Skip to main content

Requirements

Check these prerequisites before you create an enrollment package. The enrollment token in the package expires quickly (the console issues 30-minute packages), so have the host, the tools and your customer-held certificate material ready first.

Platforms​

PlatformRelease artifactRuns asNode key provider
Linux, x86-64 (amd64), systemdedgepki-node-linux-amd64systemd unit edgepki-node, user edgepkitpm2 (required by signed bootstrap packages)
Windows, x86-64 (amd64)edgepki-node-windows-amd64.exeWindows service SectigoEdgeMeshNodewindows_cng with the Microsoft Platform Crypto Provider
KubernetesHelm chart edgepki-node (in sectigo-edge-helm-charts.tgz) and a signed container imageStatefulSet, non-root (UID 65532)tpm2 or pkcs11
note

Releases contain amd64 builds only. No ARM64 Linux or Windows binaries are published.

Hardware-protected node key​

Production nodes must use a hardware-backed signing key. Software keys are rejected unless allow_software_node_key is explicitly set, and signed bootstrap packages refuse it outright.

  • Linux: a TPM 2.0 device at /dev/tpmrm0 (preferred) or /dev/tpm0. The installer stops if neither exists. On first start the node creates an ECDSA P-256 key certified by the TPM; only TPM-wrapped blobs are stored on disk. If a tss group exists, the installer adds the edgepki service user to it.
  • Windows: a TPM exposed through the Microsoft Platform Crypto Provider. The node opens an existing, non-exportable ECDSA P-256 key by name — it does not create one. The console-generated configuration names the key Sectigo Edge <node name>; provision that key for the service identity before installing.
  • Kubernetes: expose /dev/tpmrm0 through a reviewed TPM device plugin (the chart deliberately does not request privileged host access), or use a PKCS#11 module that is present in the image, with the PIN in the credential Secret.

Tools on the host​

The Linux installer checks for each of these and stops with Required verifier is not installed: <name> if one is missing:

ToolUsed for
cosignVerifying the release's Sigstore signature and the bootstrap package signature
jqValidating RELEASE.json, the bootstrap envelope and the payload
sha256sum, xxd, base64Checksums and digest encoding
date (GNU, supports -d)Validating issue and expiry times
installStaging files with exact permissions
systemctl, useradd, usermod, getentCreating the service user and service (install only)

You also need curl (or another downloader) and root privileges for installation. Verification alone (--verify-only) does not require root.

Customer-held certificate material​

Five files that you issue and keep. They never pass through the Sectigo Edge console. Put them in a private directory called node-material on the target host:

FilePurpose
local-api.crtServer certificate for the node's local TLS API
local-api.keyPrivate key for local-api.crt
workload-ca.pemCA bundle that issues your workloads' SPIFFE identities (X.509-SVIDs). The node trusts only client certificates that chain to it.
edge-client.crtOrganization-issued client certificate for the outbound mTLS connection to Sectigo Edge
edge-client.keyPrivate key for edge-client.crt

Each must be a regular file (not a symbolic link or reparse point). The installer validates the TLS key pair and the workload bundle before changing anything on the system.

Network access​

DirectionDestinationPortWhy
OutboundThe Sectigo Edge API host named in edge_url (shown in the enrollment package; the Helm chart default is https://api.sharppki.com)443/TCP (HTTPS)Enrollment, policy sync, desired state, issuance, reports
Outbounddownloads.sharppki.com443/TCPDownloading the release (can be done from another machine and copied over)
OutboundSigstore public-good infrastructure used by cosign443/TCPRelease verification during installation
Local / internalThe node's listen_address (default 127.0.0.1:9443; 0.0.0.0:9443 in Kubernetes)9443/TCPWorkload, CLI, ACME, EST and local UI access
Outbound (optional)Your OpenTelemetry collectorAs configuredSigned audit export
Outbound (optional)HashiCorp Vault, Kubernetes API, ADCS CA / Online ResponderAs configuredAdapter operations

No inbound firewall rule from the internet is required. The node ignores ambient HTTP proxies for its local CLI connection and for the OTLP exporter; do not rely on an intercepting proxy between the node and Sectigo Edge, because the connection is mutually authenticated end to end.

Post-quantum transport

If require_pqc_transport is true (the Helm chart default), every outbound connection to Sectigo Edge must negotiate TLS 1.3 with X25519MLKEM768. A TLS-inspecting middlebox that downgrades the key exchange causes the node to fail closed with a PQC transport required error.

Sizing​

The Helm chart defaults are a reasonable starting point for any platform:

ResourceRequestLimit
CPU50m500m
Memory64 MiB256 MiB
Persistent state1 GiB per node—

State (identity, audit log, ACME accounts, rotation generations, outboxes) lives in /var/lib/edgepki on Linux and Kubernetes, and in C:\ProgramData\Sectigo\Edge on Windows. Include it in your backup policy — see Backup and recovery.

Redundancy​

Plan for at least three nodes in production so the customer-side approval quorum survives maintenance and the loss of one failure domain. The Helm chart deploys three replicas with a PodDisruptionBudget of minAvailable: 2. Each replica has its own hardware-protected identity.

Console permissions​

To create an enrollment package you need the can_manage_nodes permission and a fresh MFA session. Configuring node-hosted integrations also requires can_manage_nodes; configuring Sectigo SCM requires can_manage_ca. See Access and roles.