Understand the trust sources in DigiCert® ONE
A trust source is the certificate-authority service that issues certificates. The selected trust source determines whether the resulting certificates are publicly or privately trusted.
Choose the trust source based on the systems and users that need to recognize that trust:
Use CertCentral for public trust when certificates must be recognized by public browsers, operating systems, email clients, or other systems that use public trust stores. Use it when certificates must be recognized without separately installing or distributing your organization’s private CA certificate to the relying systems.
Use DigiCert Private CA for private trust when the relying systems are managed by your organization and can be configured to trust your private CA. Use it when your organization controls the relying systems and can configure them to trust your private CA.
Your environment can have one or both trust sources, depending on its configuration and certificate requirements.
注記
Public trust does not mean that the certificate, service, or protected system is publicly accessible. It means that the certificate chains to a CA recognized by public trust stores.
Compare trust sources
Feature | CertCentral | DigiCert Private CA |
|---|---|---|
Trust type | Public trust | Private trust |
Recognition | Certificates are recognized by supported public trust stores | Certificates are recognized by systems configured to trust your private CA |
Environment scope | Can serve multiple production environments | Restricted to one environment |
Quantity | Multiple CertCentral accounts can be connected to one environment | No more than one Private CA per environment |
Sharing | Can be shared across products and production environments | Cannot be shared with another environment but can be shared across products within the same environment |
Common use | Public websites, externally distributed software, email, documents, and other public-trust workflows | Managed users, devices, servers, applications, services, and private PKI workflows |
How products use trust sources
Trust sources can work on their own, where you are soley using it to download certificates and use it in external systems.
Alternatively, when a product workflow in your environment requires a certificate:
You determine whether it requires public or private trust.
The product requests the certificate from the appropriate trust source within the same environment.
CertCentral or DigiCert Private CA issues the certificate.
The product manages, distributes, installs, or uses the certificate as part of its workflow.
ヒント
Not every product capability requests a certificate. The trust-source relationship applies to workflows that require certificate issuance.
Product workflow
│
├── Public trust requested
│ └── Request certificate from CertCentral
│
└── Private trust requested
└── Request certificate from DigiCert Private CA