- DigiCert product docs
- What's new
- Release notes
- IoT Trust Manager
IoT Trust Manager
Release notes RSS
Recent releases
November 3, 2025
DigiCert® ONE version: 1.11280.0 | IoT Trust Manager: 1.885.0
Enhancements
Immediate failure of batch jobs on critical mismatches
Batch jobs now terminate early if inconsistencies are detected between generated amounts and input values.
This prevents partial processing, accelerates error feedback, and safeguards data integrity.
Fixes
Duplicate certificate prevention
Resolved an issue where, under certain retry conditions, previously issued items in a batch could be retried again, potentially causing duplicate certificates.
September 3, 2025
DigiCert® ONE version: 1.10918.0 | IoT Trust Manager: 1.842.0
Enhancements
Display full TLS certificate chain in EST
Added a new flag to display the complete TLS certificate chain during EST configuration.
This option is available in the Enrollment Profile Edit screen.
August 13, 2025
DigiCert® ONE version: 1.10845.0 | IoT Trust Manager: 1.837.0
Enhancements
Security updates
Updated Java and Bouncy Castle libraries to the latest versions to address the potential security concerns in previous releases.
Batch processing improvements
Enhanced the batch process robustness by introducing separate queues for in-progress jobs.
Fixes
Enrollment profile
Resolved an issue preventing modifications to enrollment profiles.
June 25, 2025
DigiCert® ONE version: 1.10427.0 | IoT Trust Manager: 1.803.0
Included in this release:
Enhancements
Configure encryption algorithms in SCEP
Added support for configuring encryption algorithms in SCEP enrollment profiles. Supported algorithms include aes128WithCBC, aes256WithCBC, and desEDEWith3CBC.
This setting is stored in the enrollment profile and applies only to profiles using the SCEP method.
Custom key usage support for unmanaged intermediate CAs
Added support for configuring key usage values in the template for unmanaged intermediate CAs.
This provides greater flexibility and alignment with organizational requirements.
Certificate filtering improvements
Enhanced the certificate search and filtering functionality. With this improvement:
Thumbprint: Now fully searchable.
Organization Name: Added as a supported field for search and filtering operations.
These enhancements improve the ability to locate and analyze certificates using key metadata fields.
Fixes
MAC address handling in Common Names
Resolved an issue where colons were being removed from MAC addresses in Common Names (CN).
MAC addresses now retain their correct format, for example, AA:BB:CC:DD:EE:FF.
June 5, 2025
DigiCert® ONE version: 1.10270.0 | IoT Trust Manager: 1.792.0
Enhancements
Additional configuration for SCEP GetCACert Response
The GetCACert response can now return CA certificates in DER format. This improves compatibility with clients that expect a specific MIME type.
Fixes
Internal server error when deleting authentication certificates
Fixed an issue that stopped the deletion of authentication certificates in the portal.
Certificate re-download for IoT Account Manager
Fixed an issue with re-downloading certificates using the download API.
Internal server error on SCEP enrollment with duplicate passcode
Fixed an authentication issue when a passcode is repeated in an enrollment profile.
May 28, 2025
DigiCert® ONE version: 1.10219.0 | IoT Trust Manager: 1.789.0
Included in this release:
Enhancements
/OU support in Batch Enrollment
The Batch Enrollment flow now supports the specification of Product/Organizational Unit (OU) by the enrolling administrator. This functionality was only available in single certificate requests, and is now consistent across both certificate request types - single certificate requests and batch certificate requests.
Boolean flag for enrollment profiles
Added a new Boolean flag for enrollment profiles. This flag allows users to specify whether the CA certificate response for SCEP should be returned in DER format. It can be set during the enrollment profile creation through the wizard, and is visible on both the Details and Edit pages.
Flag:
scep_get_ca_cert_response_der_formatDefault:
False.
PEM format support for SMPB in batch download
Added a PEM file extension support for SMPB delivery method in batch downloads, enhancing certificate handling and compatibility.
Fixes
Digital signing certificate generation improvements
Fixed an error in generating digital signing certificates during enrollment profile creation with digital signing enabled. The process now completes successfully.
Resolved SCEP payload parsing issues
Resolved SCEP payload parsing issues caused by extra newline characters. These are now automatically removed for proper handling.
April 9, 2025
DigiCert® ONE version: 1.9773.0 | IoT Trust Manager: 1.763.0
Enhancements
Support for Pseudonym attribute in X.509 certificates
IOT Trust Manager now supports the inclusion and processing of the Pseudonym attribute in X.509 certificates, identified by the Object Identifier (OID) 2.5.4.65.
This enhancement enables the representation of a subject’s pseudonym within the Distinguished Name (DN) of the certificate.
Key changes:
The Pseudonym field must be configured in the certificate template.
The Pseudonym can be provided in the Certificate Signing Request (CSR).
Alternatively, it can be passed as request parameters during certificate enrollment.
April 2, 2025
DigiCert® ONE version: 1.9733.0 | IoT Trust Manager: 1.762.0
Included in this release:
New
Added PQC Algorithms SLH-DSA (SPHINCS+) and FN-DSA (FALCON) keys and algorithms
Added Post-Quantum Cryptography support with SLH-DSA (SPHINCS+) and FN-DSA (FALCON) keys and algorithms.
Added PQC composite MLDSA
Added support for Post-Quantum Cryptography (PQC) with composite MLDSA keys and algorithms.
Enhancements
REST API endpoint to download certificate by common name
Added a new REST API endpoint to download certificates by subject common name. If multiple certificates share the same common name, the response will include up to 100 matching certificates.
Added pagination to several list pages
Added pagination to the list pages for Certificates, Devices, Audit Log, Passcodes, Auth Certificates, and Certificate Requests for improved usability.
February 12, 2025
DigiCert® ONE version: 1.9391.0 | IoT Trust Manager: 1.735.0
Enhancements
Additional job for device value field correction on certificate table
A new job has been introduced to populate missing device value fields that were overlooked during migration. Records where the device value identifier is missing have been updated. This ensures clients can reliably filter and search using the device value.
Subject directory attribute retention during certificate renewal
Certificate renewals now correctly retain the Subject Directory Attribute from the original certificate. This fix helps maintain required attributes for compliance and interoperability.
Server-side key generation redirect
When requesting a certificate with server-side key generation, users are now redirected properly:
After copying the password and downloading the certificate, users are taken to the Certificate Details page.
This resolves the previous issue where users were mistakenly sent to the Request List page.
Fixes
Scheduled report data correction
Weekly scheduled reports now include all necessary certificate data.
Both Device Profile and Enrollment profile details are now included.
This update ensures reports provide comprehensive information for tracking and compliance.
ACME Lego client EC256 enrollment
The enrollment process for the ACME Lego client using the EC256 key type has been corrected:
Users are now directed to the Certificate details page after enrollment.
This resolves the issue where users were redirected to the Request list page instead.
Certificate profile dropdown visibility
On the Create Enrollment Profile page, the Certificate Profile dropdown now behaves as expected:
The dropdown remains visible with an empty list when no matching profiles are found.
This prevents confusion by ensuring users see that no available profiles exist rather than having the dropdown disappear.
Enrollment profile dropdown search enhancement
A search/filter option has been added to the Enrollment Profile dropdown on the Start batch certificate request form:
Users can now type to filter and quickly locate the desired enrollment profile.
This eliminates the need for manual scrolling through long lists.
Pre-generated keys checkbox display
The Allow use of pre-generated keys checkbox now accurately reflects its current state during profile editing:
The checkbox remains selected if it was previously enabled.
This prevents users from mistakenly altering key generation settings due to UI discrepancies.
Common name search behavior reverted
The search functionality for Common Name (CN) has been reverted to its original behavior:
Searches now use a “Starts With” filter rather than “Contains.”
This change ensures users can more efficiently locate certificates by matching the CN prefix.
February 4, 2025
DigiCert® ONE version: 1.9100.10 | IoT Trust Manager: 1.733.0
Fixes
Reverted deployment YAML changes
The deployment YAML file has been reverted to its previous configuration to ensure proper functionality when smtpAuth is enabled:
Restored email server password: The email server password is now correctly included when
smtpAuthis set.Reverted modifications: Previous changes to the YAML file have been undone to maintain the intended configuration.
Certificate templates filters
The certificate templates filter has been updated to display only relevant options for for applicable user roles. For most users, only the custom certificate template type is shown. System administrators can still view system certificate template types.
January 30, 2025
DigiCert® ONE version: 1.9100.9 | IoT Trust Manager: 1.731.0
New
Matter certificate template
A new certificate template designed specifically for Matter use cases has been introduced. This template enables the issuance of certificates compatible with Matter environments.
Enhancements
Flag to control audit logging
A new flag has been introduced, allowing DigiCert® to internally disable audit logging on a per-enrollment profile basis. This feature helps prevent excessive logging for clients who repeatedly submit invalid or malformed certificate requests, reducing unnecessary database writes.
Performance improvements
Read and write speeds have been optimized, leading to faster certificate issuance rates. These improvements enhance system efficiency and allow for better handling of high-concurrency scenarios. Users will experience reduced latency and increased throughput, particularly during peak loads.
Fixes
Gateway decryption issue
A critical issue that caused the Gateway service to fail during startup due to a decryption error has been resolved. An updated Gateway JAR file is now available for download.
Endpoint for EST protocol (/ca_certs) compatibility fixes
PKCS7 Encoding: Transitioned from BER (Basic Encoding Rules) to DER (Distinguished Encoding Rules) for PKCS7 encoding. DER is more widely accepted and ensures consistent encoding for certificate responses.
Empty Extensions in CSRs: Enabled support for empty extension sequences in Certificate Signing Requests (CSRs) for
ca_certsin the Enrollment over Secure Transport (EST) protocol. This fix enhances interoperability with client systems adhering to EST standards.