Understand what Trust Lifecycle Manager controls
DigiCert® Trust Lifecycle Manager governs the full lifecycle of certificates and the trust infrastructure around them. Understanding this scope tells you which assets fall under the following configuration guidance.
Area | What Trust Lifecycle Manager does |
|---|---|
Certificate lifecycle | Issue and enroll, renew, reissue, revoke, suspend, resume/reinstate, import from external CAs, and recover escrowed keys. |
Certificate profiles and templates | Define the key algorithms, key sizes, signature algorithms, validity, and extensions applied to issued certificates. |
Certificate authorities | Connect to and provision issuing CAs, including DigiCert-hosted and customer-hosted CAs. |
Enrollment protocols | ACME, EST, SCEP, and CMP, plus REST API and browser-based enrollment. |
Discovery and inventory | Network and system scans, sensor-based and agent-based discovery, and key discovery. |
Automation | Rule-driven certificate renewal, installation, and remediation through agents. |
Connectors and integrations | Third-party CA, cloud service, and CMDB integrations. |
Business units and seats | Tenant scoping and allocation of licensed seats within an account. |
Self-service portal (SSP) | Delegated, end-user certificate operations. |
Audit and reporting | Tamper-evident audit logging, dashboards, and scheduled reports. |
Note
Trust Lifecycle Manager doesn’t manage users, roles, or permissions itself. Identity, role assignment, and authentication are handled by Account Manager. For more information, see Users and access.