Skip to main content

Understand what Trust Lifecycle Manager controls

DigiCert​​®​​ Trust Lifecycle Manager governs the full lifecycle of certificates and the trust infrastructure around them. Understanding this scope tells you which assets fall under the following configuration guidance.

Area

What Trust Lifecycle Manager does

Certificate lifecycle

Issue and enroll, renew, reissue, revoke, suspend, resume/reinstate, import from external CAs, and recover escrowed keys.

Certificate profiles and templates

Define the key algorithms, key sizes, signature algorithms, validity, and extensions applied to issued certificates.

Certificate authorities

Connect to and provision issuing CAs, including DigiCert-hosted and customer-hosted CAs.

Enrollment protocols

ACME, EST, SCEP, and CMP, plus REST API and browser-based enrollment.

Discovery and inventory

Network and system scans, sensor-based and agent-based discovery, and key discovery.

Automation

Rule-driven certificate renewal, installation, and remediation through agents.

Connectors and integrations

Third-party CA, cloud service, and CMDB integrations.

Business units and seats

Tenant scoping and allocation of licensed seats within an account.

Self-service portal (SSP)

Delegated, end-user certificate operations.

Audit and reporting

Tamper-evident audit logging, dashboards, and scheduled reports.

Note

Trust Lifecycle Manager doesn’t manage users, roles, or permissions itself. Identity, role assignment, and authentication are handled by Account Manager. For more information, see Users and access.