Skip to content

Commit 854244c

Browse files
authored
Merge pull request #439 from smallstep/chromeos
Add ChromeOS to basic platform lists
2 parents 36028b9 + 22e675e commit 854244c

File tree

3 files changed

+17
-16
lines changed

3 files changed

+17
-16
lines changed

platform/README.mdx

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,8 @@ This process, known as cryptographic device attestation, forms the foundation fo
5656

5757
# How can you use Smallstep?
5858

59-
The Smallstep Agent is the vehicle through which Smallstep delivers cryptographically attested device identity to your organisation. It is the recommended way to identify devices and get client certificates to devices (Windows, Linux, Mac OS) for Enterprise Wi-Fi, VPN, HTTP/3 proxies, or web applications.
59+
The Smallstep Agent is the vehicle through which Smallstep delivers cryptographically attested device identity to your organisation. It is the recommended way to identify devices and get client certificates to devices (Windows, Linux, macOS, ChromeOS) for Enterprise Wi-Fi, VPN, HTTP/3 proxies, or web applications.
60+
6061

6162
It is a lightweight program that runs in the background on devices and manages end-to-end certificate lifecycle for various resources. It works with all TPM 2.0 devices—virtual TPMs, firmware TPMs, or physical TPMs—and on some TEEs and Secure Enclaves (eg. Apple Managed Device Attestation).
6263

@@ -68,7 +69,7 @@ If for any reason, you cannot have the Smallstep Agent on your devices, Smallste
6869

6970
Smallstep integrates with your MDM to deploy client certificates to company-managed devices to enable certificate-based network authentication for Wi-Fi (802.1x EAP-TLS WPA-Enterprise), VPN, ZTNA, etc.
7071

71-
We offer integrations for any MDMs for Apple and Windows devices that support Dynamic SCEP like Jamf, Intune, Workspace ONE, Mosyle, Ivanti, e.t.c.
72+
We offer integrations for any MDMs for Apple, Windows, and ChromeOS devices that support Dynamic SCEP like Jamf, Intune, Workspace ONE, Mosyle, Ivanti, and Google Workspace.
7273

7374
![Jamf MDM Marketecture.png](/graphics/Jamf_MDM_Marketecture.png)
7475

platform/core-concepts.mdx

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
updated_at: September 17, 2025
2+
updated_at: September 30, 2025
33
title: Core Concepts
44
html_title: Platform Core Security Concepts Explained
55
description: Fundamental concepts of device identity platform. Understand trust models, attestation, and certificate lifecycle management.
@@ -50,7 +50,7 @@ Now we have a great foundation for device identity. And, we've unlocked another
5050
Smallstep uses the following attestable device identifiers to build a high-assurance inventory:
5151

5252
- On Apple platforms, the device’s serial number or hardware UDID.
53-
- On Windows and Linux devices with TPMs, there is a TPM Endorsement Key and a Platform Certificate.
53+
- On Windows, Linux, and ChromeOS devices with TPMs, there is a TPM Endorsement Key and a Platform Certificate.
5454

5555
With Smallstep, you can build a device inventory by syncing devices from your MDM, via our API, or by having users self-register (with optional SSO).
5656

@@ -230,16 +230,16 @@ Because many client apps are unable to directly use hardware bound keys, Smallst
230230

231231
These provisioned credentials are short-lived. Their key attestation level varies based on the application and operating system:
232232

233-
| | macOS (Smallstep agent) | macOS (agentless) | Windows | Linux |
234-
| --- | --- | --- | --- | --- |
235-
| Wi-Fi | Smallstep attested | device attested | device attested | device attested |
236-
| SSH | Smallstep attested | not supported | device attested | device attested |
237-
| Safari | Smallstep attested | device attested | not available | not available |
238-
| Chrome | Smallstep attested | not supported | device attested | device attested |
239-
| Firefox | Smallstep attested | not supported | device attested | device attested |
240-
| Edge | talk to us | not supported | device attested | not available |
241-
| IPSec VPN | Smallstep attested | device attested | talk to us | talk to us |
242-
| Relay (MASQUE) | Smallstep attested | device attested | device attested | device attested |
233+
| | macOS (Smallstep agent) | macOS (agentless) | Windows | Linux | ChromeOS |
234+
| --- | --- | --- | --- | --- | --- |
235+
| Wi-Fi | Smallstep attested | device attested | device attested | device attested | device attested |
236+
| SSH | Smallstep attested | n/a | device attested | device attested | n/a |
237+
| Safari | Smallstep attested | device attested | n/a | n/a | n/a |
238+
| Chrome | Smallstep attested | n/a | device attested | device attested | device attested |
239+
| Firefox | Smallstep attested | n/a | device attested | device attested | n/a |
240+
| Edge | talk to us | n/a | device attested | talk to us | n/a |
241+
| IPSec VPN | Smallstep attested | device attested | talk to us | talk to us | n/a |
242+
| Relay (MASQUE) | Smallstep attested | device attested | device attested | device attested | n/a |
243243

244244
### A note about fallbacks
245245

platform/smallstep-agent.mdx

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
updated_at: September 17, 2025
2+
updated_at: October 01, 2025
33
title: Smallstep Agent for Linux
44
html_title: Smallstep Agent for Device Management Guide
55
description: Deploy and configure Smallstep Agent on Linux. Automated device identity management and certificate renewal for enterprise Linux fleets.
@@ -9,7 +9,7 @@ Choose one or the other depending on your deployment needs.
99

1010
# Introduction
1111

12-
While macOS and Windows can manage certificates and authentication settings via Mobile Device Management (MDM), Linux does not include automated remote management facilities. The Smallstep Agent brings vital certificate management features to your Linux users and endpoints. It can be installed independently on any Linux device running systemd.
12+
While macOS, Windows, and ChromeOS can manage certificates and authentication settings via Mobile Device Management (MDM), Linux does not include automated remote management facilities. The Smallstep Agent brings vital certificate management features to your Linux users and endpoints. It can be installed independently on any Linux device running systemd.
1313

1414
In this document, we will install, configure, and start the Smallstep Agent on a Linux device running systemd. We also show how to use the agent’s built-in PKCS#11 (smart card) service. With the PKCS#11 service, you can access Smallstep certificates and keys from applications that support PKCS#11.
1515

0 commit comments

Comments
 (0)