Securing certificate enrollment across connected devices at scale.
Deep security engineering for a global connected-device platform — spanning certificate lifecycle management, Embedded Linux, PKI, automated testing and long-term security maintenance.
A global physical-security technology environment required robust certificate lifecycle capabilities across connected devices running an Embedded Linux platform.
Secure certificate enrollment and renewal had to work within an established operating system, development workflow and long-term support model — without compromising reliability, maintainability or security.
The challenge therefore extended beyond implementing a cryptographic protocol. The solution needed to operate reliably across product generations, release cycles, automated testing environments and deployed devices.
TopTeam provided senior software engineering and security expertise within the networking and security domain.
The consultant designed and developed a production-grade EST client in C and integrated it with the existing certificate-management architecture for automated X.509 certificate enrollment and renewal.
The engagement extended into testing, platform migration, long-term security maintenance and evaluation of future cryptographic platform upgrades.
Security engineering from protocol to platform.
The assignment combined deep security knowledge with production software engineering and embedded-platform experience.
Production-grade EST client
Designed and developed an EST client from scratch in C, implementing certificate enrollment and renewal over HTTPS/TLS and integrating it with the existing certificate manager.
Complete protocol flow
Implemented CA certificate retrieval, initial enrollment, re-enrollment and CSR attribute handling, together with CSR generation, PKCS parsing and secure credential handling.
Automated security testing
Built comprehensive unit and integration tests covering enrollment flows, error handling, network failures, expired certificates, revoked certificate authorities and protocol compliance.
Mock EST infrastructure
Developed a Python-based mock EST server that simulated certificate issuance, CA distribution and failure scenarios — enabling CI-driven testing without dependency on external PKI infrastructure.
Core platform migration
Contributed to migration of core system libraries to GLibc across the Embedded Linux platform, including dependent packages, BitBake recipes and compatibility validation across product lines.
Long-term security maintenance
Backported critical security fixes and CVE patches to LTS releases and evaluated the implications of a future OpenSSL platform upgrade, including compatibility, deprecations and downstream impact.
From technical complexity to trusted operation.
Existing architecture, certificate lifecycle and platform dependencies.
Secure protocol implementation integrated with production systems.
Automated testing across expected behaviour, failures and edge cases.
Security maintenance and platform evolution across long-term product lifecycles.
A stronger foundation for secure connected products.
Stronger engineering support for automated certificate enrollment and renewal across the device platform.
Automated testing infrastructure reduced dependency on external PKI services during development and validation.
LTS backporting and platform analysis supported continued security maintenance across deployed product generations.
Migration and upgrade analysis created a stronger technical foundation for future evolution of the operating platform.
Connected physical-security products depend on trusted identities and maintainable cryptographic infrastructure. Security has to work not only in theory — but across platforms, releases and deployed products.
More proof across complex environments.
Turning complex business requirements into a secure modern financial system
Building technology capability for connected mobility at global scale
Start with the need. We build the relevance.
Tell us what needs to move, change or be solved. We connect the challenge with the capability required to act.
Start a conversation →