Skip to main content

Tags in Trust Lifecycle Manager

Tags are user-defined labels that help you organize, identify, and manage certificates and other resources in DigiCert​​®​​ Trust Lifecycle Manager. You can assign one or more tags to a resource and use those tags to search, filter, group, and manage certificates across your inventory.

Tags provide additional context that can help you classify certificates based on your organization's operational, business, or technical requirements. For example, you can use tags to identify certificates by environment, application, business unit, ownership group, platform, or criticality.

A certificate can have multiple tags, and the same tag can be assigned to multiple certificates. Tags are user-defined and don’t change certificate data. Instead, they provide an additional layer of classification that helps you organize and manage certificates more effectively.

Why use tags?

As certificate inventories grow, it becomes increasingly difficult to find, manage, and monitor certificates using manual processes alone. Tags help you organize certificates into meaningful groups. This makes it easier to find certificates, create targeted views, and manage notifications.

Tags help simplify certificate lifecycle management by allowing you to:

  • Manage large certificate inventories more efficiently

  • Find certificates quickly

  • Filter certificates based on specific criteria

  • Create custom inventory views

  • Configure targeted notifications

  • Improve inventory visibility and reporting

Tag naming requirements

  • Tags can contain up to 255 characters

  • Tags can include letters (A-Z, a-z), numbers (0-9), and the following special characters: number signs (#), spaces, colons (:), periods (.), ampersands (&), and at symbols (@)

Best practices

Consider the following recommendations when planning your tagging strategy:

  • Establish consistent naming conventions

  • Start with a small set of commonly used tags and expand as needed

  • Use tags that provide meaningful operational, business, or reporting value

  • Avoid creating duplicate tags with similar meanings

  • Apply tags as early as possible in issuance and discovery workflows

  • Review tags periodically to ensure they remain accurate and relevant

Tag examples

Create tags that reflect common aspects of your organization, such as applications, environments, platforms, or criticality. The following examples are intended to illustrate possible naming conventions only. You can create tags using any naming convention that suits your organization.

Applications or services:

  • service-name

  • app-id

Environments:

  • prod

  • stage

  • dev

  • test

Exposure levels:

  • external

  • internal

  • partner

Platforms:

  • f5

  • apache

  • nginx

  • k8s

  • aws

Criticality:

  • tier0

  • tier1

  • tier3

Assign tags

You can create and assign tags in various workflows throughout Trust Lifecycle Manager.

Note

The following examples highlight some of the most common ways to assign tags. They don’t represent an exhaustive list of tagging scenarios.

Create a certificate profile

When creating a certificate profile, you can specify one or more tags. These tags are automatically assigned to all certificates issued using that profile. You can assign tags on the Additional options screen of the Create certificate profile wizard.

Assigning tags at the profile level ensures consistent classification for certificates from the time they’re issued. This reduces manual effort and helps keep certificates organized.

Create discovery scans

When creating a cloud, network, or system scan, you can specify one or more tags in the Certificate assignment rules of the scan configuration. These tags are automatically assigned to all certificates discovered by the scan.

Assigning tags during certificate discovery helps classify certificates as they’re added to the inventory. This improves inventory organization and reduces the need to tag certificates manually after discovery.

Add a connector

You can specify one or more tags to assign to imported certificates when creating a supported connector.

Note

Not all connectors support tagging.

Applying tags through connectors helps classify certificates as they’re imported. This improves consistency and makes imported certificates easier to identify, find, and manage in Trust Lifecycle Manager.

Use rules to automatically assign tags

Instead of assigning tags manually, you can use metadata assignment rules to automatically assign tags to certificates that match specified conditions. Rules evaluate certificate attributes to determine which certificates receive the configured tags. This helps ensure certificates are consistently classified as they're discovered or imported into Trust Lifecycle Manager. It also reduces the need to tag certificates manually.

Use tags

Once you've assigned tags, you can use them in several ways to organize, monitor, and manage your certificate inventory.

Note

The following examples highlight some of the most common ways to use tags after they are assigned. They don’t represent every scenario that supports tags.

Configure notifications

You can use tags as additional criteria when configuring notifications and alerts. This allows you to limit notifications and alerts to certificates with specific tags. Using tags helps ensure that notifications and alerts are relevant to the intended audience.

Note

Users who sign in using single sign-on through their DigiCert​​®​​ account have access to the Alerts feature. You must also contact your account representative to enable the feature for your account.

Filter certificates and create custom views

On the Inventory > Certificates page, you can add the Tags column to the certificate table and use tags to filter certificates. This allows you to quickly monitor and find certificates that share common characteristics. For more information, see Manage tags.

After applying filters, you can save the filtered results as a custom view. Custom views help you quickly access frequently used certificate groups without recreating filters each time.