Skip to main content

Issue X9 certificates via CertCentral

Use DigiCert​​®​​ Trust Lifecycle Manager to issue X9 certificates for host-to-host communications like mutual TLS (mTLS), APIs, and other non-web browser use cases. Regulated by the ASC X9 standards body, DigiCert's X9 certificate product is governed by an independent certificate policy unaffiliated with the browsers, but that ensures interoperability by using a common root of trust.

Before you begin

For help verifying or enabling these prerequisites, contact your DigiCert account representative.

Before DigiCert can issue your certificate, DigiCert must complete X9 PKI Organization Validation using one of the following options:

  • Prevalidate your organization in CertCentral for faster issuance. See Submit an organization for validation.

  • Validate as part of the order: Add a new or expired organization and DigiCert will complete validation as part of the order process.

The X9 PKI for TLS certificate supports only fully qualified domain names and IP addresses. Wildcard domains are not supported.

Before CertCentral can issue your certificate, domain control must be demonstrated using one of the following options:

  • Prevalidate your domains in CertCentral for faster issuance. See Perform domain control validation (DCV).

  • Validate as part of the order: Add new or expired domains and complete validation manually as part of the CertCentral order.

Create X9 certificate profiles

To create a profile for issuing X9 certificates in Trust Lifecycle Manager:

  1. From the Trust Lifecycle Manager menu, go to Policies > Certificate profiles.

  2. Select the Create profile from template action at the top of the page.

  3. Select the base template CertCentral Private Server Certificate as the starting point for creating the new certificate profile.

    Work through the profile creation wizard, focusing on the X9-related options described in the following steps and making other selections for your business needs. After filling out each screen, select Next to move to the next screen.

  4. On the initial Primary options screen of the profile creation wizard, configure the:

    • Profile name: Give the profile a user-friendly name to help identify it.

    • Business unit: Assign the business unit for certificates issued from this profile.

    • Connector: Select the connector for the CertCentral account to issue X9 certificates from.

    • CertCentral division: Select the division for the issued X9 certificates in the linked CertCentral account.

    • Certificate type: Select X9 PKI for TLS.

    • Enrollment method: Select any of the supported methods for enrolling X9 certificates. To learn more, see Enrollment and authentication methods.

    • Authentication method: If applicable, select how to authenticate requests for the enrollment method you selected.

  5. On the Certificate options screen, configure the certificate validity period and cryptographic settings. Depending on the enrollment method you selected, you may also be prompted to configure the Subject DN and SAN fields for certificates. Otherwise, you will specify these at enrollment time.

  6. On the Extensions screen, configure values for the following certificate extensions:

    • Key usage:

      • Digital signature: Enabled by default to support TLS/mTLS authentication, and cannot be unselected.

      • Key encipherment: Select this option to also support key encipherment (for RSA certificates) or key agreement (for ECC certificates) use cases.

    • Extended key usage: You must select one or both of the following.

      • Server authentication: Allows the certificate to authenticate the identity of a server to a connecting client during a TLS handshake.

      • Client authentication: Allows the certificate to authenticate the identity of a client to a server during a TLS handshake. This is especially important for X9 certificates as they’re designed for non-browser use cases such as mTLS and host-to-host authentication.

  7. On the Additional options screen, configure certificate metadata to assign to certificates issued from this profile, including tags, owners, and custom attributes. DigiCert recommends using these fields to help identify, organize, and manage the X9 certificates in your Trust Lifecycle Manager inventory.

  8. On the final screen of the profile creation wizard, select Create to save the X9 certificate profile.

Enroll X9 certificates

Use the enrollment method you configured in your X9 certificate profile to enroll new certificates from that profile.

Enrollment methods

How to request a certificate

Learn more

  • Admin web request

  • DigiCert agent

  • DigiCert sensor

Enroll certificates with automated delivery or installation and manage the lifecycles of deployed certificates directly from your Trust Lifecycle Manager inventory.

Managed automation solution

  • BrowserPKCS12

  • CSR

Enroll from a web-based form using the enrollment URL for the certificate profile.

Web self-service options

CMP

Enroll and manage certificates using the Certificate Management Protocol (CMP).

CMP enrollment guide

REST API

Enroll and manage certificates using the REST API service for Trust Lifecycle Manager.

REST API enrollment guide

3rd-party ACME client

Enroll and manage certificates from the host system using a third-party ACME client.

ACME automation service

Distribute the X9 root CA certificate

X9 PKI for TLS certificates chain to an independent root of trust governed by the ASC X9 certificate policy, separate from the public Web PKI used by web browsers. Before relying on an X9 certificate, every system that will validate the certificate must be configured to trust the X9 root CA.

For certificates issued via CertCentral, install the X9 Financial PKI - RSA 4096 Root certificate into the trust store for each relying party to ensure they trust the X9 end-entity certificates that chain back to that root.

What's next

  • X9 certificates you enroll through Trust Lifecycle Manager are added to your Inventory > Certificates and can be viewed and managed there.

  • If you configured metadata assignments in the X9 certificate profile (tags, owners, or custom attributes), you can use these fields to filter the X9 certificates or create custom views.

  • For the managed automation solution (Admin web request, DigiCert agent, or DigiCert sensor enrollment methods), go to Inventory > Endpoints to manage lifecycles for deployed X9 certificates.