Safety & Security · Software component
Certificate Authority
Software componentSafety & SecuritySafety, Security & Governancearc:CertificateAuthority
A trust service that issues and automatically rotates short-lived X.509 certificates so edge systems and the management plane can mutually authenticate.
Responsibility. Establishes and renews machine identities for mutual authentication.
Also known as: Fleet Command certificate authority, Certificate-based authentication
Relationships
controls access to control
Design guidance
- SHOULD use certificate-based mutual authentication with short validity instead of static passwords for edge-to-cloud communication.
Quantitative guidance
As stated by the sources; verify before use.
- Certificates rotate with 24-48 hour validity, bounding exploitation of compromised credentials to 48 hours (Ch4.6).
Classification
- Patterns
- Mutual TLSShort-lived credential rotationZero trust
- Technologies
- X.509TLS 1.3NVIDIA Fleet Command
- Quality attributes
- Security (ISO/IEC 25010 | NIST AI RMF: secure and resilient)
- Risks mitigated
- Credential compromise via phishing or credential dumpsMan-in-the-middle attacks
Sources
- Ch4.6: T. Nguyen, "TensorRT-LLM and NVIDIA Fleet Command," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 4.6. ISBN: 9798244538229.