Requirements
Check these prerequisites before you create an enrollment package. The enrollment token in the package expires quickly (the console issues 30-minute packages), so have the host, the tools and your customer-held certificate material ready first.
Platforms
| Platform | Release artifact | Runs as | Node key provider |
|---|---|---|---|
| Linux, x86-64 (amd64), systemd | edgepki-node-linux-amd64 | systemd unit edgepki-node, user edgepki | tpm2 (required by signed bootstrap packages) |
| Windows, x86-64 (amd64) | edgepki-node-windows-amd64.exe | Windows service SectigoEdgeMeshNode | windows_cng with the Microsoft Platform Crypto Provider |
| Kubernetes | Helm chart edgepki-node (in sectigo-edge-helm-charts.tgz) and a signed container image | StatefulSet, non-root (UID 65532) | tpm2 or pkcs11 |
Releases contain amd64 builds only. No ARM64 Linux or Windows binaries are published.
Hardware-protected node key
Production nodes must use a hardware-backed signing key. Software keys are rejected unless allow_software_node_key is explicitly set, and signed bootstrap packages refuse it outright.
- Linux: a TPM 2.0 device at
/dev/tpmrm0(preferred) or/dev/tpm0. The installer stops if neither exists. On first start the node creates an ECDSA P-256 key certified by the TPM; only TPM-wrapped blobs are stored on disk. If atssgroup exists, the installer adds theedgepkiservice user to it. - Windows: a TPM exposed through the Microsoft Platform Crypto Provider. The node opens an existing, non-exportable ECDSA P-256 key by name — it does not create one. The console-generated configuration names the key
Sectigo Edge <node name>; provision that key for the service identity before installing. - Kubernetes: expose
/dev/tpmrm0through a reviewed TPM device plugin (the chart deliberately does not request privileged host access), or use a PKCS#11 module that is present in the image, with the PIN in the credential Secret.
Tools on the host
- Linux
- Windows
- Kubernetes
The Linux installer checks for each of these and stops with Required verifier is not installed: <name> if one is missing:
| Tool | Used for |
|---|---|
cosign | Verifying the release's Sigstore signature and the bootstrap package signature |
jq | Validating RELEASE.json, the bootstrap envelope and the payload |
sha256sum, xxd, base64 | Checksums and digest encoding |
date (GNU, supports -d) | Validating issue and expiry times |
install | Staging files with exact permissions |
systemctl, useradd, usermod, getent | Creating the service user and service (install only) |
You also need curl (or another downloader) and root privileges for installation. Verification alone (--verify-only) does not require root.
- Windows PowerShell 5.1 or PowerShell 7, run as Administrator for installation.
cosignon thePATH. The installer stops withcosign is required to verify the Sectigo Edge release identity before installation.if it is missing.- If you run the service under a dedicated identity, a group Managed Service Account (gMSA) or computer account whose name ends in
$. Passwords are never accepted.
helmandkubectlwith permission to create Secrets, a StatefulSet, a headless Service, a ConfigMap and a PodDisruptionBudget in the target namespace (plus a ServiceAccount, Lease and ClusterRole if you enable the Kubernetes CSR signer).- A StorageClass that can provision a
ReadWriteOncevolume per replica (default request1Gi). - Pull access to the private, signed image registry through a namespace-scoped
imagePullSecretsentry. cosignon your workstation to verify the image digest before deploying.
Customer-held certificate material
Five files that you issue and keep. They never pass through the Sectigo Edge console. Put them in a private directory called node-material on the target host:
| File | Purpose |
|---|---|
local-api.crt | Server certificate for the node's local TLS API |
local-api.key | Private key for local-api.crt |
workload-ca.pem | CA bundle that issues your workloads' SPIFFE identities (X.509-SVIDs). The node trusts only client certificates that chain to it. |
edge-client.crt | Organization-issued client certificate for the outbound mTLS connection to Sectigo Edge |
edge-client.key | Private key for edge-client.crt |
Each must be a regular file (not a symbolic link or reparse point). The installer validates the TLS key pair and the workload bundle before changing anything on the system.
Network access
| Direction | Destination | Port | Why |
|---|---|---|---|
| Outbound | The Sectigo Edge API host named in edge_url (shown in the enrollment package; the Helm chart default is https://api.sharppki.com) | 443/TCP (HTTPS) | Enrollment, policy sync, desired state, issuance, reports |
| Outbound | downloads.sharppki.com | 443/TCP | Downloading the release (can be done from another machine and copied over) |
| Outbound | Sigstore public-good infrastructure used by cosign | 443/TCP | Release verification during installation |
| Local / internal | The node's listen_address (default 127.0.0.1:9443; 0.0.0.0:9443 in Kubernetes) | 9443/TCP | Workload, CLI, ACME, EST and local UI access |
| Outbound (optional) | Your OpenTelemetry collector | As configured | Signed audit export |
| Outbound (optional) | HashiCorp Vault, Kubernetes API, ADCS CA / Online Responder | As configured | Adapter operations |
No inbound firewall rule from the internet is required. The node ignores ambient HTTP proxies for its local CLI connection and for the OTLP exporter; do not rely on an intercepting proxy between the node and Sectigo Edge, because the connection is mutually authenticated end to end.
If require_pqc_transport is true (the Helm chart default), every outbound connection to Sectigo Edge must negotiate TLS 1.3 with X25519MLKEM768. A TLS-inspecting middlebox that downgrades the key exchange causes the node to fail closed with a PQC transport required error.
Sizing
The Helm chart defaults are a reasonable starting point for any platform:
| Resource | Request | Limit |
|---|---|---|
| CPU | 50m | 500m |
| Memory | 64 MiB | 256 MiB |
| Persistent state | 1 GiB per node | — |
State (identity, audit log, ACME accounts, rotation generations, outboxes) lives in /var/lib/edgepki on Linux and Kubernetes, and in C:\ProgramData\Sectigo\Edge on Windows. Include it in your backup policy — see Backup and recovery.
Redundancy
Plan for at least three nodes in production so the customer-side approval quorum survives maintenance and the loss of one failure domain. The Helm chart deploys three replicas with a PodDisruptionBudget of minAvailable: 2. Each replica has its own hardware-protected identity.
Console permissions
To create an enrollment package you need the can_manage_nodes permission and a fresh MFA session. Configuring node-hosted integrations also requires can_manage_nodes; configuring Sectigo SCM requires can_manage_ca. See Access and roles.