Skip to main content

Configure certificate enrollment securely

DigiCert​​®​​ Trust Lifecycle Manager supports several enrollment protocols. Enable only the ones you actually use, and disable the rest to reduce the attack surface.

Protocol

Guidance

ACME

Use ACME for automated server certificate issuance. Use an external account binding so that only authorized clients can enroll. Rotate ACME credentials on the same cycle as other secrets.

EST

Use EST with client authentication. Tightly control the trust anchor used to authenticate clients.

SCEP

Use SCEP only where a device platform requires it. Treat SCEP challenge passwords as secrets, scope them narrowly, and rotate them frequently.

CMP

Use CMP with authenticated transport and a controlled trust anchor.

REST API

Use service users with the least-privileged role required. Do not reuse a human administrator's credentials for automation.

Self-service portal

Enable only the specific end-user operations you intend to delegate. Key recovery and revocation should not be delegated to end users.

Important

Do not disable TLS verification. The product exposes a TLS verification bypass only for development and QA profiles. Do not use this bypass in a FedRAMP deployment.