Secure agents, sensors, and service users
Agents and sensors act on your infrastructure using machine identities that DigiCert® Trust Lifecycle Manager provisions through DigiCert® Account Manager.
Treat activation codes as secrets. Issue them just in time and let them expire.
Maintain an inventory of registered agents and sensors, and disable any that are no longer deployed. Disabling the agent or sensor also disables its service user certificate.
Review service users in Account Manager during access reviews. They’re identities with real permissions, not configuration objects.
Remember that agent post-processing scripts are disabled in the FIPS distribution. Do not design automation that depends on them.
Scope agent and sensor automation rules to the narrowest set of assets required.