Install on Windows
The Windows installer (install-node-windows.ps1) authenticates the release with cosign, verifies your signed enrollment package, validates your certificate material in a private staging folder, and only then installs the SectigoEdgeMeshNode Windows service. If any check fails, nothing on the machine is changed.
Before you start: confirm the requirements — Windows on amd64, cosign on the PATH, an elevated PowerShell session, the Platform Crypto Provider key for the node, and the five customer-held files.
What gets installed
| Location | Contents |
|---|---|
C:\Program Files\Sectigo\Edge\edgepki-node.exe | Node binary (-InstallDirectory changes the folder) |
C:\ProgramData\Sectigo\Edge\ | config.json, policy-trust.json, registration-trust.json, your TLS material, acme-eab.json, the one-time enrollment-token, and all node state (identity, audit log, ACME and rotation state) |
Service SectigoEdgeMeshNode | Display name Sectigo Edge Mesh Node, startup type Automatic, command line "C:\Program Files\Sectigo\Edge\edgepki-node.exe" -config "C:\ProgramData\Sectigo\Edge\config.json" |
The data folder's inherited permissions are removed and replaced with SYSTEM, BUILTIN\Administrators and, if you pass -ServiceAccount, that account — each with Full Control. The service is configured to restart after failures (after 5 s, 15 s and 60 s; the failure count resets daily).
Hardware key
Signed Windows packages require node_key_provider: windows_cng. The node opens an existing non-exportable ECDSA P-256 key in the Microsoft Platform Crypto Provider (the TPM) by name; it never creates or exports a key. The name in the console-generated configuration is Sectigo Edge <node name> (for example Sectigo Edge mesh-win-01). Provision that key so the service identity can open it before you install, otherwise the service starts but cannot initialize its identity.
Service identity
By default the service runs as LocalSystem. To run it under a dedicated identity — for example when the Microsoft ADCS template must be granted to a specific account — pass -ServiceAccount with a gMSA or computer account ending in $. The installer never accepts a password.
Install
- Create the enrollment package. In ConsoleMesh nodes select Enroll node, enter the node name, choose Windows service as the runtime and select Create one-time package. Download the signed package. See Enrollment.
- Prepare a working folder on the host containing the bootstrap package (
sectigo-edge-<node-name>.bootstrap.json) and a privatenode-materialfolder withlocal-api.crt,local-api.key,workload-ca.pem,edge-client.crtandedge-client.key. - Download the release into the same folder (below).
- Verify the release and package (below).
- Install from an elevated PowerShell session (below).
- Delete the bootstrap package once the installer reports success.
Download the release
The console's ConsoleDownloads & install page shows this command with the current version; v0.1.26 is an example.
$base = 'https://downloads.sharppki.com/v0.1.26'
$files = 'edgepki-node-windows-amd64.exe','install-node-windows.ps1','RELEASE.json','bootstrap-trust.json','SHA256SUMS','manifest.sigstore.json'
foreach ($f in $files) { Invoke-WebRequest "$base/$f" -OutFile $f }
Keep the installer's file name as install-node-windows.ps1: the installer verifies its own bytes against the signed checksum list under that name. If your execution policy blocks the downloaded script, Unblock-File .\install-node-windows.ps1 removes the download mark; the installer still performs its own signature and digest checks.
Verify without installing
-VerifyOnly checks the Sigstore signature over SHA256SUMS against the exact repository, release workflow, tag and GitHub OIDC issuer, checks the digests of the binary, the installer and the trust file, and verifies the bootstrap package's signature, lifetime, platform and path confinement. It does not change the machine.
.\install-node-windows.ps1 -VerifyOnly `
-Binary .\edgepki-node-windows-amd64.exe `
-BootstrapPackage .\sectigo-edge-mesh-win-01.bootstrap.json `
-ReleaseDirectory .
Sectigo Edge v0.1.26 release and signed Windows bootstrap package verified.
Install the service
Run the same command without -VerifyOnly, adding -MaterialDirectory (and -ServiceAccount if needed). Verification runs again before any change. The installer then starts the service and waits up to 60 seconds for the node to enroll and delete its one-time token.
.\install-node-windows.ps1 `
-Binary .\edgepki-node-windows-amd64.exe `
-BootstrapPackage .\sectigo-edge-mesh-win-01.bootstrap.json `
-MaterialDirectory .\node-material `
-ReleaseDirectory .
Status Name DisplayName
------ ---- -----------
Stopped SectigoEdgeMeshNode Sectigo Edge Mesh Node
Sectigo Edge Mesh Node v0.1.26 enrolled and installed from a verified release. Securely delete the source bootstrap package.
Installer parameters
| Parameter | Default | Meaning |
|---|---|---|
-Binary | (required) | Path to edgepki-node-windows-amd64.exe. Its digest must match the signed checksum list. |
-BootstrapPackage | — | Signed package from the console. Required for installation. |
-MaterialDirectory | — | Folder with the five customer-held files. Required for installation. |
-ReleaseDirectory | Installer's folder | Folder containing SHA256SUMS, manifest.sigstore.json, RELEASE.json and bootstrap-trust.json. |
-Repository | hassard0/sharppki | OWNER/REPOSITORY pinned in the Sigstore identity. |
-VerifyOnly | off | Authenticate and exit without changes. |
-Upgrade | off | In-place upgrade of an enrolled node. Cannot be combined with -BootstrapPackage, -Config or -MaterialDirectory. See Upgrades. |
-ServiceAccount | LocalSystem | gMSA or computer account ending in $. |
-InstallDirectory | C:\Program Files\Sectigo\Edge | Where edgepki-node.exe is copied. |
-DataDirectory | C:\ProgramData\Sectigo\Edge | Must stay at the default: signed packages require this exact folder. |
-Config | — | Verify a plain config.json instead of a package. Verification only; installation requires -BootstrapPackage. |
Specify exactly one of -BootstrapPackage or -Config (unless -Upgrade).
Confirm the node is healthy
Get-Service SectigoEdgeMeshNode
Status Name DisplayName
------ ---- -----------
Running SectigoEdgeMeshNode Sectigo Edge Mesh Node
Test-Path C:\ProgramData\Sectigo\Edge\identity.json
True
Test-Path C:\ProgramData\Sectigo\Edge\enrollment-token
False
Then check the local health endpoint with the sectigo-edge CLI (sectigo-edge-windows-amd64.exe from the same release), passing the CA bundle that verifies your local-api.crt:
.\sectigo-edge-windows-amd64.exe -ca .\node-material\local-api-ca.pem status
{
"audit_head": "q3V9kM2f0bX8w1n4Ezr7cT5yHjL0pA6sDgUe2RiWoNc",
"audit_sequence": 12,
"dependency_discovery": {
"configured_probes": 0,
"enabled": false,
"failed": 0,
"queued": 0,
"successful": 0
},
"integrations": [
{
"assigned": false,
"enabled": false,
"health": "disabled",
"installed": true,
"kind": "acme",
"revision": 0
},
{
"assigned": false,
"enabled": false,
"health": "disabled",
"installed": false,
"kind": "est",
"revision": 0
}
],
"node_id": "node_3f9a2c71-6d4e-4b8a-9e15-c07d2a8b6f40",
"policy_last_synced_at": "2026-10-01T14:03:40Z",
"policy_sha256": "Jd8rT2qWm5Xz1vB7nK4eYc0hLpA9sF3uGiR6oE2wNtM",
"policy_version": 7,
"status": "ok"
}
Values are examples. Finally, confirm the node shows as healthy under ConsoleMesh nodes.
Troubleshooting installation
| Message | Cause and fix |
|---|---|
cosign is required to verify the Sectigo Edge release identity before installation. | Install cosign and make sure it is on the PATH of the elevated session. |
Release signature or workflow identity is invalid: … | Files are not from the expected repository/workflow/tag or were modified. Re-download all release files. |
Release artifact digest mismatch: <name> / Signed checksum is missing for <name> | A file (including the installer itself) does not match SHA256SUMS, or was renamed. Re-download. |
Bootstrap or signing-key validity window is invalid. | The package expired or the clock is wrong. Create a new package. |
Bootstrap payload schema or platform is invalid. | The package was made for another runtime. Create a Windows service package. |
Bootstrap configuration violates the Windows control-plane or hardware-key confinement policy. | The package configuration is not a standard Windows one (for example it does not use windows_cng). Create a new package from the console. |
Run as Administrator. | Start PowerShell with Run as administrator. |
ServiceAccount must be a gMSA or computer account ending in $; passwords are never accepted. | Use a gMSA such as CORP\gmsa-edge$. |
Signed bootstrap packages require the confined data directory C:\ProgramData\Sectigo\Edge. | Remove the custom -DataDirectory. |
This host is already enrolled; rerun with -Upgrade and no bootstrap package. | identity.json already exists. Use -Upgrade. |
Bootstrap material failed node runtime validation; no system files were changed: … | A TLS key pair does not match, workload-ca.pem has no certificates, or a trust file belongs to another workspace. Fix and rerun. |
The verified service is installed and retrying, but enrollment did not finish within 60 seconds… | Check the service status, the outbound connection, and that the Platform Crypto Provider key exists for the service identity. The token stays protected on disk until it succeeds or expires. |
See also Troubleshooting.