|
1 | 1 | --- |
2 | | -updated_at: September 17, 2025 |
| 2 | +updated_at: September 30, 2025 |
3 | 3 | title: Core Concepts |
4 | 4 | html_title: Platform Core Security Concepts Explained |
5 | 5 | description: Fundamental concepts of device identity platform. Understand trust models, attestation, and certificate lifecycle management. |
@@ -50,7 +50,7 @@ Now we have a great foundation for device identity. And, we've unlocked another |
50 | 50 | Smallstep uses the following attestable device identifiers to build a high-assurance inventory: |
51 | 51 |
|
52 | 52 | - On Apple platforms, the device’s serial number or hardware UDID. |
53 | | -- On Windows and Linux devices with TPMs, there is a TPM Endorsement Key and a Platform Certificate. |
| 53 | +- On Windows, Linux, and ChromeOS devices with TPMs, there is a TPM Endorsement Key and a Platform Certificate. |
54 | 54 |
|
55 | 55 | With Smallstep, you can build a device inventory by syncing devices from your MDM, via our API, or by having users self-register (with optional SSO). |
56 | 56 |
|
@@ -230,16 +230,16 @@ Because many client apps are unable to directly use hardware bound keys, Smallst |
230 | 230 |
|
231 | 231 | These provisioned credentials are short-lived. Their key attestation level varies based on the application and operating system: |
232 | 232 |
|
233 | | -| | macOS (Smallstep agent) | macOS (agentless) | Windows | Linux | |
234 | | -| --- | --- | --- | --- | --- | |
235 | | -| Wi-Fi | Smallstep attested | device attested | device attested | device attested | |
236 | | -| SSH | Smallstep attested | not supported | device attested | device attested | |
237 | | -| Safari | Smallstep attested | device attested | not available | not available | |
238 | | -| Chrome | Smallstep attested | not supported | device attested | device attested | |
239 | | -| Firefox | Smallstep attested | not supported | device attested | device attested | |
240 | | -| Edge | talk to us | not supported | device attested | not available | |
241 | | -| IPSec VPN | Smallstep attested | device attested | talk to us | talk to us | |
242 | | -| Relay (MASQUE) | Smallstep attested | device attested | device attested | device attested | |
| 233 | +| | macOS (Smallstep agent) | macOS (agentless) | Windows | Linux | ChromeOS | |
| 234 | +| --- | --- | --- | --- | --- | --- | |
| 235 | +| Wi-Fi | Smallstep attested | device attested | device attested | device attested | device attested | |
| 236 | +| SSH | Smallstep attested | n/a | device attested | device attested | n/a | |
| 237 | +| Safari | Smallstep attested | device attested | n/a | n/a | n/a | |
| 238 | +| Chrome | Smallstep attested | n/a | device attested | device attested | device attested | |
| 239 | +| Firefox | Smallstep attested | n/a | device attested | device attested | n/a | |
| 240 | +| Edge | talk to us | n/a | device attested | talk to us | n/a | |
| 241 | +| IPSec VPN | Smallstep attested | device attested | talk to us | talk to us | n/a | |
| 242 | +| Relay (MASQUE) | Smallstep attested | device attested | device attested | device attested | n/a | |
243 | 243 |
|
244 | 244 | ### A note about fallbacks |
245 | 245 |
|
|
0 commit comments