remain Rotating while an endpoint is offline, cannot be inspected, or still reports a certificate issued by the prior authority. Run Check and then Remediate for reachable endpoints that still use the prior generation. The authority retires after every managed certificate from that generation has completed its replacement and removal workflow.

Lifecycle states

Ordyn displays these states for managed AMT certificates:

  • Current: valid and outside its renewal window
  • Renewal due: within the one-year renewal window
  • Renewal in progress: replacement material has been issued but is not fully verified
  • Retiring: retained while the replacement is verified or another endpoint still depends on its authority
  • Retired: no longer selected for managed connections
  • Expired: outside its validity period

View authority validity and Rotation due under Administration > Certificate Authorities. The authority Certificates tab contains issued-certificate history. The endpoint Hardware > Intel AMT > Certificates page shows the certificate store reported by firmware and associates recognized entries with their Ordyn lifecycle state.

Recovery after expiry

Expired or unavailable identityResultRecovery
Activation credential leafNew ACM activations cannot use that credentialOrdyn issues a new leaf under the same usable root. If the root is also due or expired, rotate the authority and apply a new setup artifact.
Activation authorityFirmware cannot validate credentials under a replacement root until it trusts that rootRotate the authority, create a replacement credential, and apply a new setup artifact. Use the local firmware or OEM recovery workflow if the device cannot accept an artifact remotely.
Device server certificate or operational authorityNormal strict TLS management failsOrdyn can use the last verified device identity for a bounded certificate-recovery operation, install a replacement, and return to normal strict TLS validation. If identity verification or network access fails, use local MEBx or OEM recovery.
AMT service enrollment certificateThe AMT client cannot authenticate to EdgeIssue a new service-client enrollment token, stop the AMT client, run forced enrollment, start it after enrollment succeeds, and confirm that it reconnects.

Certificate recovery never accepts an arbitrary expired certificate. Ordyn requires the previously verified device identity and returns to normal CA and hostname validation after the replacement is installed.

Emergency rotation

For a suspected operational-authority compromise:

  1. Rotate the operational authority immediately.
  2. Run Remediate for affected Intel AMT configuration profiles.
  3. Confirm that endpoints show current certificates from the replacement authority.
  4. Recover or deprovision endpoints that cannot be reached and still depend on the affected authority.

For a suspected activation-authority compromise, rotate the activation authority, disable the affected activation credentials, create replacements, and distribute a new setup artifact. Firmware that still trusts the affected root must be reset or have that trust removed through its supported local firmware workflow before the old root can be considered eliminated.

Ordyn does not publish a private AMT certificate revocation list. Private AMT trust incidents are handled through authority rotation, credential retirement, replacement certificate deployment, and removal of the affected firmware trust. Intel ODCA revocation data is a separate Intel trust workflow.

Download a fresh AMT recovery bundle after certificate or credential rotation.