Configure certificate enrollment securely
DigiCert® Trust Lifecycle Manager supports several enrollment protocols. Enable only the ones you actually use, and disable the rest to reduce the attack surface.
Protocol | Guidance |
|---|---|
ACME | Use ACME for automated server certificate issuance. Use an external account binding so that only authorized clients can enroll. Rotate ACME credentials on the same cycle as other secrets. |
EST | Use EST with client authentication. Tightly control the trust anchor used to authenticate clients. |
SCEP | Use SCEP only where a device platform requires it. Treat SCEP challenge passwords as secrets, scope them narrowly, and rotate them frequently. |
CMP | Use CMP with authenticated transport and a controlled trust anchor. |
REST API | Use service users with the least-privileged role required. Do not reuse a human administrator's credentials for automation. |
Self-service portal | Enable only the specific end-user operations you intend to delegate. Key recovery and revocation should not be delegated to end users. |
Important
Do not disable TLS verification. The product exposes a TLS verification bypass only for development and QA profiles. Do not use this bypass in a FedRAMP deployment.