diff --git a/metropolis/node/core/curator/bootstrap.go b/metropolis/node/core/curator/bootstrap.go
index 6147125..c764104 100644
--- a/metropolis/node/core/curator/bootstrap.go
+++ b/metropolis/node/core/curator/bootstrap.go
@@ -39,6 +39,7 @@
 		Template:  pki.Server([]string{id}, nil),
 		Mode:      pki.CertificateExternal,
 		PublicKey: pubkey,
+		Name:      fmt.Sprintf("node-%s", id),
 	}
 	node, err = nodeCert.Ensure(ctx, etcd)
 	if err != nil {
diff --git a/metropolis/pkg/pki/certificate.go b/metropolis/pkg/pki/certificate.go
index 4ec3bf0..e7788b1 100644
--- a/metropolis/pkg/pki/certificate.go
+++ b/metropolis/pkg/pki/certificate.go
@@ -177,6 +177,14 @@
 		return nil, fmt.Errorf("invalid certificate mode %v", c.Mode)
 	}
 
+	if c.Name == "" {
+		if c.Mode == CertificateExternal {
+			return nil, fmt.Errorf("external certificate must have name set")
+		} else {
+			return nil, fmt.Errorf("managed certificate must have name set")
+		}
+	}
+
 	certPath := c.Namespace.etcdPath("%s-cert.der", c.Name)
 
 	// Try loading certificate from etcd.
