A device starts out unknown and is refused at a closed gateway. An admin mints a single-use, expiring enrollment token, which is delivered to the device. The device generates a hybrid classical and post-quantum key pair internally, sends only a certificate signing request to the certificate authority, and receives a signed certificate. If approval is required, the device waits in a pending state until an admin approves it. The gateway then opens only for this device, and only to the one resource policy permits; the other resources stay unreachable.
Nobody
A device nobody has heard of knocks on a closed gate. Nothing happens. The network has never heard of it and doesn't care.
Keys never leave the device. On Linux, they never leave the chip.