Create certificate profiles for DigiCert ONE Login
Before enrolling certificates in DigiCert® Trust Lifecycle Manager, create a certificate profile that defines the general properties of the certificate type to issue, along with the enrollment and DigiCert ONE Login (OIDC/SAML) authentication settings. To learn more, see Use the profile configuration wizard.
Certificate profiles
OpenID Connect (OIDC) and SAML authentication protocols are supported only for certificate profiles configured with the Browser PKCS12, CSR, or DigiCert Trust Assistant enrollment method and the DigiCert ONE Login (OIDC/SAML) authentication method.
Specific options for DigiCert ONE Login (OIDC/SAML)
This section explains the specific options available for profiles selected as DigiCert ONE Login (OIDC/SAML) as Authentication method.
Approval and access options
Enforce manual approval flow: Select this option to require manual approval before a certificate is issued.
Restrict user access based on Identity Provider (IdP) metadata: Select this option to configure authorized user groups. Only users with the configured attributes will be able to access this profile.
For example, specifying Group as Key and Sales as Value will only allow users with attribute group=Sales to issue certificates from this profile. Select OR to add more Key Value configuration to expand the target of allowed user groups. So adding Group as Key and Marketing as Value will allow both user with group=Sales and group=Marketing access to this profile. Refer to IdP attribute mapping on how user attributes from the IdP will get relayed to DigiCert ONE.
Using User info as field source
For profiles configured with
DigiCert ONE Login (OIDC/SAML)authentication, you can use user information relayed from your organization’s identity provider to be printed on the issued certificate.In the Subject DN and SAN fields section, you can add Subject DN and Subject Alternative Name (SAN). Selecting User info will allow you to select the specific user info attribute to use for the field.
For example, if you add Email for Subject DN field and selected Email as User info attribute, issued certificate will display user’s email used in your organization’s Identity Provider.
You can select the following as User info attribute:
Name
Email
Surname
Given name
Phone
Custom
Select Custom to configure any other user attribute not in the predefined list. Refer to IdP attribute mapping on how user attributes from the IdP are relayed to DigiCert ONE.
Allowing duplicate certificates across multiple machines
Under the Flow options, enable Allow duplicate certificates to issue certificates with the same Subject DN to multiple machines from a single profile while consuming only one seat.