Configure Software Trust Manager support for customer-hosted Private CA
Introduces a new hybrid architecture capability in DigiCert® Software Trust Manager (STM) that enables secure integration with customer-hosted Private CA and HSM deployments in closed, outbound-only networks using the Software Trust Manager daemon.This hybrid approach combines the control of on-prem infrastructure with the centralized visibility and management of Software Trust Manager cloud.
The Software Trust Manager daemon is a centralized, on‑premises gateway that routes client requests between the Software Trust Manager cloud and the customer-hosted Private CA. It performs cryptographic operations locally and synchronizes metadata and audit logs with the Software Trust Manager cloud, enabling secure operations while keeping key custody within the customer environment.
The Software Trust Manager daemon is a containerized proxy/orchestrator that:
Acts as a gateway between client tools and backend systems.
Routes requests between Software Trust Manager cloud and customer-hosted Private CA.
Enables secure hybrid workflows without inbound network access.
Maintains user identity and audit context across all operations.
Hybrid request routing
Perform key operations (keypair creation, signing, certificate issuance) directly on your on-prem HSM using customer-hosted Private CA.
Continue using Software Trust Manager cloud for centralized policy, visibility, and audit.
Secure outbound-only architecture
No inbound connections required.
All communication initiated from within the customer network.
Meets strict zero-trust security requirements.
Security and authentication
Supports API key–based authentication (1FA) for on-prem operations.
Operations requiring multi-factor authentication (2FA) must be performed directly in Software Trust Manager cloud.
Customer-hosted Private CA credentials remain strictly on-prem.
Centralized visibility and audit
Automatically syncs keypairs, certificates, and audit logs to Software Trust Manager cloud.
Maintains a complete, user-attributed audit trail.
Ensures centralized visibility and compliance.
Capability | Description |
|---|---|
Deployment model | Centralized daemon per data center |
Communication | Outbound HTTPS only |
Key management | Keys never leave HSM |
Audit | Full user-attributed audit trail |
Scalability | Multi-tenant, multi-region, HA support |
Integration | Works with CLI tools (SMCTL, PKCS11, JCE, etc.) |
On-Prem Operations using Software Trust Manager daemon
Keypair creation on HSM
Certificate issuance from on-prem ICA
Signing using HSM keys
Certificate revocation
Keypair deletion
Cloud operations
List/get keypairs, certificates, metadata
Profile and account queries
Restricted (2FA Required)
Cloud keypair creation
Cloud signing operations
Public certificate workflows
Discovery of existing HSM keypairs and import into Software Trust Manager cloud