Quick links for Software Trust Manager
Use this section to administer Software Trust Manager, including user access, authentication, roles, API integrations, and audit monitoring. These settings help ensure secure and governed access to your Software Trust Manager environment.
Follow your organization’s approved access-management and change-management procedures before granting, changing, or removing access.
Important
FedRAMP certification status
DigiCert for Government is pursuing FedRAMP certification. Publishing this documentation doesn't indicate certification or agency authorization. For the current status, refer to the DigiCert for Government listing in FedRAMP Marketplace.
Tasks | Description |
|---|---|
For sign-in methods, two-factor authentication, users and service users, role assignment, API credentials, and platform audit logs. | |
Users responsible for signing, managing signing-related assets, and requesting releases. | |
Users responsible for managing cryptographic assets, enforcing policy, and monitoring compliance for other users in the account. | |
Users responsible for managing the developers and engineering teams who sign and release software. | |
Users or automated pipelines responsible for signing and running threat-detection scans. | |
Engineers or authenticated devices whose sole responsibility is signing software. |
Restrict the following permissions to authorized users to protect sensitive operations and maintain appropriate access controls:
Permission | Description |
|---|---|
Create, view, update, and manage keypairs. | |
Review and approve requests to delete keypairs. | |
Review and approve requests to export keypairs. | |
Review and approve software releases. | |
Create, view, update, and manage certificate profiles. | |
View and update account-level settings and configurations. | |
View and export audit logs and signature logs. |