Set up your environment
If you're setting up DigiCert® Device Trust Manager for the first time, start by preparing your environment using this chapter. It walks you through the essential setup and configuration steps so you can quickly establish device trust and begin managing your IoT devices with Device Trust Manager.
Default resources
Device Trust Manager includes several default resources that are automatically created during provisioning. These resources provide a starting point for configuring device management and certificate lifecycle operations.
Issuing CA: You'll use this when creating a certificate management policy. It serves as the certificate authority that issues and signs device certificates.
Certificate templates: You'll select this when requesting or issuing certificates. It defines the certificate settings and attributes applied to your devices.
Certificate profiles: You'll use this within a certificate management policy to configure the specific attributes and settings for certificates issued to devices.
Device rendezvous zones: You'll use this during device onboarding. It provides the location information devices need to connect to Device Trust Manager.
Device group: You'll use the device groups to organize devices and apply policies consistently across a set of devices.
Before you begin
Work with your DigiCert® ONE account representative to initialize your account. A DigiCert® system administrator will complete the tasks below in the specified manager.
In DigiCert® Account Manager:
Add needed license files.
Create your primary DigiCert ONE Account Administrator user role.
Create your primary DigiCert ONE account and organization.
In DigiCert® Private CA:
Create your root CA and intermediate CA. Intermediate CAs are used as your Device Trust Manager issuing CA.
Add HSMs and register the partitions.
Add the domains for OCSP, AIA, and other policies.
Set defaults for OCSP, CRL, and AIA.
What’s next?
Continue to Part 1: Initial access and setup to complete your first sign-in, configure administrative access, and verify that you can access Device Trust Manager.