Case Library
CASE C01 PHYSICAL SECURITY & IoT DELIVERY CASE

Securing certificate enrollment across connected devices at scale.

Deep security engineering for a global connected-device platform — spanning certificate lifecycle management, Embedded Linux, PKI, automated testing and long-term security maintenance.

Cybersecurity & Resilience Software Engineering & Development
Client confidentiality by design. We focus on challenge, capability and impact.
SECURITY ENGINEERING Trust across the device lifecycle.

A global physical-security technology environment required robust certificate lifecycle capabilities across connected devices running an Embedded Linux platform.

Secure certificate enrollment and renewal had to work within an established operating system, development workflow and long-term support model — without compromising reliability, maintainability or security.

The challenge therefore extended beyond implementing a cryptographic protocol. The solution needed to operate reliably across product generations, release cycles, automated testing environments and deployed devices.

Environment Connected devices
Platform Embedded Linux
Security domain PKI & certificates
Delivery model Production engineering

TopTeam provided senior software engineering and security expertise within the networking and security domain.

The consultant designed and developed a production-grade EST client in C and integrated it with the existing certificate-management architecture for automated X.509 certificate enrollment and renewal.

The engagement extended into testing, platform migration, long-term security maintenance and evaluation of future cryptographic platform upgrades.

CAPABILITY DEPLOYED

Security engineering from protocol to platform.

The assignment combined deep security knowledge with production software engineering and embedded-platform experience.

C OpenSSL EST / RFC 7030 PKI X.509 TLS Embedded Linux Yocto / BitBake Python GLibc Git CI/CD PKCS#7 PKCS#10 CVE remediation
01

Production-grade EST client

Designed and developed an EST client from scratch in C, implementing certificate enrollment and renewal over HTTPS/TLS and integrating it with the existing certificate manager.

02

Complete protocol flow

Implemented CA certificate retrieval, initial enrollment, re-enrollment and CSR attribute handling, together with CSR generation, PKCS parsing and secure credential handling.

03

Automated security testing

Built comprehensive unit and integration tests covering enrollment flows, error handling, network failures, expired certificates, revoked certificate authorities and protocol compliance.

04

Mock EST infrastructure

Developed a Python-based mock EST server that simulated certificate issuance, CA distribution and failure scenarios — enabling CI-driven testing without dependency on external PKI infrastructure.

05

Core platform migration

Contributed to migration of core system libraries to GLibc across the Embedded Linux platform, including dependent packages, BitBake recipes and compatibility validation across product lines.

06

Long-term security maintenance

Backported critical security fixes and CVE patches to LTS releases and evaluated the implications of a future OpenSSL platform upgrade, including compatibility, deprecations and downstream impact.

DELIVERY LOGIC

From technical complexity to trusted operation.

01 Understand

Existing architecture, certificate lifecycle and platform dependencies.

02 Engineer

Secure protocol implementation integrated with production systems.

03 Validate

Automated testing across expected behaviour, failures and edge cases.

04 Sustain

Security maintenance and platform evolution across long-term product lifecycles.

04 — IMPACT

A stronger foundation for secure connected products.

Secure certificate lifecycle

Stronger engineering support for automated certificate enrollment and renewal across the device platform.

Better testability

Automated testing infrastructure reduced dependency on external PKI services during development and validation.

Maintainable security

LTS backporting and platform analysis supported continued security maintenance across deployed product generations.

Platform evolution

Migration and upgrade analysis created a stronger technical foundation for future evolution of the operating platform.

WHY IT MATTERS
Connected physical-security products depend on trusted identities and maintainable cryptographic infrastructure. Security has to work not only in theory — but across platforms, releases and deployed products.
Intelligence in service of better human decisions.
HAVE A COMPLEX TECHNOLOGY CHALLENGE?

Start with the need. We build the relevance.

Tell us what needs to move, change or be solved. We connect the challenge with the capability required to act.

Start a conversation