October 16, 2025 - Enhanced certificate management with ability to sign and issue certificates

Context


Change Type: Feature
Product area: Platform services
Component: Authentication
Deployed at: eu.latest.cumulocity.com, apj.cumulocity.com, jp.cumulocity.com, cumulocity.com, us.cumulocity.com, emea.cumulocity.com

Technical details

Build artifact: cumulocity (2025.348.0)
Internal ID: MTM-64106

Description


The certificate authority feature previously released in Public Preview is now Generally Available (GA).
It is available in CD versions 2025.348.0 and higher, and in the 2026 annual release.

The feature can be accessed in the Device Management application under Management → Trusted certificates, where the Add CA Certificate option is now available by default.

Cumulocity has been enhanced to function as a Certificate Authority (CA), providing the following capabilities:

  • Manage signing certificates
  • Accept Certificate Signing Requests (CSR)
  • Perform legitimacy checks, as defined by each tenant
  • Issue signed X.509 certificates trusted by the device tenant

For more details about this feature refer to Certificate Authority (CA).

Caution
Migration from Public Preview to General Availability - action required.

As part of the move to General Availability you need to remove all the devices you have registered under Public Preview and re-register them. All such devices will continue to be able to connect, but none of the other capabilities of the certificate lifecycle management will be available until they are re-registered.