Quick links for Trust Lifecycle Manager
Use this topic to find DigiCert® Trust Lifecycle Manager features available for U.S. government organizations and access the related configuration guidance. Feature support can differ from standard DigiCert ONE cloud deployments, and some supported features have limitations in the FedRAMP offering.
Important
FedRAMP certification status
DigiCert for Government is pursuing FedRAMP certification. Publishing this documentation doesn't indicate certification or agency authorization. For the current status, refer to the DigiCert for Government listing in FedRAMP Marketplace.
Feature support
Trust Lifecycle Manager provides certificate lifecycle management and PKI services for managing digital trust across your organization.
The following tables list supported Trust Lifecycle Manager features for U.S. government organizations. The Feature availability column identifies features that are fully or partially supported and describes any applicable limitations.
Inventory
Use the inventory to discover certificates and other cryptographic assets across your environment. Import existing certificate information from supported external sources.
Feature | Description | Feature availability |
|---|---|---|
Discover and automate certificates on cloud-based load balancers, certificate managers, and content distribution networks. | Supported | |
Import and manage certificates and IP/port targets from external scanning services (Qualys or Tenable). | Supported | |
Import and manage certificates from issuing CAs outside of DigiCert® Private CA. | Supported | |
Import certificates from third-party (external) CA systems into Trust Lifecycle Manager using the REST API for centralized inventory and management. | Supported | |
Copy and synchronize certificates from a Trust Lifecycle Manager business unit to the ServiceNow CMDB for querying, filtering, and monitoring. | Partially supported Username and password authentication is supported. PKCS#12 client certificate authentication using mutual TLS (mTLS) is not supported. | |
Find certificates and other cryptographic assets on servers by scanning the file/operating system. | Supported |
Management
Use management features to enroll, renew, and manage certificates. Choose from enrollment protocols, APIs, self-service enrollment, and integrations with supported systems.
Feature | Description | Feature availability |
|---|---|---|
Use device identity to authenticate managed devices during certificate enrollment. | Partially supported RSA and elliptic curve (EC) keyed requests are supported. Post-quantum cryptography (PQC) and Ed25519 keyed requests are not supported. | |
Authenticate requests via OIDC or SAML using DigiCert ONE login | Configure certificate profiles to authenticate certificate requests using DigiCert ONE login with an external OIDC or SAML identity provider (IdP). | Supported Supports standard XML digital signatures (XML-DSig) and TLS with RSA or EC signing certificates. |
Authenticate requests via SAML 2.0 using Microsoft Azure AD SAML IdP | Configure certificate profiles to authenticate certificate requests using Microsoft Azure AD as an external SAML 2.0 identity provider (IdP). | Supported Supports standard XML digital signatures (XML-DSig) and TLS with RSA or EC signing certificates. |
Configure certificate profiles to authenticate certificate requests using Okta as an external SAML 2.0 identity provider (IdP). | Supported Supports standard XML digital signatures (XML-DSig) and TLS with RSA or EC signing certificates. | |
Enable the self-service portal to allow authenticated users to request and manage certificates based on certain criteria. | Supported | |
Use DigiCert® Autoenrollment Server to automate certificate deployment and renewal for users and/or computers within an Active Directory (AD) domain. | Partially supported RSA and EC keyed requests are supported. PQC and Ed25519 keyed requests are not supported. | |
Customize the look and feel of Trust Lifecycle Manager email notifications and internet-accessible web pages | Supported | |
Use the Certificate Management Protocol (CMP) to enroll certificates from Trust Lifecycle Manager. | Partially supported RSA and EC keyed requests are supported. PQC and Ed25519 keyed requests are not supported. | |
Request certificates using web-based enrollment URLs, or view and manage existing certificates through the web self-service portal. | Partially supported RSA and EC keyed requests are supported. PQC and Ed25519 keyed requests are not supported. | |
Enroll and renew certificates using REST API. | Partially supported RSA and EC keyed requests are supported. PQC and Ed25519 keyed requests are not supported. | |
Configure Trust Lifecycle Manager and DigiCert® Private CA applications to enroll and provision certificates using Enrollment over Secure Transport (EST) protocol. | Partially supported RSA and EC keyed requests are supported. PQC and Ed25519 keyed requests are not supported. | |
Discover and manage assets on servers. | Supported | |
Discover and manage assets on network appliances and cloud services. Enable secure network-based integrations, proxy services, and discovery scans. | Supported | |
Use the Microsoft Intune connector to issue certificates from Trust Lifecycle Manager and deliver them to the Intune unified endpoint management (UEM) platform for distribution to users, devices, and servers. | Supported | |
Enable the self-service portal to allow users to search, download, and revoke certificates. | Supported | |
Configure Trust Lifecycle Manager and CA Manager applications to enroll certificates using Simple Certificate Enrollment Protocol (SCEP). | Partially supported RSA and EC keyed requests are supported. PQC and Ed25519 keyed requests are not supported. |
Certificate authorities (CAs)
Connect Trust Lifecycle Manager to supported certificate authorities (CAs) to import, issue, and manage certificates. All CA integrations listed in this section are supported.
Feature | Description |
|---|---|
Connects Trust Lifecycle Manager to DigiCert CertCentral® to issue, import, and manage public DigiCert certificates. | |
Connects Trust Lifecycle Manager to a customer-hosted DigiCert Private CA to issue, import, and revoke private non-escrow certificates. | |
Connects Trust Lifecycle Manager to EJBCA to issue, enroll, and manage certificates, and import existing certificates for centralized management. | |
Connects Trust Lifecycle Manager to GlobalSign Certificate Center (GCC) to discover and import certificates, and issue, manage, and automate public server certificates. | |
Connects Trust Lifecycle Manager to Sectigo to discover and import certificates, and issue, manage, and automate public server certificates. |
Other capabilities and integrations
Use additional Trust Lifecycle Manager capabilities and integrations for reporting, notifications, authentication, and certificate automation.
Feature | Description | Feature availability |
|---|---|---|
Use third-party ACME clients to request, install, and manage certificates from Trust Lifecycle Manager. | Supported | |
Create and manage custom reports for certificate enrollments and certificates. | Supported | |
Enroll new certificates with automated delivery to Windows Certificate Store (CAPI) or IBM Global Security Kit (GSK) keystores on servers, using DigiCert agents. | Supported | |
Discover certificates in Google Cloud and automate certificate delivery and management for supported Google Cloud services. | Supported | |
Configure email notifications for important certificate and system events that require attention. | Supported | |
Use SCIM-provisioned user groups to control access to business units and automatically map group members to those business units. | Supported | |
Integrate privileged access management (PAM) platforms with Trust Lifecycle Manager to securely manage credentials used to authenticate other integrations. | Supported | |
Integrate Trust Lifecycle Manager with ServiceNow to manage certificate lifecycle workflows through the DigiCert Trust Lifecycle Manager app for ServiceNow. | Partially supported Username and password authentication is supported. PKCS#12 client certificate authentication using mutual TLS (mTLS) is not supported. | |
Connect UltraDNS to CertCentral to automate domain control validation (DCV) for certificate issuance. | Supported |