Skip to main content

IoT Trust Manager

Release notes RSS

Recent releases

November 3, 2025

DigiCert® ONE version: 1.11280.0 | IoT Trust Manager: 1.885.0

Enhancements

Immediate failure of batch jobs on critical mismatches

Batch jobs now terminate early if inconsistencies are detected between generated amounts and input values.

This prevents partial processing, accelerates error feedback, and safeguards data integrity.

Fixes

Duplicate certificate prevention

Resolved an issue where, under certain retry conditions, previously issued items in a batch could be retried again, potentially causing duplicate certificates.

September 3, 2025

DigiCert® ONE version: 1.10918.0 | IoT Trust Manager: 1.842.0

Enhancements

Display full TLS certificate chain in EST
  • Added a new flag to display the complete TLS certificate chain during EST configuration.

  • This option is available in the Enrollment Profile Edit screen.

August 13, 2025

DigiCert® ONE version: 1.10845.0 | IoT Trust Manager: 1.837.0

Enhancements

Security updates

Updated Java and Bouncy Castle libraries to the latest versions to address the potential security concerns in previous releases.

Batch processing improvements

Enhanced the batch process robustness by introducing separate queues for in-progress jobs.

Fixes

Enrollment profile

Resolved an issue preventing modifications to enrollment profiles.

June 25, 2025

DigiCert® ONE version: 1.10427.0 | IoT Trust Manager: 1.803.0

Included in this release:

Enhancements

Configure encryption algorithms in SCEP

Added support for configuring encryption algorithms in SCEP enrollment profiles. Supported algorithms include aes128WithCBC, aes256WithCBC, and desEDEWith3CBC.

This setting is stored in the enrollment profile and applies only to profiles using the SCEP method.

Custom key usage support for unmanaged intermediate CAs

Added support for configuring key usage values in the template for unmanaged intermediate CAs.

This provides greater flexibility and alignment with organizational requirements.

Certificate filtering improvements

Enhanced the certificate search and filtering functionality. With this improvement:

  • Thumbprint: Now fully searchable.

  • Organization Name: Added as a supported field for search and filtering operations.

These enhancements improve the ability to locate and analyze certificates using key metadata fields.

Fixes

MAC address handling in Common Names

Resolved an issue where colons were being removed from MAC addresses in Common Names (CN).

MAC addresses now retain their correct format, for example, AA:BB:CC:DD:EE:FF.

June 5, 2025

DigiCert® ONE version: 1.10270.0 | IoT Trust Manager: 1.792.0

Enhancements

Additional configuration for SCEP GetCACert Response

The GetCACert response can now return CA certificates in DER format. This improves compatibility with clients that expect a specific MIME type.

Fixes

Internal server error when deleting authentication certificates

Fixed an issue that stopped the deletion of authentication certificates in the portal.

Certificate re-download for IoT Account Manager

Fixed an issue with re-downloading certificates using the download API.

Internal server error on SCEP enrollment with duplicate passcode

Fixed an authentication issue when a passcode is repeated in an enrollment profile.

May 28, 2025

DigiCert® ONE version: 1.10219.0 | IoT Trust Manager: 1.789.0

Included in this release:

Enhancements

/OU support in Batch Enrollment

The Batch Enrollment flow now supports the specification of Product/Organizational Unit (OU) by the enrolling administrator. This functionality was only available in single certificate requests, and is now consistent across both certificate request types - single certificate requests and batch certificate requests.

Boolean flag for enrollment profiles

Added a new Boolean flag for enrollment profiles. This flag allows users to specify whether the CA certificate response for SCEP should be returned in DER format. It can be set during the enrollment profile creation through the wizard, and is visible on both the Details and Edit pages.

  • Flag: scep_get_ca_cert_response_der_format

  • Default: False.

PEM format support for SMPB in batch download

Added a PEM file extension support for SMPB delivery method in batch downloads, enhancing certificate handling and compatibility.

Fixes

Digital signing certificate generation improvements

Fixed an error in generating digital signing certificates during enrollment profile creation with digital signing enabled. The process now completes successfully.

Resolved SCEP payload parsing issues

Resolved SCEP payload parsing issues caused by extra newline characters. These are now automatically removed for proper handling.

April 9, 2025

DigiCert® ONE version: 1.9773.0 | IoT Trust Manager: 1.763.0

Enhancements

Support for Pseudonym attribute in X.509 certificates

IOT Trust Manager now supports the inclusion and processing of the Pseudonym attribute in X.509 certificates, identified by the Object Identifier (OID) 2.5.4.65.

This enhancement enables the representation of a subject’s pseudonym within the Distinguished Name (DN) of the certificate.

Key changes:

  • The Pseudonym field must be configured in the certificate template.

  • The Pseudonym can be provided in the Certificate Signing Request (CSR).

  • Alternatively, it can be passed as request parameters during certificate enrollment.

April 2, 2025

DigiCert® ONE version: 1.9733.0 | IoT Trust Manager: 1.762.0

Included in this release:

New

Added PQC Algorithms SLH-DSA (SPHINCS+) and FN-DSA (FALCON) keys and algorithms

Added Post-Quantum Cryptography support with SLH-DSA (SPHINCS+) and FN-DSA (FALCON) keys and algorithms.

Added PQC composite MLDSA

Added support for Post-Quantum Cryptography (PQC) with composite MLDSA keys and algorithms.

Enhancements

REST API endpoint to download certificate by common name

Added a new REST API endpoint to download certificates by subject common name. If multiple certificates share the same common name, the response will include up to 100 matching certificates.

Added pagination to several list pages

Added pagination to the list pages for Certificates, Devices, Audit Log, Passcodes, Auth Certificates, and Certificate Requests for improved usability.

February 12, 2025

DigiCert® ONE version: 1.9391.0 | IoT Trust Manager: 1.735.0

Enhancements

Additional job for device value field correction on certificate table

A new job has been introduced to populate missing device value fields that were overlooked during migration. Records where the device value identifier is missing have been updated. This ensures clients can reliably filter and search using the device value.

Subject directory attribute retention during certificate renewal

Certificate renewals now correctly retain the Subject Directory Attribute from the original certificate. This fix helps maintain required attributes for compliance and interoperability.

Server-side key generation redirect

When requesting a certificate with server-side key generation, users are now redirected properly:

  • After copying the password and downloading the certificate, users are taken to the Certificate Details page.

  • This resolves the previous issue where users were mistakenly sent to the Request List page.

Fixes

Scheduled report data correction

Weekly scheduled reports now include all necessary certificate data.

  • Both Device Profile and Enrollment profile details are now included.

  • This update ensures reports provide comprehensive information for tracking and compliance.

ACME Lego client EC256 enrollment

The enrollment process for the ACME Lego client using the EC256 key type has been corrected:

  • Users are now directed to the Certificate details page after enrollment.

  • This resolves the issue where users were redirected to the Request list page instead.

Certificate profile dropdown visibility

On the Create Enrollment Profile page, the Certificate Profile dropdown now behaves as expected:

  • The dropdown remains visible with an empty list when no matching profiles are found.

  • This prevents confusion by ensuring users see that no available profiles exist rather than having the dropdown disappear.

Enrollment profile dropdown search enhancement

A search/filter option has been added to the Enrollment Profile dropdown on the Start batch certificate request form:

  • Users can now type to filter and quickly locate the desired enrollment profile.

  • This eliminates the need for manual scrolling through long lists.

Pre-generated keys checkbox display

The Allow use of pre-generated keys checkbox now accurately reflects its current state during profile editing:

  • The checkbox remains selected if it was previously enabled.

  • This prevents users from mistakenly altering key generation settings due to UI discrepancies.

Common name search behavior reverted

The search functionality for Common Name (CN) has been reverted to its original behavior:

  • Searches now use a Starts With filter rather than Contains.

  • This change ensures users can more efficiently locate certificates by matching the CN prefix.

February 4, 2025

DigiCert® ONE version: 1.9100.10 | IoT Trust Manager: 1.733.0

Fixes

Reverted deployment YAML changes

The deployment YAML file has been reverted to its previous configuration to ensure proper functionality when smtpAuth is enabled:

  • Restored email server password: The email server password is now correctly included when smtpAuth is set.

  • Reverted modifications: Previous changes to the YAML file have been undone to maintain the intended configuration.

Certificate templates filters

The certificate templates filter has been updated to display only relevant options for for applicable user roles. For most users, only the custom certificate template type is shown. System administrators can still view system certificate template types.

January 30, 2025

DigiCert® ONE version: 1.9100.9 | IoT Trust Manager: 1.731.0

New

Matter certificate template

A new certificate template designed specifically for Matter use cases has been introduced. This template enables the issuance of certificates compatible with Matter environments.

Enhancements

Flag to control audit logging

A new flag has been introduced, allowing DigiCert​​®​​ to internally disable audit logging on a per-enrollment profile basis. This feature helps prevent excessive logging for clients who repeatedly submit invalid or malformed certificate requests, reducing unnecessary database writes.

Performance improvements

Read and write speeds have been optimized, leading to faster certificate issuance rates. These improvements enhance system efficiency and allow for better handling of high-concurrency scenarios. Users will experience reduced latency and increased throughput, particularly during peak loads.

Fixes

Gateway decryption issue

A critical issue that caused the Gateway service to fail during startup due to a decryption error has been resolved. An updated Gateway JAR file is now available for download.

Endpoint for EST protocol (/ca_certs) compatibility fixes
  • PKCS7 Encoding: Transitioned from BER (Basic Encoding Rules) to DER (Distinguished Encoding Rules) for PKCS7 encoding. DER is more widely accepted and ensures consistent encoding for certificate responses.

  • Empty Extensions in CSRs: Enabled support for empty extension sequences in Certificate Signing Requests (CSRs) for ca_certs in the Enrollment over Secure Transport (EST) protocol. This fix enhances interoperability with client systems adhering to EST standards.