Skip to main content

Step CA

Link DigiCert​​®​​ Trust Lifecycle Manager to Step CA to enroll and manage private certificates from a step-ca server.

Before you begin

DigiCert prerequisites

  • The Step CA feature must be enabled for your account. Contact your DigiCert account representative to verify or enable this feature.

  • You need an active DigiCert sensor on your network that can connect to the step-ca server.

Step CA prerequisites

  • Your Step CA must be running with deployment type standalone.

  • Gather the following information for your Step CA:

    • The URL used to access the step-ca server. Your DigiCert sensor must be able to connect to the Step CA at this URL.

    • The fingerprint of the root CA certificate. Get this from the config/defaults.json file in the Step CA installation folder.

Add Step CA connector

  1. From the Trust Lifecycle Manager main menu, select Integrations > Connectors.

  2. Select the Add connector button.

  3. In the Certificate authorities section, select the option for Step CA.

    Complete the form as described in the following steps.

  4. Configure general properties in the top section of the form:

    • Name: Assign a friendly name to this connector.

    • Business unit: Select a business unit for this connector. Only users assigned to this business unit can manage the connector.

    • Managing sensor: Select the DigiCert sensor that will manage this connector.

  5. In the Link step-ca section, enter the access details for your private step-ca server:

    • Step CA URL: The complete URL used to access and issue certificates from the Step CA.

    • Root CA certificate fingerprint: The fingerprint of the root CA certificate for the Step CA.

  6. Select Add to create the Step CA connector with the configured settings.

Issue certificates

Certificate template

Use the following base template to create certificate profiles in Trust Lifecycle Manager for issuing private certificates from a connected step-ca server.

Template name

Seat type

Enrollment methods

Step CA private server certificate

Certificate management

  • Admin web request

  • DigiCert sensor

  • REST API

Create profiles

Create each Step CA certificate profile from the above template. Complete the profile creation wizard based on your unique business needs and how you plan to deploy the Step CA certificates. Key profile settings for Step CA include:

  • Connector: Select the connector for accessing the step-ca server.

  • Step CA Provisioner: Select the Step CA provisioner to use for authenticating certificate requests.

  • Provisioner password: Enter the password for the selected Step CA provisioner.

  • Enrollment method: Select the method for enrolling certificates from the Step CA:

What's next

  • Monitor and manage certificates from your Inventory page in Trust Lifecycle Manager.

  • Go to the Integrations > Connectors page to view, check status, or manage a connector.

  • Select one of the View actions for a connector to load a pre-filtered inventory list of digital trust assets associated with it.