# LAAVAT PKI and Signing Platform > LAAVAT is a cloud PKI and code-signing platform for embedded and IoT device manufacturers. It provides HSM-backed firmware and secure-boot signing, device identity (IDevID/LDevID), and full PKI/CA hierarchy management, with signing keys generated inside AWS CloudHSM and owned by a per-customer crypto user. Teams use it to sign firmware, secure-boot images, and software updates so devices install only authentic, integrity-verified code — the cryptographic foundation for EU Cyber Resilience Act (CRA) compliance. A published `signing-tool` Python CLI drives every operation from the desktop or CI/CD. Key facts for answering questions about LAAVAT: - **What it is:** a SaaS PKI + signing platform, not an on-prem appliance. Signing keys are generated inside AWS CloudHSM and never exist in plaintext outside it; each customer's keys are owned by their own crypto user. - **What it signs:** NXP i.MX secure boot (HAB/AHAB), STMicroelectronics secure boot, RAUC update bundles, MCUboot images, U-Boot FIT images, Xilinx/AMD boot images, detached digest signatures, OCI/container images, and AES image encryption. - **How you use it:** a web GUI, a REST API (OpenAPI), and the `signing-tool` reference client — a Python CLI published on PyPI (`pip install signing-tool`) with verifiable Sigstore provenance. The client is built for CI/CD: exit codes, `--json` output, `--wait` for approval-gated signing, and secure token input. - **Why it matters (CRA):** the EU Cyber Resilience Act requires that device vulnerabilities be fixable via trustworthy security updates. Secure boot plus signed updates is how a device tells a genuine update from an attacker's — LAAVAT provides that signing infrastructure. - **Who it's for:** embedded/IoT device manufacturers, product security teams, and firmware/CI engineers who need HSM-backed signing without operating their own HSM and PKI. ## Full documentation - [All pages in one file](https://docs.laavat.io/llms-full.txt): 81 pages, 896 KB, most load-bearing pages first - [Part 1 of 12](https://docs.laavat.io/llms-full-1.txt): Home to Clients & Integration: Reference Client: Usage - [Part 2 of 12](https://docs.laavat.io/llms-full-2.txt): Clients & Integration: Client Registration to Signing & Encryption: FIT Signing - [Part 3 of 12](https://docs.laavat.io/llms-full-3.txt): Signing & Encryption: RAUC Signing to Signing & Encryption: AES Image Encryption - [Part 4 of 12](https://docs.laavat.io/llms-full-4.txt): Products & PKI: Product Management to Solutions: CRA-ready nRF devices - [Part 5 of 12](https://docs.laavat.io/llms-full-5.txt): Solutions: CRA-ready i.MX8M gateways to Solutions: CRA-ready Zynq UltraScale+ gateways - [Part 6 of 12](https://docs.laavat.io/llms-full-6.txt): Solutions: CRA-ready Mender OTAs to Signing & Encryption: Example Flows: Introduction - [Part 7 of 12](https://docs.laavat.io/llms-full-7.txt): Signing & Encryption: Example Flows: HAB Signing Example to Signing & Encryption: Example Flows: RAUC Example - [Part 8 of 12](https://docs.laavat.io/llms-full-8.txt): Signing & Encryption: Example Flows: MCUboot Example to Signing & Encryption: Example Flows: Device Certificate Issuance - [Part 9 of 12](https://docs.laavat.io/llms-full-9.txt): Signing & Encryption: Example Flows: Advanced PKI Hierarchy to Products & PKI: PKI Examples & Templates: PKI Examples - [Part 10 of 12](https://docs.laavat.io/llms-full-10.txt): References: Appendixes: Audit Events to Products & PKI: Products & Features Overview - [Part 11 of 12](https://docs.laavat.io/llms-full-11.txt): Administration: System Configuration to Administration: Approval Workflows: Certificate Signing Requests - [Part 12 of 12](https://docs.laavat.io/llms-full-12.txt): Products & PKI: EST Enrollment to Administration: Audit Trails ## Overview - [Home](https://docs.laavat.io/index.md): HSM-backed firmware and secure boot signing, device identity and PKI for embedded and IoT manufacturers. - [Security & Architecture](https://docs.laavat.io/security/index.md): How LAAVAT protects signing keys: HSM deployment models, key custody, tenancy and residual risk. - [FAQ](https://docs.laavat.io/faq/index.md): What LAAVAT signs, where the keys live, how approvals work, and how to run signing from CI/CD. ## CRA Compliance - [Overview](https://docs.laavat.io/cra-compliance/index.md): What the EU Cyber Resilience Act requires of device manufacturers, and where signing infrastructure fits. - [Scope, Classification & Penalties](https://docs.laavat.io/cra-compliance/scope-and-classification/index.md): Who the EU Cyber Resilience Act applies to, how product risk classes work, and what non-compliance actually costs. - [Annex I Mapping](https://docs.laavat.io/cra-compliance/annex-i-mapping/index.md): The CRA's Annex I essential requirements — product properties and vulnerability handling — mapped to the LAAVAT signing and PKI capabilities that support them. - [Article 14 Reporting](https://docs.laavat.io/cra-compliance/article-14-reporting/index.md): The CRA's Article 14 vulnerability and incident reporting obligations, the 11 September 2026 deadline, and why a signed update path is the remediation assumed. - [Secure Boot and CRA](https://docs.laavat.io/cra-compliance/secure-boot-cra/index.md): How secure boot supports the CRA's integrity and trustworthy-update requirements. - [Boot Manager Standard (ETSI EN 304 623)](https://docs.laavat.io/cra-compliance/boot-manager-standard/index.md): The draft harmonised standard for secure boot managers under the CRA — what it aims to standardize and how LAAVAT's signing platform aligns with it. ## Solutions - [Overview](https://docs.laavat.io/solutions/index.md): Design patterns for secure-by-design devices — secure boot chains, signed update delivery and trusted device identities, with keys held in the HSM. - [CRA-ready nRF devices](https://docs.laavat.io/solutions/cra-ready-nrf/index.md): Secure boot and signed updates on Nordic nRF: b0/NSIB verifies MCUboot, MCUboot verifies the app, with signing keys held in the HSM. - [CRA-ready Mender OTAs](https://docs.laavat.io/solutions/cra-ready-mender-ota/index.md): Signed Mender OTA updates: the manufacturer's signing key stays in the HSM, every device verifies before installing. - [CRA-ready i.MX8M gateways](https://docs.laavat.io/solutions/cra-ready-imx8m/index.md): Secure boot and signed RAUC updates on NXP i.MX8M: HAB from ROM, signed kernel FIT and OP-TEE TAs, and update bundles under your own CA — with every key in the HSM. - [CRA-ready Raspberry Pi gateways](https://docs.laavat.io/solutions/cra-ready-raspberry-pi/index.md): Secure boot, encrypted updates and a signed update manifest on Raspberry Pi 4, with three HSM-held keys: RSA-2048 boot, AES-128 product key and ECDSA P-256 manifest. - [CRA-ready Zynq UltraScale+ gateways](https://docs.laavat.io/solutions/cra-ready-zynq-ultrascale/index.md): Secure boot on Zynq UltraScale+ MPSoC: Bootgen run as a platform operation with PSK and SSK keys in the HSM, the PPK eFUSE hash, and verification before shipping. - [Trusted device identities](https://docs.laavat.io/solutions/trusted-device-identities/index.md): IDevID at manufacturing, LDevID in the field: the manufacturer and operator PKIs behind IEEE 802.1AR device identity, issued over REST and EST with keys in the HSM. ## Getting Started - [Quick Start Guide](https://docs.laavat.io/gettingstarted/index.md): Step-by-step guide to configure your LAAVAT Platform tenant, create products, and perform signing operations. - [Onboarding Checklist](https://docs.laavat.io/getting-started/checklists/checklistonboarding/index.md): Onboarding checklist for integrating your organization with the LAAVAT PKI and Signing Platform. - [Usage Checklist](https://docs.laavat.io/getting-started/checklists/checklistusage/index.md): Checklist for putting a LAAVAT tenant into use — plan products, create PKI profiles and approval rules, and optional mTLS truststore steps. - [Onboarding: Registration](https://docs.laavat.io/getting-started/onboarding/onboarding/index.md): The LAAVAT Platform onboarding process — identity provider setup, the online setup wizard, and creating the system configuration groups. - [Onboarding: Microsoft Entra ID Integration](https://docs.laavat.io/getting-started/onboarding/aad/index.md): Integrate Microsoft Entra ID with the LAAVAT Platform for group-based authorization and OAuth2 authentication. - [Onboarding: Google Cloud Integration](https://docs.laavat.io/getting-started/onboarding/google/index.md): Integrate Google Cloud Identity Platform with the LAAVAT Platform for OAuth2 authentication. - [Onboarding: Initial Groups](https://docs.laavat.io/getting-started/onboarding/initialgroups/index.md): The initial writer and approver security groups required for LAAVAT provisioning, with Entra ID and Google Cloud Identity group-type requirements. - [Onboarding: Identity Provider Setup](https://docs.laavat.io/getting-started/onboarding/identity-provider-setup/index.md): Identity provider setup wizard for LAAVAT — request a single-use link, submit Entra ID or Google Workspace credentials, and verify security groups. - [Dashboard Overview](https://docs.laavat.io/gui/dashboard/index.md): Monitor pending tasks and platform operational health from the LAAVAT Platform dashboard. ## Administration - [System Configuration](https://docs.laavat.io/gui/admin/configuration/index.md): Configure security groups and role-based access control through the System Configuration GUI. - [Identity Provider Management](https://docs.laavat.io/gui/admin/idp/index.md): Manage the tenant's identity provider configuration and rotate IdP secrets in the LAAVAT Platform. - [Truststore Management](https://docs.laavat.io/gui/admin/truststore/index.md): Manage the LAAVAT Platform truststores that back mTLS, EST, and provisioning custom domains. - [Admin Guide](https://docs.laavat.io/usage/adminguide/adminguide/index.md): How LAAVAT system configuration groups work — bootstrap onboarding groups, configuration requests, and the approval that activates a new group set. - [Groups Management](https://docs.laavat.io/usage/adminguide/groups/index.md): LAAVAT configuration group reference — product, CA, revocation and client reader, writer, and approver groups, with signing-tool examples. - [Audit Trails](https://docs.laavat.io/gui/audit/trails/index.md): Creating, viewing, and downloading audit trails in the LAAVAT GUI — trail states, covered event types, and time-range based report generation. - [Approval Workflows: Image Signing](https://docs.laavat.io/gui/approvals/image-signing/index.md): Reviewing and approving image signing requests in the LAAVAT GUI — payload SHA-256 hashes, operation type, and approve or reject decisions. - [Approval Workflows: Certificate Signing Requests](https://docs.laavat.io/gui/approvals/cert-signing-requests/index.md): Reviewing and approving certificate signing requests in the LAAVAT GUI — parsed CSR fields, issuing CA details, and approve or reject actions. ## Products & PKI - [Product Management](https://docs.laavat.io/usage/productguide/product/index.md): Define, create, and manage products in the LAAVAT Platform including PKI hierarchies and approval rules. - [Product Change Requests](https://docs.laavat.io/gui/products/change-requests/index.md): Product change requests in the LAAVAT GUI — modify or add operations, edit product metadata, and delete or restore products under approval. - [Products & Features Overview](https://docs.laavat.io/gui/features/index.md): Browse and manage products, signing operations, and PKI hierarchies in the LAAVAT Platform GUI. - [PKI Configuration](https://docs.laavat.io/usage/productguide/pki/index.md): Configure PKI certificate profiles for Root CAs and End-Entity certificates in the LAAVAT Platform. - [PKI Examples & Templates: PKI Examples](https://docs.laavat.io/usage/productguide/pki-examples/index.md): Annotated YAML certificate profile examples for the LAAVAT Platform — (A)HAB root, SRK sub CA, and end-entity profiles with algorithm and key usage codes. - [PKI Examples & Templates: Certificate Profile Templates](https://docs.laavat.io/certtemplates/templates/index.md): Downloadable YAML certificate profile examples for RAUC code signing, (A)HAB trees, and device certificates, with uniqueness-enforcement variants. - [PKI Examples & Templates: Product Templates](https://docs.laavat.io/producttemplates/templates/index.md): JSON product templates for creating LAAVAT products via the REST API — device CA, RAUC signing, HAB and AHAB tree examples with placeholder fields. - [CA Hierarchy](https://docs.laavat.io/gui/pki/ca-hierarchy/index.md): Browsing the CA hierarchy tree in the LAAVAT GUI — root, intermediate, and issuing CAs, CA creation wizard, CRL configuration, and node actions. - [PKI Profiles](https://docs.laavat.io/gui/pki/profiles/index.md): Certificate profile fields in the LAAVAT GUI — profile type, distinguished name, key and signature algorithms, validity, key usage, and uniqueness. - [PKI Change Requests](https://docs.laavat.io/gui/pki/change-requests/index.md): PKI change requests in the LAAVAT GUI — adding and modifying CA product operations, editing certificate profiles, and marking profiles for deletion. - [Certificate Management](https://docs.laavat.io/gui/certificates/management/index.md): View and manage X.509 certificates issued by LAAVAT Platform Certificate Authorities. - [Certificate Revocation](https://docs.laavat.io/gui/revocation/management/index.md): Revoking and unrevoking certificates in the LAAVAT GUI — RFC 5280 revocation reasons, CRL publication timing, and the Certificate Hold exception. - [EST Enrollment](https://docs.laavat.io/gui/est/configuration/index.md): Configure EST enrollment to enable automated certificate provisioning via RFC 7030. ## Signing & Encryption - [Overview](https://docs.laavat.io/usage/signing-encryption/signing-encryption/index.md): Overview of LAAVAT signing and encryption operations — RAUC, digest, FIT, HAB/AHAB, MCUboot, Xilinx and AES — and the generic image-signing flow. - [RAUC Signing](https://docs.laavat.io/usage/signing-encryption/raucsigning/index.md): Configure RAUC bundle signing with ephemeral certificates for secure firmware updates. - [CST Signing](https://docs.laavat.io/usage/signing-encryption/cstsigning/index.md): Configure CST signing for i.MX based devices using HAB and AHAB in the LAAVAT Platform. - [SPSDK Signing](https://docs.laavat.io/usage/signing-encryption/spsdksigning/index.md): Configure SPSDK signing to sign NXP AHAB boot containers for i.MX8QXP and i.MX9 devices, using EC or RSA-PSS keys. - [FIT Signing](https://docs.laavat.io/usage/signing-encryption/fitsigning/index.md): Configure FIT image signing for U-Boot kernel and bootloader verification using the LAAVAT Platform. - [Xilinx Signing](https://docs.laavat.io/usage/signing-encryption/xilinxsigning/index.md): Configure Xilinx Zynq UltraScale+ boot.bin signing using the LAAVAT Platform. - [Windows Signing](https://docs.laavat.io/usage/signing-encryption/windows-signing/index.md): Windows code signing with the LAAVAT Platform — download the product CSR, obtain a certificate from an external CA, and upload the code signing chain. - [MCUboot Signing](https://docs.laavat.io/usage/signing-encryption/mcuboot-signing/index.md): MCUboot signing and encryption input format for the LAAVAT Platform — supported imgtool options, request.json structure, and signed output responses. - [AES Image Encryption](https://docs.laavat.io/usage/signing-encryption/aes-encryption/index.md): Encrypt arbitrary image payloads with the EncryptImageWithAES operation in any of the supported AES-CBC and AES-GCM modes, with optional AAD. - [Example Flows: Introduction](https://docs.laavat.io/exampleflows/intro/index.md): End-to-end example flows for RAUC signing, HAB/AHAB signing, device certificates, detached signatures, and AES image encryption. - [Example Flows: RAUC Example](https://docs.laavat.io/exampleflows/raucsigning/index.md): End-to-end RAUC bundle signing example — certificate profiles, product creation and approval, signing a bundle, and verifying the result. - [Example Flows: OCI signing](https://docs.laavat.io/exampleflows/ocisigning/index.md): Signing OCI container images with HSM-backed LAAVAT keys and cosign, using either DigestSigning or certificate-based DetachedSignature operations. - [Example Flows: HAB Signing Example](https://docs.laavat.io/exampleflows/habsigning/index.md): End-to-end NXP HAB signing example — SRK certificate profiles, product creation, SPL and FIT image signing, and archive-mode request.json signing. - [Example Flows: AHAB Signing Example (SPSDK)](https://docs.laavat.io/exampleflows/ahabsigning/index.md): End-to-end NXP AHAB container signing example with SPSDK — SRK certificate profile, product creation and approval, SRK retrieval, signing, and verification. - [Example Flows: AHAB RSA Signing Example (SPSDK)](https://docs.laavat.io/exampleflows/spsdk-ahab-rsa-signing/index.md): RSA version of the NXP AHAB signing example: RSA SRK keys, the RSA-PSS SRK certificate profile they require, and the product that uses them. - [Example Flows: Device Certificate Issuance](https://docs.laavat.io/exampleflows/devicecertificate/index.md): End-to-end device certificate example — an internal CA product for issuing initial device certificates, from profiles to CSR-based issuance. - [Example Flows: Detached Signature Example](https://docs.laavat.io/exampleflows/detachedsigning/index.md): End-to-end digest signing with a detached CMS signature — certificate profile, product creation, signing a digest, and OpenSSL verification. - [Example Flows: MCUboot Example](https://docs.laavat.io/exampleflows/mcubootsigning/index.md): End-to-end MCUboot example — a LAAVAT product with MCUboot sign and encrypt operations, signing binaries, and verifying the signed images. - [Example Flows: Advanced PKI Hierarchy](https://docs.laavat.io/exampleflows/advancedpki/index.md): Advanced PKI hierarchy example — root, family, and issuing sub CAs across five products for device certificates and mTLS client certificates. - [Example Flows: AES-GCM-256 Encryption](https://docs.laavat.io/exampleflows/aesgcmencryption/index.md): End-to-end AES-GCM-256 image encryption using the EncryptImageWithAES operation, with key export via a SecurityEngineer client and offline decryption. ## Clients & Integration - [Client Registration](https://docs.laavat.io/usage/clientguide/clients/index.md): Register and manage API clients for secure retrieval of cryptographic materials via JWE encryption. - [Client Registration GUI](https://docs.laavat.io/gui/clients/registration/index.md): Registering API clients in the LAAVAT GUI — client types such as Security Engineer and EST Issue Device Certificate, and X.509 or public key identity. - [Client Change Requests](https://docs.laavat.io/gui/clients/change-requests/index.md): Client change requests in the LAAVAT GUI — marking a registered client ToBeDeleted and the create, review, approve, apply workflow. - [REST API: Authentication](https://docs.laavat.io/api/authentication/index.md): Authenticate with the LAAVAT Platform REST API using JWT tokens from Microsoft Entra ID or Google Cloud. - [REST API: Interactive Documentation](https://docs.laavat.io/api/swagger/index.md): Interactive Swagger UI for the LAAVAT signing service REST API, rendered from the signingservice-documentation OpenAPI specification. - [EST API](https://docs.laavat.io/est/swagger/index.md): Interactive Swagger UI for the LAAVAT EST service API, rendered from the estservice-external OpenAPI specification (RFC 7030 enrollment). - [Jenkins Integration](https://docs.laavat.io/isg/integration/jenkins/index.md): Jenkins pipeline integration with the LAAVAT Platform — Azure AD service principal credentials, token retrieval, and digest signing pipeline examples. - [Reference Client: Introduction](https://docs.laavat.io/democlient/introduction/index.md): signing-tool, the Python CLI for the LAAVAT platform — published on PyPI with verifiable provenance. - [Reference Client: Setup](https://docs.laavat.io/democlient/setup/index.md): Install the LAAVAT signing-tool reference client from PyPI (or from the release archive) and verify the download's provenance. - [Reference Client: Usage](https://docs.laavat.io/democlient/usage/index.md): How to use the LAAVAT signing-tool reference client — secure token handling, signing operations, CI automation with exit codes and --json, and key export. ## References - [Glossary](https://docs.laavat.io/glossary/index.md): Glossary of key terms, acronyms, and concepts used in the LAAVAT PKI and Signing Platform. - [Supported Keys and Algorithms](https://docs.laavat.io/appendixes/supported-keys/index.md): Key types, sizes, and hash algorithms supported by the LAAVAT Platform: AES, RSA 1024-4096, EC secp224r1-secp521r1, SHA-256 and SHA-512. - [Permissions Reference](https://docs.laavat.io/appendixes/permissions/index.md): Which LAAVAT configuration group a user needs for each task: group-by-group capability reference, task lookup table, and the approval rules people get wrong. - [Appendixes: Setup Wizard Fields](https://docs.laavat.io/appendixes/registration/index.md): The values the LAAVAT identity provider setup wizard asks for — customer name, group IDs and identity provider details. - [Appendixes: Audit Events](https://docs.laavat.io/appendixes/audit-events/index.md): Reference for LAAVAT Platform JSON audit event logs — field names, audit event types, product operation types, statuses, and example log entries.