Groupings
Integrators
Not loaded
Create integrator
Integrators
Fresh from the directory
Autoconf control plane
Choose one workspace. Its current data loads when you open it.
Open a tray item to load its current data and controls.
Groupings
Not loaded
Fresh from the directory
Groupings
Not loaded
Endpoint sets and owning integrators
A dashboard references one intermediate. This direct change is allowed only while the dashboard has no active certificates; commissioned replacements use the rotation or compromise workflow.
Groupings
Not loaded
Derived live from dashboard assignments. Every dashboard automatically provides a Dashboard: Friendly Name smart group, so there is no separate membership list to maintain.
Dashboard grouping summaries
Groupings
Not loaded
Role definition names are labels only; they do not activate special behavior.
users.is_super_adminintegrators.is_site_ownerconfigure_sso. Only a super administrator may configure the site owner itself.users.delegate_permissionassign_to_integratorconfigure_ssoassign_bundle_deploymentsassign_dashboardsFresh from the directory
Groupings
Not loaded
Fresh from the catalog
Groupings
Not loaded
Creates a protected request. Complete it under Request Signing.
The selected release replaces this group's current release for the same bundle type after signature verification.
Kiosks and one release per bundle type
Entries
Not loaded
Fresh from the directory
Entries
Not loaded
Fresh from the directory
Entries
Not loaded
This creates a protected request. Open Request Signing to copy its message and complete the assignment with an authorized signature.
This replaces the kiosk's one dashboard endpoint set after completion under Request Signing.
Fresh from the directory
Entries
Not loaded
Fresh from the catalog
Details
Not loaded
Hardware IDs, customer, and notes
Details
Not loaded
Awaiting a valid signature
Details
Not loaded
Associated users and authorized actions
Details
Not loaded
Uploads are stored privately with their SHA-256 digest. Uploading does not authorize kiosk activation.
Private catalog metadata
Details
Not loaded
Private PKI manages intermediate certificates independently. A dashboard references one intermediate from the Dashboards workspace; that intermediate issues the dashboard M3S app certificate and certificates for its kiosks. The root private key stays on the YubiKey and offline. Autoconf stores the public trust chain and the online intermediate key. Kiosks create their own keys and submit only CSRs.
If a root or intermediate is compromised, revoke and reissue its leaves, replace the affected trust material, and deliver recovery through the public-cert-TLS protected RPC path.
Defines an intermediate independently. Dashboards reference this record; neither the dashboard nor this record represents a root.
Download the offline-signing configuration, then generate the replaceable intermediate key inside protected Autoconf storage. Only its CSR leaves Autoconf.
Upload the signed intermediate plus its issuer trust anchor as public chain-verification material. Autoconf verifies the issuer self-signature, intermediate chain and constraints, and that the intermediate matches its protected key. Dashboards reference the activated intermediate, never the root.
The CSR common name must match the dashboard M3S hostname. Autoconf fixes the SAN to that hostname and issues a serverAuth-only leaf.
Independent commissioning records and their optional dashboard references; no root keys
Details
Not loaded