Skip to main content

Secure agents, sensors, and service users

Agents and sensors act on your infrastructure using machine identities that DigiCert​​®​​ Trust Lifecycle Manager provisions through DigiCert® Account Manager.

  • Treat activation codes as secrets. Issue them just in time and let them expire.

  • Maintain an inventory of registered agents and sensors, and disable any that are no longer deployed. Disabling the agent or sensor also disables its service user certificate.

  • Review service users in Account Manager during access reviews. They’re identities with real permissions, not configuration objects.

  • Remember that agent post-processing scripts are disabled in the FIPS distribution. Do not design automation that depends on them.

  • Scope agent and sensor automation rules to the narrowest set of assets required.