During operation, new certificates can be provisioned through a Device Management system and an appropriate Corporate PKI. Standardized interfaces such as EST or CMP can be used to automate certificate requests and renewals.
In combination with MTG Corporate PKI, MTG supports automated certificate renewal through EST, for example. In LwM2M-based environments, the EST mechanisms defined in RFC 7030 and RFC 9148 can be used for this purpose. Timely renewal helps prevent devices from losing secure communication capabilities because of expired certificates.