Manage end entity certificates
DigiCert® Private CA categorizes end entity certificates into the following types:
End entity | Description | Examples |
|---|---|---|
Server | Secure communication channels between servers, clients, or devices. Used for TLS/SSL on internal services, APIs, application backends, or IoT gateways that expose endpoints. | Internal company portal, API endpoint, mail servers, proxy, VPN concentrator, IoT gateway, or MQTT endpoint. |
User | Authenticate and secure the digital identities of individual users or devices. Used for email signing/encryption, VPN access, smart-card logins, or IoT devices authenticating to a service. | User authentication, S/MIME, smart-card, or hardware-token, VPN/Wi-Fi (EAP-TLS) authentication, IoT device identity certificates. |
Organization | Represent an internal department, functional group, or system identity. Used for document signing, encrypted group communication, service accounts, or IoT fleet-level provisioning. | Departmental encryption, automation bot, doc signing workflows, service account authentication, and provisioning or product-line identity. |
Code signing | Verify the authenticity and integrity of internal software, scripts, or IoT firmware. Used for signing executables, mobile apps, or firmware update packages. | Certificates for signing: internal software release packages, PowerShell scripts, configuration tools, mobile apps distributed through internal MDM platforms, docker container images before pushing to a private registry. |
Wildcard | Secure multiple subdomains under a single parent domain. Simplifies TLS across environments with shared subdomains. This isn’t recommended for IoT devices, since each device should have a unique, traceable identity. | Wildcard domains covering internal portals, load balancers, APIs, VPNs, test servers, regional clusters under the same parent domain. |
You consume your end entity licenses to create this type of certificates.
View end entity certificates
You can find an end entity certificate using its serial number or public key.
To find an end entity certificate in DigiCert Private CA:
In the main menu, under Manage CAs, select EE Search.
Select Serial number or Public key, whichever you have handy.
Enter the serial number or public key in the search box and select Search.
The certificates matching your search criteria appear in the table.
Download end entity certificates
You can download an end entity certificate from the EE search page.
On the EE search page, select a certificate from your search results, and select the download button.
Issue and manage end entity certificates
You can issue and manage end entity certificates chained to your private CA via:
Connected DigiCert® ONE apps