Skip to main content

Configure Software Trust Manager support for customer-hosted Private CA

Introduces a new hybrid architecture capability in DigiCert​​®​​ Software Trust Manager (STM) that enables secure integration with customer-hosted Private CA and HSM deployments in closed, outbound-only networks using the Software Trust Manager daemon.This hybrid approach combines the control of on-prem infrastructure with the centralized visibility and management of Software Trust Manager cloud.

The Software Trust Manager daemon is a centralized, on‑premises gateway that routes client requests between the Software Trust Manager cloud and the customer-hosted Private CA. It performs cryptographic operations locally and synchronizes metadata and audit logs with the Software Trust Manager cloud, enabling secure operations while keeping key custody within the customer environment.

The Software Trust Manager daemon is a containerized proxy/orchestrator that:

  • Acts as a gateway between client tools and backend systems.

  • Routes requests between Software Trust Manager cloud and customer-hosted Private CA.

  • Enables secure hybrid workflows without inbound network access.

  • Maintains user identity and audit context across all operations.

Hybrid request routing

  • Perform key operations (keypair creation, signing, certificate issuance) directly on your on-prem HSM using customer-hosted Private CA.

  • Continue using Software Trust Manager cloud for centralized policy, visibility, and audit.

Secure outbound-only architecture

  • No inbound connections required.

  • All communication initiated from within the customer network.

  • Meets strict zero-trust security requirements.

Security and authentication

  • Supports API key–based authentication (1FA) for on-prem operations.

  • Operations requiring multi-factor authentication (2FA) must be performed directly in Software Trust Manager cloud.

  • Customer-hosted Private CA credentials remain strictly on-prem.

Centralized visibility and audit

  • Automatically syncs keypairs, certificates, and audit logs to Software Trust Manager cloud.

  • Maintains a complete, user-attributed audit trail.

  • Ensures centralized visibility and compliance.

Capability

Description

Deployment model

Centralized daemon per data center

Communication

Outbound HTTPS only

Key management

Keys never leave HSM

Audit

Full user-attributed audit trail

Scalability

Multi-tenant, multi-region, HA support

Integration

Works with CLI tools (SMCTL, PKCS11, JCE, etc.)

On-Prem Operations using Software Trust Manager daemon

  • Keypair creation on HSM

  • Certificate issuance from on-prem ICA

  • Signing using HSM keys

  • Certificate revocation

  • Keypair deletion

Cloud operations

  • List/get keypairs, certificates, metadata

  • Profile and account queries

Restricted (2FA Required)

  • Cloud keypair creation

  • Cloud signing operations

  • Public certificate workflows

Discovery of existing HSM keypairs and import into Software Trust Manager cloud