- In the tunnel entrypoint somewhere, install a non-exportable private key into the keystore
- Connect to the control plane as usual, sending a CSR signed by this private key
- Portal fulfills the CSR using the account's internal CA
- device installs the updated leaf cert into the keychain
- device reconnects using this new chain -> mTLS and uses this going forward to connect
This strongly identifies the device going forward.
This strongly identifies the device going forward.