Skip to main content

Downloads & install

The Downloads & install screen (page heading Install Sectigo Edge locally) is where you get every component that runs in your own environment, together with ready-to-copy commands that verify the release before anything is installed.

ConsoleDownloads & install

What it's for​

  • Download the Mesh Node for Linux, Windows or Kubernetes.
  • Download the operator CLI and the optional private signer.
  • Verify that a release is authentic before installing it.
  • Create the one-time enrollment package a new node needs.

What you see​

Downloads and install screen with the local stack overview, verified release banner, four download cards and the four-step Connect a local environment guide
Downloads & install.

The screen has five parts.

1. What runs in your environment​

Your private PKI control point lists the components and whether you need them:

ComponentDescription in the console
Mesh NodeRequired · Windows, Linux, or Kubernetes
Operator CLIHealth, discovery, events, enrollment, and MCP
Private signerOptional · isolate signing behind your policy boundary
SDKs and adaptersACME, SPIFFE, EST, ADCS, NGINX, Apache, and Kubernetes

Start with one Mesh Node. Add redundant nodes, the CLI, a private signer and the read-only MCP bridge only where your architecture needs them. Every component connects outbound; CA keys and local credentials stay under your control.

Shortcut links jump to the Linux, Windows and Kubernetes cards.

2. Verified release banner​

Shows the current release, for example Sectigo Edge v0.1.26. Every package is built from the tagged source and comes with three verification files:

ButtonFileUse it to
ChecksumsSHA256SUMSCheck the SHA-256 digest of each download.
SBOMsbom.spdx.jsonReview the SPDX software bill of materials.
Sigstore proofmanifest.sigstore.jsonVerify keyless build provenance with cosign.

3. Download cards​

CardDownloadsCommands shown
Mesh Node (LINUX · AMD64)Download Linux node, Installer script, systemd unit, plus links to the NGINX and Apache adapter guidesDownload and authenticate, Upgrade an enrolled node in place
Mesh Node for Windows (WINDOWS · AMD64)Download Windows node, PowerShell installer, UninstallerDownload and authenticate, Upgrade an enrolled node in place
Helm deployment (KUBERNETES)Download Helm chartsInstall or upgrade
CLI and private signer (OPERATOR TOOLS)Linux CLI, Windows CLI, Linux signerWatch verified local events, Enable the local UI for one operator path, Enable signed OTLP audit export

Every command has a Copy button. Always copy commands from the console so you get the exact current release version.

4. Connect a local environment​

A four-step summary of the install process, described in Install and connect a node below.

5. Footnote​

No inbound firewall opening is required. Nodes discover the service, establish an authenticated outbound channel, and fail closed when exact policy or quorum evidence is unavailable.

Install and connect a node​

  1. Authenticate the release. Install cosign, then copy and run the Download and authenticate command for your platform. It downloads the release files and runs the installer in verify-only mode, which pins the exact repository, workflow, tag, Sigstore issuer and SHA-256 digests before any privileged installation.
  2. Create a signed one-time enrollment. Select Create enrollment and download the bootstrap package. Its token is short-lived, bound to the exact node and platform, and never appears in command arguments or config.json. See Mesh nodes.
  3. Install the verified bytes. Put your five customer-held TLS files in node-material, then run the installer without verify-only and pass that directory. The installer validates everything in an isolated staging directory before changing the system.
  4. Verify quorum and adapters. Confirm the node is healthy on Mesh nodes, then assign ACME, SPIFFE, NGINX, Apache, Kubernetes, EST or ADCS desired state from Integrations.

Example: verify a Linux release​

The Download and authenticate command for Linux downloads the node binary, systemd unit, installer, RELEASE.json, bootstrap-trust.json, SHA256SUMS and manifest.sigstore.json, then runs the installer with --verify-only. The command below is shown as it appeared for v0.1.26, split across lines for readability. Copy the live version from the console.

Download and authenticate (Linux)
base=https://downloads.sharppki.com/v0.1.26
for f in edgepki-node-linux-amd64 edgepki-node.service install-node-linux.sh RELEASE.json bootstrap-trust.json SHA256SUMS manifest.sigstore.json; do curl -fSLO "$base/$f"; done
sudo sh ./install-node-linux.sh --verify-only --bootstrap-package ./sectigo-edge-node.bootstrap.json . hassard0/sharppki

Example: verify a Windows release​

Download and authenticate (Windows)
$base='https://downloads.sharppki.com/v0.1.26'
$files='edgepki-node-windows-amd64.exe','install-node-windows.ps1','RELEASE.json','bootstrap-trust.json','SHA256SUMS','manifest.sigstore.json'
foreach($f in $files){Invoke-WebRequest "$base/$f" -OutFile $f}
.\install-node-windows.ps1 -VerifyOnly -Binary .\edgepki-node-windows-amd64.exe -BootstrapPackage .\sectigo-edge-node.bootstrap.json -ReleaseDirectory .

Rename the bootstrap file in the command to match the package you downloaded, for example sectigo-edge-production-edge-01.bootstrap.json.

Upgrade an enrolled node​

Use the Upgrade an enrolled node in place command from the Linux or Windows card after downloading the new release files:

Upgrade (Linux)
sudo sh ./install-node-linux.sh --upgrade . hassard0/sharppki

See Upgrades for the complete procedure.

Operator tool snippets​

The CLI and private signer card includes three snippets:

SnippetWhat it is
Watch verified local eventsA sectigo-edge … -watch events command that follows signed trust events from a local node, pinned to that node's public key. See Trust events.
Enable the local UI for one operator pathTwo config.json settings, local_ui_enabled and local_ui_allowed_spiffe_prefixes, that turn on the node's read-only operations UI for one SPIFFE operator path. See Local operations UI.
Enable signed OTLP audit exportThree config.json settings, otlp_audit_enabled, otlp_audit_exporter_id and otlp_audit_endpoint, that send signed audit records to your OpenTelemetry collector.

Permissions​

Every role can view this screen and download files. Creating an enrollment package requires PKI Operator or Tenant Admin and MFA within the last ten minutes.

Troubleshooting​

SymptomCause and fix
Verify-only mode failsDo not install. Re-download the files, make sure all of them come from the same release, and check that cosign is installed.
The bootstrap package is rejectedIt expired, was already used, or targets a different runtime. Create a new enrollment.
A link opens a general documentation pageSome links on this screen point to the docs home rather than a specific guide. Use Install on Linux, Install on Windows or Kubernetes (Helm).