Trust stores management
The Inventory > Trust stores page in DigiCert® Trust Lifecycle Manager is a centralized location for defining, distributing, and managing trusted CA certificates across your environment. It gives you a single interface to control how trust is configured and maintained across all your servers. You can manage individual CA certificates or create trust bundles to define which CA certificates are included or excluded and how trust is enforced across your trust stores. It also supports provisioning certificates and trust bundles to multiple trust store locations on the same server through DigiCert agents.
Features
With trust stores, you can:
Manage trusted root and intermediate CA certificates.
Create trust bundles to define included and excluded CA certificates and configure trust enforcement policies.
Provision CA certificates to trust stores on Windows and Linux servers through DigiCert agents.
Provision CA certificates and trust bundles to multiple trust store locations on the same server.
Monitor certificate and trust bundle provisioning status and track related activity across your environment.
Trust stores support the following operating systems and trust store formats.
Operating systems | Trust store formats |
|---|---|
Windows 10, Windows Server | CAPI, JKS |
Red Hat Enterprise Linux, Ubuntu | JKS |
Prerequisites
To start using trust stores management in Trust Lifecycle Manager, make sure these prerequisites are met.
Trust stores feature is enabled for your account. To verify that trust stores management is available, go to Inventory > Trust stores and ensure the Endpoints and Provisioning history tabs appear. For help verifying or enabling this feature, contact your DigiCert account representative.
Ensure that the required CA certificates are available in Trust Lifecycle Manager before proceeding with certificate provisioning. To learn more, see Trust anchors.
Ensure that there are DigiCert agents installed on the servers where you want to manage trust stores. To learn more, see Deploy and manage agents.
Ensure that DigiCert agent version 3.1.12 or later is installed on a supported Linux or Windows server. For more information, see Agent system requirements.