Appearance
Intel AMT Certificates and Renewal
Ordyn uses separate certificate identities for firmware activation, managed device connections, and AMT service enrollment. Each identity has its own recovery path.
Certificate purposes
| Certificate | Purpose | Scope | Validity | Maintenance starts |
|---|---|---|---|---|
| Activation authority | Trust anchor installed for ACM activation | One tenant and activation profile | 15 years | Root refresh is shown six years before expiry |
| Activation credential | Authenticates ACM provisioning under an activation authority | One AMT client and DNS suffix | 5 years | One year before expiry |
| Operational authority | Trust anchor for managed AMT TLS | One tenant | 15 years | Overlap rotation six years before expiry |
| Device server certificate | Authenticates one AMT firmware endpoint | One endpoint | 5 years | One year before expiry |
| AMT service enrollment certificate | Authenticates the AMT service client to Edge | One AMT client | Uses the normal service-client lifetime | Operator re-enrollment before expiry |
The AMT service enrollment certificate follows the common service-client certificate renewal workflow. It is independent of the tenant AMT authorities and device certificates.
Key profiles
Activation authorities and credentials use the profile selected when the activation credential is created:
- ECDSA P-384 with SHA-384
- RSA-2048 with SHA-256 for firmware that requires RSA activation material
Ordyn uses RSA-2048 operational authorities with SHA-256 as a compatibility policy across supported firmware generations. Device server keys are generated by firmware. Preflight selects RSA-2048 for AMT 11–14 and AMT 15 versions before 15.0.30.1545. AMT 15 beginning with 15.0.30.1545 and supported newer firmware prefer ECDSA P-384 with RSA-2048 available as a fallback.
This retry applies only to the operational device server certificate. ACM activation uses one selected activation credential for the provisioning attempt and any recovery. It does not retry activation with a different credential profile.
A supported device already provisioned in ACM can be adopted using its current Intel AMT administrator password. Adoption preserves its activation trust and does not require an Ordyn activation root or matching firmware PKI DNS suffix. Ordyn installs and verifies a new operational device server certificate before management begins. An interrupted adoption reuses the exact installed certificate when recovery verification succeeds, avoiding another firmware key request.
Automatic renewal
Ordyn starts device certificate maintenance one year before expiry. Certificate continuity is maintained even when the assigned configuration profile is in Audit only mode. Disabling the effective Intel AMT configuration profile for an endpoint stops communication and certificate maintenance for that endpoint.
For a device server certificate, Ordyn:
- requests a fresh key from firmware
- issues a five-year certificate from the current operational authority
- installs the required operational trust and the replacement certificate
- verifies the endpoint FQDN, platform identity, and certificate chain
- retires the old Ordyn-managed certificate after the replacement is verified
External certificates and trust roots remain untouched. If firmware certificate storage is full, renewal fails without deleting an external entry.
Activation credential renewal
An activation credential renews automatically under the same activation authority. Firmware that already trusts that authority does not need another setup.bin for a leaf-only renewal.
When the activation authority reaches its root-refresh period, the Activation Credentials table shows Setup trust refresh required. To move to a new root:
- Open
Administration>Certificate Authoritiesand open the activation authority. - Select
Rotate authorityand confirm the rotation. - Open
Administration>Services>Intel AMT>Activation Credentials. - Create a replacement activation credential with the required profile and DNS suffix.
- Generate a new setup artifact under
Software>Intel AMT Setup. - Apply the setup artifact to devices that must trust the replacement root.
The old root and credential can remain during the transition. An already managed endpoint uses its operational certificate for normal management; activation trust is needed when the endpoint is activated or provisioned again.
Operational authority rotation
Ordyn starts an operational-authority overlap six years before expiry. An administrator can also select Rotate authority on the authority detail page to begin the overlap immediately.
During the overlap, new and renewing endpoints receive certificates from the newest authority. The prior authority remains available while a live endpoint certificate still depends on it. It retires after certificate maintenance has moved the remaining managed identities away from it.
Use the Intel AMT configuration profile Check action to inspect current state. Use Remediate to force a fresh device certificate and apply the effective configuration. This is the manual renewal path; there is no separate certificate-renewal action in the endpoint Intel AMT menu.
An authority can remain Rotating while an endpoint is offline, cannot be inspected, or still reports a certificate issued by the prior authority. Run Check and then Remediate for reachable endpoints that still use the prior generation. The authority retires after every managed certificate from that generation has completed its replacement and removal workflow.
Lifecycle states
Ordyn displays these states for managed AMT certificates:
Current: valid and outside its renewal windowRenewal due: within the one-year renewal windowRenewal in progress: replacement material has been issued but is not fully verifiedRetiring: retained while the replacement is verified or another endpoint still depends on its authorityRetired: no longer selected for managed connectionsExpired: outside its validity period
View authority validity and Rotation due under Administration > Certificate Authorities. The authority Certificates tab contains issued-certificate history. The endpoint Hardware > Intel AMT > Certificates page shows the certificate store reported by firmware and associates recognized entries with their Ordyn lifecycle state.
Recovery after expiry
| Expired or unavailable identity | Result | Recovery |
|---|---|---|
| Activation credential leaf | New ACM activations cannot use that credential | Ordyn issues a new leaf under the same usable root. If the root is also due or expired, rotate the authority and apply a new setup artifact. |
| Activation authority | Firmware cannot validate credentials under a replacement root until it trusts that root | Rotate the authority, create a replacement credential, and apply a new setup artifact. Use the local firmware or OEM recovery workflow if the device cannot accept an artifact remotely. |
| Device server certificate or operational authority | Normal strict TLS management fails | Ordyn can use the last verified device identity for a bounded certificate-recovery operation, install a replacement, and return to normal strict TLS validation. If identity verification or network access fails, use local MEBx or OEM recovery. |
| AMT service enrollment certificate | The AMT client cannot authenticate to Edge | Issue a new service-client enrollment token, stop the AMT client, run forced enrollment, start it after enrollment succeeds, and confirm that it reconnects. |
Certificate recovery never accepts an arbitrary expired certificate. Ordyn requires the previously verified device identity and returns to normal CA and hostname validation after the replacement is installed.
Emergency rotation
For a suspected operational-authority compromise:
- Rotate the operational authority immediately.
- Run
Remediatefor affected Intel AMT configuration profiles. - Confirm that endpoints show current certificates from the replacement authority.
- Recover or deprovision endpoints that cannot be reached and still depend on the affected authority.
For a suspected activation-authority compromise, rotate the activation authority, disable the affected activation credentials, create replacements, and distribute a new setup artifact. Firmware that still trusts the affected root must be reset or have that trust removed through its supported local firmware workflow before the old root can be considered eliminated.
Ordyn does not publish a private AMT certificate revocation list. Private AMT trust incidents are handled through authority rotation, credential retirement, replacement certificate deployment, and removal of the affected firmware trust. Intel ODCA revocation data is a separate Intel trust workflow.
Download a fresh AMT recovery bundle after certificate or credential rotation.