Certificates and their Uses

Network Fandango Service

The following certificates are generated by the Network Fandango Service:

Root CA

API TLS Certificate

JWT Certificate

SSH User CA (OpenSSH CA for user certs)

SSH Host CA (OpenSSH CA for host certs)

Enrolled Network Fandango Hosts

Enrolled hosts download the Root CA public key and SSH public keys at the point of enrollment, in order to verify the identity of nfsvc, but these certificates are not generated on the enrolled hosts.

mTLS Client Certificate


Revision #6
Created 6 September 2025 16:27:12 by Neil Bullock
Updated 6 September 2025 17:36:29 by Neil Bullock