# DigiCert Documentation > Official product documentation for DigiCert's digital certificate and trust platforms, including CertCentral, Trust Lifecycle Manager, Software Trust Manager, and more. This is a curated index of the documentation, grouped by product. Each link points to a page on the published docs site. Last updated: 2026-08-17. ## Platform overview - [Welcome to DigiCert® ONE](https://docs.digicert.com/en/platform-overview.html): This user guide provides concepts, use cases, and contextual help for managing your DigiCert® ONE account, products, users, roles, and sign-in experience. - [Understand the platform](https://docs.digicert.com/en/platform-overview/understand-the-digicert-one-platform.html): DigiCert ONE is a cloud platform that helps you manage digital trust. It includes DigiCert tools for certificates, public key infrastructure (PKI), document signing, software signing, DNS, and other digital trust needs. - [Understand your account](https://docs.digicert.com/en/platform-overview/understand-the-digicert-one-platform/understand-your-account.html): Your DigiCert ONE account is your organization's top-level space for accessing and managing DigiCert products. It provides a central place to manage users, permissions, subscriptions, global settings, and environments. - [Understand the environments](https://docs.digicert.com/en/platform-overview/understand-the-digicert-one-platform/understand-environments.html): An environment is an isolated workspace within your DigiCert ONE account. Each environment has its own products, configurations, integrations, and certificate workflows. - [Understand the products](https://docs.digicert.com/en/platform-overview/understand-the-digicert-one-platform/understand-products.html): DigiCert products provide capabilities for digital-trust, certificate-issuance, and infrastructure workflows. Products are enabled or connected within an environment. - [Understand users, roles, and access](https://docs.digicert.com/en/platform-overview/understand-the-digicert-one-platform/understand-users--roles--and-access.html): DigiCert ONE uses role-based access control (RBAC) to determine who can access products, and what actions they can perform. - [Understand the licenses, subscriptions, and purchasing models](https://docs.digicert.com/en/platform-overview/understand-the-digicert-one-platform/understand-licenses--subscriptions--and-purchases.html): Access to DigiCert ONE products depends on what is enabled for your account and the purchasing model used. Licenses are typically provided through a subscription or service agreement. They determine the features… - [Understand solutions for post-quantum computing](https://docs.digicert.com/en/platform-overview/understand-the-digicert-one-platform/digicert-solutions-for-post-quantum-computing.html): To enable cryptographic agility across your enterprise, DigiCert® supports the post-quantum cryptography (PQC) standards that can be incorporated in your key pairs and certificates. - [Understand the audit logs](https://docs.digicert.com/en/platform-overview/understand-the-digicert-one-platform/understand-audit-logs.html): Audit logs help you review user activity, investigate security events, and track administrative changes in DigiCert ONE. DigiCert ONE provides two types of audit logs, platform and product. - [Onboard with DigiCert ONE](https://docs.digicert.com/en/platform-overview/onboard-with-digicert-one.html): Use this section to plan and track your DigiCert ONE onboarding. - [Checklist to onboard](https://docs.digicert.com/en/platform-overview/onboard-with-digicert-one/checklist-to-onboard.html): Use this checklist to plan and track your DigiCert ONE onboarding. Complete the tasks in the order listed to ensure that trust sources and products are configured correctly for your organization. - [Create your DigiCert® account](https://docs.digicert.com/en/platform-overview/onboard-with-digicert-one/create-your-digicert-account.html): Your DigiCert® account is your central access point for DigiCert solutions. One account can manage multiple solution instances and environments, such as production and demo. - [Manage your accounts](https://docs.digicert.com/en/platform-overview/manage-your-accounts.html): To stay in control of your accounts and services, review the documentation for: - [DigiCert® account](https://docs.digicert.com/en/platform-overview/manage-your-accounts/digicert-account.html): DigiCert® account is a single sign-in experience to access and manage all your DigiCert services. - [MSP Hub accounts](https://docs.digicert.com/en/platform-overview/manage-your-accounts/partner-account.html): DigiCert® MSP Hub accounts are designed for managed service providers (MSPs) who manage multiple customer subaccounts from a single parent account. - [Account Manager](https://docs.digicert.com/en/platform-overview/manage-your-accounts/account-manager.html): Account Manager is used to manage account access, API integrations, sign-in methods, license usage, and organizations. It also provides audit capabilities through detailed account activity logs, ensuring visibility and… - [Manage your subscriptions](https://docs.digicert.com/en/platform-overview/manage-your-subscriptions.html): DigiCert subscriptions include the certificate (for example, TLS/SSL or code signing) or other service (for example, DNS services), access to customer support, and additional services such as web server vulnerability… - [Common questions about DigiCert subscriptions](https://docs.digicert.com/en/platform-overview/manage-your-subscriptions/common-questions-about-subscriptions.html): DigiCert’s 12-month subscription model is the new, standard payment structure for customers purchasing DigiCert services, including certificate products from CertCentral and DNS services. - [Cancel a service from your DigiCert subscription](https://docs.digicert.com/en/platform-overview/manage-your-subscriptions/cancel-a-service-from-your-digicert-subscription.html): Remove a service from your subscription if you no longer need it and don’t want it included the next time your subscription renews. Your account subscription and all other services remain valid and active. - [Restart a canceled service in your DigiCert subscription](https://docs.digicert.com/en/platform-overview/manage-your-subscriptions/restart-a-canceled-service-in-your-digicert-subscription.html): If you cancel a service in your subscription but later decide to keep it through the next renewal period, restart the service. You can restart a service any time before the end date. - [Cancel your DigiCert subscription](https://docs.digicert.com/en/platform-overview/manage-your-subscriptions/cancel-your-digicert-subscription.html): If you no longer need your DigiCert account and all services that you currently manage, cancel and end your subscription. - [Restart your DigiCert subscription](https://docs.digicert.com/en/platform-overview/manage-your-subscriptions/restart-your-digicert-subscription.html): If you cancel your subscription but later decide to keep your services through the next renewal period, or if you want to add new services, restart your subscription. You can restart your subscription any time before… - [Keep valid certificates after your subscription ends](https://docs.digicert.com/en/platform-overview/manage-your-subscriptions/keep-valid-certificates-after-your-subscription-ends.html): If you cancel your subscription more than 30 days since purchase and want to keep certificates that expire after your subscription ends, you can pay a one-time fee to cover the remaining validity period beyond the… - [What happens when a certificate is revoked?](https://docs.digicert.com/en/platform-overview/manage-your-subscriptions/what-happens-when-a-certificate-is-revoked-1175881.html): When a certificate is revoked, it can no longer be used to provide authentication and encryption for the entity for which it was issued. The risks to your business are different depending on the type of service and… - [How DigiCert subscriptions affect CertCentral Services API integrations](https://docs.digicert.com/en/platform-overview/manage-your-subscriptions/how-digicert-subscriptions-affect-certcentral-services-api-integrations.html): The order validity will work differently for requests placed via your CertCentral Services API integration once we migrate your CertCentral account to a CertCentral subscription-based account. - [Sign in to the platform](https://docs.digicert.com/en/platform-overview/sign-in-url.html): Use this documentation to find the correct sign in URL for your account. The URL you use depends on: - [Use IP addresses and URLs in your firewall allowlist](https://docs.digicert.com/en/platform-overview/platform-ip-addresses-and-urls.html): The following guide provides the necessary DigiCert® ONE IP addresses, URLs, and host environment configurations per region to ensure proper connectivity for your client tools. Add these to your applicable allowlists… - [Access the platform tools](https://docs.digicert.com/en/platform-overview/platform-tools.html) - [Use the DigiCert ONE Clients app](https://docs.digicert.com/en/platform-overview/platform-tools/digicert-one-clients.html): The DigiCert ONE Clients app provides a centralized location to manage all of your DigiCert ONE client tools. It automates installation, configuration and, updates to reduce manual effort, minimize errors, and ensures… - [Manage alerts](https://docs.digicert.com/en/platform-overview/platform-tools/manage-alerts.html): Currently available only with Trust Lifecycle Manager - [Access the audit logs](https://docs.digicert.com/en/platform-overview/audit-logs.html): Platform audit logs track various actions performed by you and users in your account. All solutions have their own audit logs. Use these logs to enhance security, monitor activities, and ensure compliance with… - [Actions tracked in Audit logs](https://docs.digicert.com/en/platform-overview/audit-logs/actions-tracked-in-account-manager.html): The following actions performed by you and users in your account can be tracked in the DigiCert® account Audit logs. - [View Audit logs](https://docs.digicert.com/en/platform-overview/audit-logs/view-audit-logs.html): Audit signs in DigiCert® account provide a detailed record of user actions, to help you monitor activity, troubleshoot issues, and ensure compliance. This guide shows you how to: - [Release notes](https://docs.digicert.com/en/platform-overview/digicert-one-platform-release-notes.html): DigiCert ONE is a unified suite of digital trust products that allow you to deploy and manage multiple PKI solutions in any environment. These release notes provide information about: ## CertCentral - [CertCentral](https://docs.digicert.com/en/certcentral.html): CertCentral is DigiCert's unified platform for managing digital certificates and automating certificate lifecycle workflows. It supports public TLS/SSL, Verified Mark, Code Signing, Document Signing, Client, and S/MIME… - [Get started](https://docs.digicert.com/en/certcentral/get-started.html): CertCentral is DigiCert®'s unified platform for managing digital certificates and automating certificate lifecycle workflows. It centralizes certificate requests, approvals, renewals, validation, reporting, automation… - [Discover your CertCentral path](https://docs.digicert.com/en/certcentral/get-started/discover-your-certcentral-path.html): CertCentral supports multiple account types that align with different business models, purchasing methods, and certificate management needs. Your account path determines how you manage organizations, billing, users, and… - [DigiCert annual plans](https://docs.digicert.com/en/certcentral/get-started/digicert-annual-plans.html): DigiCert® annual plans provide one year of TLS/SSL certificate coverage. However, each TLS certificate issued under the plan is valid for up to 199 days. To keep coverage active for the full year, you must reissue and… - [Explore support and pricing in CertCentral](https://docs.digicert.com/en/certcentral/get-started/explore-support-and-pricing-in-certcentral.html): Support plans define the level of technical assistance, response times, and services available to your organization. Review available support options to identify appropriate resources based on your role and account type. - [Understand how CertCentral works](https://docs.digicert.com/en/certcentral/get-started/understand-how-certcentral-works.html): CertCentral provides a centralized platform for requesting, issuing, and managing digital certificates. It combines account management, validation workflows, and automation capabilities to support secure certificate… - [Certificate types and benefits in CertCentral](https://docs.digicert.com/en/certcentral/get-started/certificate-types-and-benefits-in-certcentral.html): CertCentral supports DigiCert certificates ranging from domain-validated encryption to high-assurance certificates with verified business identity. Certificate types differ by validation level, trust signals, and… - [Choose your certificate workflow in CertCentral](https://docs.digicert.com/en/certcentral/get-started/choose-your-certificate-workflow-in-certcentral.html): CertCentral supports multiple certificate workflows depending on how certificates are purchased, managed, and renewed. Selecting the appropriate workflow ensures that certificate operations align with organizational… - [Onboard an organization in CertCentral](https://docs.digicert.com/en/certcentral/get-started/onboard-an-organization-in-certcentral.html): Organizations represent the legal entity that owns certificates and must complete validation before certificates can be issued. - [Set up your CertCentral account](https://docs.digicert.com/en/certcentral/get-started/set-up-your-certcentral-account.html): This section guides you through the initial setup of your CertCentral account. Work through the topics in this section to establish your user profile, organization information, and personal settings before placing… - [Set up your CertCentral subscription](https://docs.digicert.com/en/certcentral/get-started/set-up-your-certcentral-subscription.html): Before you can request certificates on a Subscription account, purchase a subscription for each certificate type you want to secure. Subscriptions are purchased separately from certificate requests and must be active… - [Configure billing and payment settings](https://docs.digicert.com/en/certcentral/get-started/configure-billing-and-payment-settings.html): Billing and payment settings control how Enterprise and Partner accounts pay for certificates. These settings determine available payment methods and payment workflows. - [Set up notifications and alerts](https://docs.digicert.com/en/certcentral/get-started/set-up-notifications-and-alerts.html): Set up notifications and alerts to control how CertCentral sends certificate, account, and renewal-related messages. Notifications help ensure that the right users are informed about lifecycle events such as expiration… - [Enrollment and validity options in CertCentral](https://docs.digicert.com/en/certcentral/get-started/enrollment-and-validity-options-in-certcentral.html): As of February 24, 2026, DigiCert TLS/SSL certificate plans are one year by default. Learn more about DigiCert annual plans. - [Configure products and certificate settings in CertCentral](https://docs.digicert.com/en/certcentral/get-started/configure-products-and-certificate-settings-in-certcentral.html): Product and certificate settings control how certificates are requested, validated, and issued in CertCentral. These settings define defaults and constraints applied during certificate enrollment and help establish… - [Migrate to CertCentral and modernize certificate workflows](https://docs.digicert.com/en/certcentral/get-started/migrate-to-certcentral-and-modernize-certificate-workflows.html): As of February 24, 2026, DigiCert TLS/SSL certificate plans are one year by default. Learn more about DigiCert annual plans. - [Manage users and access](https://docs.digicert.com/en/certcentral/manage-users-and-access.html): Control who can access CertCentral and define what each user can do within your account. - [User access model](https://docs.digicert.com/en/certcentral/manage-users-and-access/user-access-model.html): CertCentral controls access through user roles, division scope, and the account user management model. Review all three before adding or modifying users. - [Add users to your account](https://docs.digicert.com/en/certcentral/manage-users-and-access/add-users-to-your-account.html): Add users to give them access to CertCentral based on their assigned role and division scope. - [Control user permissions](https://docs.digicert.com/en/certcentral/manage-users-and-access/control-user-permissions.html): Control user permissions by assigning roles and defining division access. Roles determine what actions a user can perform. Division scope limits what a user can view and manage when divisions are enabled. - [Control user authentication method](https://docs.digicert.com/en/certcentral/manage-users-and-access/control-user-authentication-method.html): Control how users authenticate when signing in to CertCentral. Authentication method settings determine whether a user signs in using CertCentral credentials, is restricted to single sign-on (SSO) through a configured… - [Manage CertCentral access through DigiCert Account](https://docs.digicert.com/en/certcentral/manage-users-and-access/manage-certcentral-access-through-digicert-account.html): Manage CertCentral user access through your DigiCert account when your organisation uses centralised identity provisioning across DigiCert services. - [Modify or remove access](https://docs.digicert.com/en/certcentral/manage-users-and-access/modify-or-remove-access.html): Remove or restrict user access when it is no longer required or needs to change. The available actions depend on how your organisation manages user accounts. - [Subaccount management](https://docs.digicert.com/en/certcentral/manage-users-and-access/subaccount-management.html): Subaccounts are CertCentral accounts linked to and managed by a top-level parent CertCentral account. Partners and resellers use subaccounts to give customers individual control over their own CertCentral account and… - [Generate and manage guest URLs](https://docs.digicert.com/en/certcentral/manage-users-and-access/generate-and-manage-guest-urls.html): Guest URLs allow non-CertCentral users to request certificates without needing a login or user account. These URLs provide limited access to specific certificate request forms and are ideal for external users or teams… - [Manage guest access](https://docs.digicert.com/en/certcentral/manage-users-and-access/manage-guest-access.html): Guest access lets a person manage an order without a CertCentral login. With an email address and order number, or the FQDN in the certificate, the person can download, reissue, or revoke the certificate. Enable guest… - [Manage billing and account settings](https://docs.digicert.com/en/certcentral/manage-billing-and-account-settings.html): This chapter covers billing, finances, and account-level configuration settings for your CertCentral account. These tasks do not require technical knowledge of certificates or validation. - [Finances](https://docs.digicert.com/en/certcentral/manage-billing-and-account-settings/finances.html): Manage your account finances, invoices, payment methods, and pricing from the Finances menu in CertCentral. - [CertCentral account balance and purchase order processing](https://docs.digicert.com/en/certcentral/manage-billing-and-account-settings/certcentral-account-balance-and-po-processing.html): Review how the CertCentral account balance is updated and how purchase order (PO) processing affects available funds, billing timelines, and certificate workflows. - [Settings](https://docs.digicert.com/en/certcentral/manage-billing-and-account-settings/settings.html): Configure account-level settings for notifications, integrations, and certificate request forms from the Settings menu in CertCentral. - [Secure your CertCentral account](https://docs.digicert.com/en/certcentral/secure-your-certcentral-account.html): CertCentral provides configurable controls to protect account access and reduce exposure to unauthorised users. - [Configure password policy requirements](https://docs.digicert.com/en/certcentral/secure-your-certcentral-account/configure-password-policy-requirements.html): Define password complexity and expiration requirements for all users in your CertCentral account. Password policies are configured in Settings > Authentication Settings. - [Configure two-factor authentication](https://docs.digicert.com/en/certcentral/secure-your-certcentral-account/configure-two-factor-authentication.html): CertCentral requires two-factor authentication (2FA) for all accounts. Two-factor authentication (2FA) verifies identity through two forms: a username and password, and a second factor such as a one-time password (OTP)… - [Manage two-factor authentication recovery](https://docs.digicert.com/en/certcentral/secure-your-certcentral-account/manage-two-factor-authentication-recovery.html): Administrators can reset two-factor authentication methods when users lose access to a second factor or are locked out after repeated failed authentication attempts. - [Restrict account access by IP address ranges](https://docs.digicert.com/en/certcentral/secure-your-certcentral-account/restrict-account-access-by-ip-address-ranges.html): IP restrictions control which IP addresses can access CertCentral, Guest URLs, and the CertCentral API. By default, CertCentral allows access from any IP address. - [Configure OpenID Connect single sign-on](https://docs.digicert.com/en/certcentral/secure-your-certcentral-account/configure-openid-connect-single-sign-on.html): OpenID Connect (OIDC) allows users to authenticate in CertCentral using credentials from a configured identity provider (IdP). After configuration, users sign in through their IdP rather than with direct CertCentral… - [Configure SAML single sign-on](https://docs.digicert.com/en/certcentral/secure-your-certcentral-account/configure-saml-single-sign-on.html): Use SAML Single Sign-On (SSO) to connect your identity provider (IdP) with CertCentral. - [Perform domain control validation (DCV)](https://docs.digicert.com/en/certcentral/perform-domain-control-validation--dcv-.html): Before DigiCert issues a certificate, you must demonstrate control over the fully qualified domain names or IP addresses included in your request. This process is called domain control validation (DCV). - [Domain validation](https://docs.digicert.com/en/certcentral/perform-domain-control-validation--dcv-/domain-validation.html): The purpose of DigiCert’s domain validation process is to confirm that an organization has the authority to request a certificate for a specific domain. - [Use DigiCert-supported domain control validation (DCV) methods](https://docs.digicert.com/en/certcentral/perform-domain-control-validation--dcv-/use-digicert-supported-domain-control-validation--dcv--methods.html): Select a DCV method that aligns with your environment, infrastructure, and automation requirements. DigiCert supports the following DCV methods: - [Validate domains before or during certificate orders](https://docs.digicert.com/en/certcentral/perform-domain-control-validation--dcv-/validate-domains-before-or-during-certificate-orders.html): CertCentral supports two domain validation workflows. Select the one that fits your certificate type and operational timing. - [Automatic domain control validation (DCV) check](https://docs.digicert.com/en/certcentral/perform-domain-control-validation--dcv-/automatic-domain-control-validation--dcv--check.html): DigiCert's automatic DCV check, also called DCV polling, eliminates the need for you to run validation checks manually when using random-value-based DCV methods. CertCentral performs the DCV check automatically… - [Hide alternative domain control validation (DCV) methods](https://docs.digicert.com/en/certcentral/perform-domain-control-validation--dcv-/hide-alternative-domain-control-validation--dcv--methods.html): CertCentral allows you to customize your DCV method user experience as follows: - [Validate domains on an organization-validated (OV) and extended validation (EV) TLS certificate order](https://docs.digicert.com/en/certcentral/perform-domain-control-validation--dcv-/validate-domains-on-an-ov-and-ev-tls-certificate-order.html): Validate each domain included in an OV or EV TLS certificate order before DigiCert issues the certificate. Domain validation must be complete for all domains on the order before the certificate can be issued. - [Validate domains on a domain validation (DV) TLS certificate order](https://docs.digicert.com/en/certcentral/perform-domain-control-validation--dcv-/validate-domains-on-a-dv-tls-certificate-order.html): Validate each domain included in a DV TLS certificate order before DigiCert issues the certificate. Domain validation must be complete for all domains in the order before the certificate can be issued. - [Domain validation requirements and reuse periods](https://docs.digicert.com/en/certcentral/perform-domain-control-validation--dcv-/domain-validation-requirements-and-reuse-periods.html): Domain validation confirms control of a fully qualified domain name or IP address before DigiCert issues a certificate. Industry requirements limit how long domain validation remains valid and define how validation… - [Validate domains and perform validation checks](https://docs.digicert.com/en/certcentral/perform-domain-control-validation--dcv-/validate-domains-and-perform-validation-checks.html): Use the topics in this section to complete domain control validation for certificate orders and manage DNS CAA records that control which certificate authorities can issue certificates for your domains. - [Order and manage certificates](https://docs.digicert.com/en/certcentral/order-and-manage-certificates.html): As of February 24, 2026, DigiCert TLS/SSL certificate plans are one year by default. Learn more about DigiCert annual plans. - [Prepare to request certificates](https://docs.digicert.com/en/certcentral/order-and-manage-certificates/prepare-to-request-certificates.html): Confirm that you have the required information, validations, and permissions before submitting a certificate request. - [Purchase and manage certificate subscriptions](https://docs.digicert.com/en/certcentral/order-and-manage-certificates/purchase-and-manage-certificate-subscriptions.html): Subscription accounts use a two-step process to obtain certificates. Purchase the certificate first, then submit your request. - [Request certificates](https://docs.digicert.com/en/certcentral/order-and-manage-certificates/request-certificates.html): Use the topics in this section to request certificates in CertCentral by product type and validation level. - [Secure Email products](https://docs.digicert.com/en/certcentral/order-and-manage-certificates/secure-email-certificates.html): DigiCert offers three types of Secure Email Certificates to sign and encrypt your emails. Signing confirms your emails as coming from you, while encryption protects sensitive email data. Secure Email Certificates are… - [Request EU (eIDAS) products](https://docs.digicert.com/en/certcentral/order-and-manage-certificates/request-eu--eidas--products.html): EU (eIDAS) products are only available in DigiCert's European instance of CertCentral, where we store your data in our Europe data centers. If your account uses the European instance, your CertCentral console displays… - [Request PKIoverheid products](https://docs.digicert.com/en/certcentral/order-and-manage-certificates/request-pkioverheid-products.html): PKIoverheid is the Dutch government's Public Key Infrastructure (PKI) system. It is a secure framework that helps organisations and individuals safely exchange information online, ensuring privacy and trust. It uses… - [Order approval delegation](https://docs.digicert.com/en/certcentral/order-and-manage-certificates/authorized-representative-approval-delegation.html): DigiCert provides an automated delegation process in CertCentral that streamlines certificate issuance for certificate products that require approval from a verified contact or authorized representative. - [Manage certificate orders](https://docs.digicert.com/en/certcentral/order-and-manage-certificates/manage-certificate-orders.html): Manage certificate requests and issued certificates throughout the certificate lifecycle in CertCentral. - [Approve certificate requests and manage order-level access](https://docs.digicert.com/en/certcentral/order-and-manage-certificates/approve-certificate-requests-and-manage-order-level-access.html): By default, certificate requests require approval before they are submitted to DigiCert for certificate issuance. - [Configure renewal and notification settings](https://docs.digicert.com/en/certcentral/order-and-manage-certificates/configure-renewal-and-notification-settings.html): Use the topics in this section to configure renewal notification timing, recipients, and certificate lifecycle email settings for your CertCentral account and individual certificate orders. - [Manage domains and organizations](https://docs.digicert.com/en/certcentral/order-and-manage-certificates/manage-domains-and-organizations.html): Use the topics in this section to manage organizations and domains in CertCentral. Organization and domain settings affect certificate requests, validation workflows, approval processes, and lifecycle management. - [Manage certificate transparency (CT) logging](https://docs.digicert.com/en/certcentral/order-and-manage-certificates/manage-certificate-transparency--ct--logging.html): Manage certificate transparency (CT) logging behavior for public TLS/SSL certificates in CertCentral. Public TLS/SSL certificates are logged to public CT logs by default. - [Configure advanced certificate options](https://docs.digicert.com/en/certcentral/order-and-manage-certificates/configure-advanced-certificate-options.html): Control certificate content, issuance behavior, and site presentation in CertCentral. These settings apply at the product or account level depending on your configuration. - [Request SAML certificates](https://docs.digicert.com/en/certcentral/order-and-manage-certificates/request-saml-certificates.html): Use the SAML certificate requests feature to connect your identity provider (IdP) with CertCentral so that users without a CertCentral account can use their Single Sign-On (SSO) credentials to order and manage client… - [Reports and advisories](https://docs.digicert.com/en/certcentral/order-and-manage-certificates/reports-and-advisories.html): Access certificate reports and review advisories that affect certificate validity and lifecycle management. Use reports to monitor certificate inventory, expiration status, validation status, and usage across your… - [Automate certificate lifecycle](https://docs.digicert.com/en/certcentral/automate-certificate-lifecycle.html): Retiring Managed Automation in CertCentral - [Automation service overview](https://docs.digicert.com/en/certcentral/automate-certificate-lifecycle/automation-service-overview.html): Retiring Managed Automation in CertCentral - [Guided TLS/SSL certificate lifecycle automation](https://docs.digicert.com/en/certcentral/automate-certificate-lifecycle/guided-tls-ssl-certificate-lifecycle-automation.html): Certificate lifecycle automation reduces the time and resources you need for repetitive, human-dependent TLS/SSL management tasks. Automation assigns common certificate work, such as generating a certificate signing… - [Before you automate: prerequisites and limitations](https://docs.digicert.com/en/certcentral/automate-certificate-lifecycle/before-you-automate.html): Before configuring automation in CertCentral, confirm that your account, environment, and validation requirements are ready. Automation behavior depends on your account type, user role, payment configuration, and… - [Set up managed automation](https://docs.digicert.com/en/certcentral/automate-certificate-lifecycle/set-up-managed-automation.html): Retiring Managed Automation in CertCentral - [Third-party ACME client integration](https://docs.digicert.com/en/certcentral/automate-certificate-lifecycle/third-party-acme-client-integration.html): CertCentral supports third-party ACME clients such as EFF Certbot and Kubernetes cert-manager as an alternative to the DigiCert native ACME agent. Use third-party ACME clients when the native agent does not fit your… - [Automate certificate issuance using ACME](https://docs.digicert.com/en/certcentral/automate-certificate-lifecycle/automate-certificate-issuance-using-acme.html): The Automated Certificate Management Environment (ACME) protocol enables automated certificate enrollment and lifecycle management in CertCentral. ACME-based automation supports certificate enrollment, renewal… - [Discover certificates to enable lifecycle automation](https://docs.digicert.com/en/certcentral/automate-certificate-lifecycle/discover-certificates-to-enable-lifecycle-automation.html): CertCentral Discovery identifies certificates deployed across internal and public-facing systems. Discovery helps administrators locate unmanaged certificates and bring them under automated lifecycle management. - [Schedule automation events](https://docs.digicert.com/en/certcentral/automate-certificate-lifecycle/schedule-automation-events.html): Use the Automated IPs menu to schedule certificate lifecycle automation events for configured ACME agents and sensors. Schedule automation events after automation clients are installed, configured, and associated with… - [Automate certificate deployment and key management](https://docs.digicert.com/en/certcentral/automate-certificate-lifecycle/automate-certificate-deployment-and-key-management.html): CertCentral automation deploys certificates to supported environments and external key management systems after issuance or renewal. Automated deployment installs certificates consistently and updates them when they are… - [Automate domain validation and reuse](https://docs.digicert.com/en/certcentral/automate-certificate-lifecycle/automate-domain-validation-and-reuse.html): As of February 24, 2026, the domain validation reuse period is limited to 199 days. Learn more about Domain validation requirements and reuse periods. - [Automate certificate renewal and replacement](https://docs.digicert.com/en/certcentral/automate-certificate-lifecycle/automate-certificate-renewal-and-replacement.html): As of February 24, 2026, DigiCert TLS/SSL certificate plans are one year by default. Learn more about DigiCert annual plans. - [Monitor automation health and failures](https://docs.digicert.com/en/certcentral/automate-certificate-lifecycle/monitor-automation-health-and-failures.html): Monitor automation workflows to verify that automated certificate events run successfully and to detect failures that may interrupt certificate issuance, renewal, or deployment. - [Troubleshoot automation issues](https://docs.digicert.com/en/certcentral/automate-certificate-lifecycle/troubleshoot-automation-issues.html): Known issues and troubleshooting tips for CertCentral's automation features. - [Integrate with CertCentral](https://docs.digicert.com/en/certcentral/integrate-with-certcentral.html): As of February 24, 2026, DigiCert TLS/SSL certificate plans are one year by default. Learn more about DigiCert annual plans. - [Automatic domain validation with UltraDNS](https://docs.digicert.com/en/certcentral/integrate-with-certcentral/ultradns-to-certcentral-integration.html): Connect CertCentral with UltraDNS to automate domain control validation (DCV) and keep your domain validations up to date. - [Integrate cloud key management with CertCentral](https://docs.digicert.com/en/certcentral/integrate-with-certcentral/integrate-cloud-key-management-with-certcentral.html): CertCentral integrates with cloud key management platforms to request, store, and manage TLS certificates directly in your cloud environment. When the integration is active, the connected platform submits certificate… - [Monitor certificates, generate reports, and maintain compliance](https://docs.digicert.com/en/certcentral/monitor-certificates--generate-reports--and-maintain-compliance.html): As of February 24, 2026, all public TLS/SSL certificates have a maximum validity of 199 days and domain validation reuse is limited to 199 days. Monitor certificate and domain expiration dates more frequently to avoid… - [Monitor certificate inventory](https://docs.digicert.com/en/certcentral/monitor-certificates--generate-reports--and-maintain-compliance/monitor-certificate-inventory.html): Monitor your certificate inventory to identify upcoming expiration dates, renewal activity, and certificates that require attention. With certificates now capped at 199 days maximum validity, proactive monitoring is… - [CT log monitoring service](https://docs.digicert.com/en/certcentral/monitor-certificates--generate-reports--and-maintain-compliance/ct-log-monitoring-service.html): Secure Site Pro certificates include access to the CT log monitoring service. The service monitors public Certificate Transparency (CT) logs in near real time for TLS/SSL certificates issued for the domains on your… - [Vulnerability assessment service](https://docs.digicert.com/en/certcentral/monitor-certificates--generate-reports--and-maintain-compliance/vulnerability-assessment-service.html): Secure Site Pro SSL, Secure Site Pro EV SSL, and Secure Site EV certificates include access to the vulnerability assessment service. The service scans the public domains on your certificate order for exploitable… - [Generate and export certificate inventory reports](https://docs.digicert.com/en/certcentral/monitor-certificates--generate-reports--and-maintain-compliance/generate-and-export-certificate-inventory-reports.html): CertCentral provides a Report Library for generating and exporting certificate inventory and compliance reports for operational reviews and audits. - [Review audit logs and run validation audits](https://docs.digicert.com/en/certcentral/monitor-certificates--generate-reports--and-maintain-compliance/review-audit-logs-and-run-validation-audits.html): Use exported reports to review account activity and verify validation readiness for governance and compliance purposes. - [Migrate to CertCentral](https://docs.digicert.com/en/certcentral/migrate-to-certcentral.html): As of February 24, 2026, DigiCert TLS/SSL certificate plans are one year by default. Learn more about DigiCert annual plans. - [Prepare for migration](https://docs.digicert.com/en/certcentral/migrate-to-certcentral/prepare-for-migration-to-certcentral.html): Preparing for migration ensures a smooth transition to CertCentral and reduces disruption during certificate lifecycle changes. This topic covers readiness and planning considerations before your CertCentral account is… - [Review your certificate inventory](https://docs.digicert.com/en/certcentral/migrate-to-certcentral/review-your-certificate-inventory.html): Reviewing your existing certificate inventory before migration helps you identify which certificates require immediate revalidation, which are approaching expiration, and which workflows need to be rebuilt in… - [Set up CertCentral after migration](https://docs.digicert.com/en/certcentral/migrate-to-certcentral/set-up-certcentral-after-migration.html): After your CertCentral account is activated, complete the initial configuration before requesting or renewing certificates. This section covers account setup steps specific to migration: adding users, assigning roles… - [Common migration tasks](https://docs.digicert.com/en/certcentral/migrate-to-certcentral/common-migration-tasks.html): As of February 24, 2026, renewed certificates have a maximum validity of 199 days. Plan renewal cycles accordingly. See Moving to 199-day validity for public TLS certificates. - [Welcome QuoVadis users](https://docs.digicert.com/en/certcentral/migrate-to-certcentral/welcome-quovadis-users.html): Migrating from a QuoVadis product? You'll find CertCentral powerful and easy to use, with increased flexibility and security for your certificates. Refer to this documentation as you get comfortable with your new tools. - [Order from a guest URL](https://docs.digicert.com/en/certcentral/migrate-to-certcentral/order-from-a-guest-url.html): A guest URL allows you to order certificates without a login. Learn more here. If you receive a guest URL link: - [Migration FAQ](https://docs.digicert.com/en/certcentral/migrate-to-certcentral/migration-faq.html): Migrating to CertCentral involves changes to how you manage certificates, organizations, domains, and users. Use this section to find answers to common questions about what changes, what stays the same, and how to get… - [Troubleshoot CertCentral issues](https://docs.digicert.com/en/certcentral/troubleshoot-certcentral-issues.html): Use this page to locate troubleshooting guidance for common issues in CertCentral. - [Contact DigiCert Support](https://docs.digicert.com/en/certcentral/contact-digicert-support.html): DigiCert Support can assist with account updates, migration guidance, feature enablement, and technical issues that cannot be resolved through the CertCentral interface. - [CertCentral glossary](https://docs.digicert.com/en/certcentral/glossary.html): An optional OTP app authentication setting that allows users to remember a trusted device for 30 days before re-verification is required. Applies to OTP app authentication only. - [Change log](https://docs.digicert.com/en/certcentral/certcentral-change-log.html): For maintenance schedules and older changes, visit the What's new section of this website. ## DigiCert Private CA - [DigiCert Private CA](https://docs.digicert.com/en/digicert-private-ca.html): DigiCert® Private CA helps you build and operate a privately trusted Public Key Infrastructure (PKI) for securing your organization’s users, devices, applications, and digital assets across both on-premises and cloud… - [Get started](https://docs.digicert.com/en/digicert-private-ca/get-started.html): Here are some basic tenets to keep in mind while using this documentation. - [Licensing](https://docs.digicert.com/en/digicert-private-ca/get-started/licensing.html): DigiCert Private CA operates on a subscription licensing model, offering a range of licenses corresponding to different activities within your account. Understanding these licenses and their limits is essential for… - [Quick start](https://docs.digicert.com/en/digicert-private-ca/get-started/quick-start.html): On a high-level, the setup of your DigiCert® Private CA includes these steps: - [Common workflows](https://docs.digicert.com/en/digicert-private-ca/get-started/common-workflows.html): Here's a quick look at the most common workflows in DigiCert® Private CA. - [Set up a private CA](https://docs.digicert.com/en/digicert-private-ca/set-up-a-private-ca.html): This section walks you through the initial setup process of configuring your private CA hierarchy, creating certificate authorities, managing users and permissions, and preparing your environment for certificate… - [Set up your CA hierarchy](https://docs.digicert.com/en/digicert-private-ca/set-up-a-private-ca/set-up-your-ca-hierarchy.html) - [Set up certificate validation infrastructure](https://docs.digicert.com/en/digicert-private-ca/set-up-a-private-ca/set-up-certificate-validation-infrastructure.html) - [Manage HSMs and Keys](https://docs.digicert.com/en/digicert-private-ca/set-up-a-private-ca/set-up-hsms-and-keypools.html) - [Configure trusted domains](https://docs.digicert.com/en/digicert-private-ca/set-up-a-private-ca/configure-trusted-domains.html): To view the approved domains for your DigiCert ONE OCSPs, CRLS, and AIA Issuers, in CA Manager, visit the Domains page (left main menu, go to Domains), - [Set default OCSP, CRL, AIA issuer, and certificate policies](https://docs.digicert.com/en/digicert-private-ca/set-up-a-private-ca/set-default-ocsp--crl--aia-issuer--and-certificate-policies.html): Default settings in CA Services define the global configuration for OCSP, CRL, Authority Information Access (AIA), and common elements that are applied to a root CA, ICA or end-entity during creation. You do not need to… - [Manage users and API access](https://docs.digicert.com/en/digicert-private-ca/manage-users.html): DigiCert® Private CA enables advanced user access control across your private CA infrastructure, with predefined user roles and a comprehensive list of user permissions. - [User roles in DigiCert-hosted private CA](https://docs.digicert.com/en/digicert-private-ca/manage-users/user-roles-in-digicert-hosted-private-ca.html): DigiCert ONE has a granular role-based access model designed for large-scale, multi-team, multi-product environments. All user roles in DigiCert ONE, including those for DigiCert-hosted private CA, are managed in… - [User roles in customer-hosted private CA](https://docs.digicert.com/en/digicert-private-ca/manage-users/user-roles-in-customer-hosted-private-ca.html): User roles in customer-hosted variant of DigiCert Private CA are optimized for tightly managed offline environments. - [Add users in customer-hosted environments](https://docs.digicert.com/en/digicert-private-ca/manage-users/add-users-in-self-hosted-environments.html): To add a user in the customer-hosted variant of DigiCert Private CA: - [Add API users in customer-hosted environments](https://docs.digicert.com/en/digicert-private-ca/manage-users/add-api-users-in-self-hosted-environments.html): API service users are for API access and functions. Unlike standard users, service users do not represent an individual but are used for automated workflows and integrations. - [Define certificate templates](https://docs.digicert.com/en/digicert-private-ca/set-up-certificate-templates.html): With certificate templates in DigiCert® Private CA, you can govern how your organization uses its private CA resources. - [View certificate templates](https://docs.digicert.com/en/digicert-private-ca/set-up-certificate-templates/view-certificate-templates.html): To view your certificate templates in DigiCert® Private CA select Templates under Manage CAs in the main menu. - [Create a certificate template](https://docs.digicert.com/en/digicert-private-ca/set-up-certificate-templates/create-a-certificate-template.html): Define templates for your root, intermediate, and end-entity certificates. - [Certificate template structure](https://docs.digicert.com/en/digicert-private-ca/set-up-certificate-templates/certificate-template-structure.html): The Template body defines the parameters of certificates issued using that template. The body is coded in JSON format and includes guidelines for the following items: - [Template samples, considerations, and constraints](https://docs.digicert.com/en/digicert-private-ca/set-up-certificate-templates/template-samples-and-best-practices.html): This section provides a sample template for each certificate type, with an exhaustive set of possible parameters. You can also review some important considerations associated with the intermediate and root CA templates. - [Advanced settings: Overriding system defaults](https://docs.digicert.com/en/digicert-private-ca/set-up-certificate-templates/advanced-settings--overriding-system-defaults.html): DigiCert follows system-enforced rules that take priority over your customization while processing your certificate requests. This is necessary for enforcing security policies and maintaining a consistent level of trust. - [Manage CA certificates](https://docs.digicert.com/en/digicert-private-ca/manage-ca-certificates.html) - [Download a root CA certificate](https://docs.digicert.com/en/digicert-private-ca/manage-ca-certificates/download-a-root-ca-certificate.html): To download a root CA certificate in DigiCert® Private CA: - [Export a root CA certificate](https://docs.digicert.com/en/digicert-private-ca/manage-ca-certificates/export-a-root-ca-certificate.html): When a root CA certificate has been configured during creation to allow you to export its keys (private and public), you can export the certificate using a two-person authentication process. - [Download an intermediate CA certificate](https://docs.digicert.com/en/digicert-private-ca/manage-ca-certificates/download-an-intermediate-ca-certificate.html): To download an intermediate CA certificate in DigiCert® Private CA: - [Export an intermediate CA certificate](https://docs.digicert.com/en/digicert-private-ca/manage-ca-certificates/export-an-intermediate-ca-certificate.html): When an intermediate CA certificate has been configured during creation to allow you to export its keys (private and public), you can export the certificate using a multi-factor authentication process. - [Revoke an intermediate CA](https://docs.digicert.com/en/digicert-private-ca/manage-ca-certificates/revoke-an-intermediate-ca.html): To revoke an intermediate CA, you must have two users with any of the following roles: - [Recertify a root or intermediate CA](https://docs.digicert.com/en/digicert-private-ca/manage-ca-certificates/recertify-cas.html): Create a new root or intermediate CA to take over certificate issuance for an expiring CA. When you recertify a CA: - [Manage end entity certificates](https://docs.digicert.com/en/digicert-private-ca/manage-end-entity-certificates.html): DigiCert® Private CA categorizes end entity certificates into the following types: - [REST APIs for end entities](https://docs.digicert.com/en/digicert-private-ca/manage-end-entity-certificates/rest-apis-for-end-entities.html): You can enroll, issue, and manage end-entity certificates using your private CAs through the DigiCert APIs. - [Enrollment protocols](https://docs.digicert.com/en/digicert-private-ca/manage-end-entity-certificates/enrollment-protocols.html): Certificate enrollment or management protocols allow clients and devices to communicate directly with your private CA for certificate enrollment, renewal, and other advanced actions. - [Set up MCP server for Private CA](https://docs.digicert.com/en/digicert-private-ca/set-up-mcp-server-for-private-ca.html): The DigiCert® Private CA Model Context Protocol (MCP) server gives you a conversational way to explore information in your Private CA account using an AI client. Ask questions in natural language to retrieve information… - [Available Private CA MCP tools](https://docs.digicert.com/en/digicert-private-ca/set-up-mcp-server-for-private-ca/available-private-ca-mcp-tools.html): The DigiCert® Private CA MCP server provides read-only tools for retrieving information about your Private CA environment. Your AI client selects the appropriate tool based on your question. - [Prepare to connect an AI client](https://docs.digicert.com/en/digicert-private-ca/set-up-mcp-server-for-private-ca/prepare-to-connect-an-ai-client.html): Before you connect an AI client to the DigiCert® Private CA MCP server, make sure that you have the required DigiCert ONE access and connection information. - [Connect Claude Desktop](https://docs.digicert.com/en/digicert-private-ca/set-up-mcp-server-for-private-ca/connect-claude-desktop.html): Connect Claude Desktop to the DigiCert® Private CA MCP server to ask questions about your Private CA environment. - [Connect Cursor](https://docs.digicert.com/en/digicert-private-ca/set-up-mcp-server-for-private-ca/connect-cursor.html): Connect Cursor to the DigiCert® Private CA MCP server to ask questions about your Private CA environment. - [Connect GitHub Copilot in Visual Studio](https://docs.digicert.com/en/digicert-private-ca/set-up-mcp-server-for-private-ca/connect-github-copilot-in-visual-studio.html): Connect GitHub Copilot in Visual Studio to the DigiCert® Private CA MCP server to ask questions about your DigiCert-hosted Private CA environment. - [Connect GitHub Copilot in Visual Studio Code](https://docs.digicert.com/en/digicert-private-ca/set-up-mcp-server-for-private-ca/connect-github-copilot-in-visual-studio-code.html): Connect GitHub Copilot in Visual Studio Code to the DigiCert® Private CA MCP server to ask questions about your DigiCert-hosted Private CA environment. - [Use post-quantum cryptography](https://docs.digicert.com/en/digicert-private-ca/use-post-quantum-cryptography.html): To help you prepare your environments for the impact of quantum computing in the future, DigiCert supports post-quantum cryptography (PQC) signature algorithms. - [Install and host your private CA](https://docs.digicert.com/en/digicert-private-ca/install-and-host-your-private-ca.html) - [Prepare for installation](https://docs.digicert.com/en/digicert-private-ca/install-and-host-your-private-ca/prepare-for-installation.html): Before installing DigiCert® Private CA, contact your DigiCert account manager and make sure your environment meets these minimum requirements. - [Install DigiCert Private CA](https://docs.digicert.com/en/digicert-private-ca/install-and-host-your-private-ca/install-digicert-private-ca.html): Before installing a self-hosted DigiCert® Private CA: - [Setup SAML SSO in customer-hosted environments](https://docs.digicert.com/en/digicert-private-ca/install-and-host-your-private-ca/setup-saml-sso-in-customer-hosted-environments.html): Security Assertion Markup Language (SAML) Single Sign-On (SSO) lets your team sign in to DigiCert® Private CA, in a customer-hosted environment, with credentials from your organization’s own identity provider (IdP). - [Release notes](https://docs.digicert.com/en/digicert-private-ca/ca-manager-release-notes.html): For maintenance schedules and older releases, visit the What's new section of this website. ## DigiCert DNS - [DigiCert DNS](https://docs.digicert.com/en/digicert-dns.html): DigiCert® DNS is a purpose-built platform that gives teams full control, flexibility, and scale to manage modern DNS infrastructure. Designed for dynamic, distributed, and multi-tenant environments, it elevates DNS from… - [Get started](https://docs.digicert.com/en/digicert-dns/get-started.html): DigiCert® DNS is a fully managed DNS solution integrated into the DigiCert® ONE platform. Built for engineers, operators, and platform teams, it offers centralized control, fine-grained access, and enterprise-grade… - [Overview](https://docs.digicert.com/en/digicert-dns/get-started/overview.html): DigiCert® DNS is a modern, enterprise-grade DNS management platform that gives infrastructure and platform teams complete control over DNS configuration, security, and operations across distributed environments. With… - [Benefits](https://docs.digicert.com/en/digicert-dns/get-started/benefits.html): DigiCert® DNS is a comprehensive DNS management platform that gives users complete control over their DNS infrastructure. This document outlines its key benefits. - [Use cases](https://docs.digicert.com/en/digicert-dns/get-started/use-cases.html): This document highlights common scenarios for managing and optimizing domain and network infrastructure using DigiCert® DNS. These include: - [Access DigiCert DNS](https://docs.digicert.com/en/digicert-dns/get-started/access-digicert-dns.html): To access DigiCert® DNS, you must have a DigiCert® account. To sign up, click here. - [Features and functions](https://docs.digicert.com/en/digicert-dns/features-and-functions.html): This document provides a comprehensive listing of DigiCert® DNS’s key features and their associated functions, offering a clear overview of the platform’s capabilities. - [Access and credential management](https://docs.digicert.com/en/digicert-dns/features-and-functions/access-and-credential-management.html): A feature that enhances security and ensures compliance by providing authentication token management, API key lifecycle control, and TSIG-based DNS transaction security. - [Domain configuration and management](https://docs.digicert.com/en/digicert-dns/features-and-functions/domain-configuration-and-management.html): In DigiCert® DNS, managed domains (as seen in the UI) are referred to as primary domains in the documentation. Both terms refer to the same concept. - [Nameserver and nameserver set configuration](https://docs.digicert.com/en/digicert-dns/features-and-functions/nameserver-and-nameserver-set-configuration.html): A feature that enables users to configure nameservers and nameserver sets, giving them full control, consistency, and flexibility in managing DNS across multiple domains. - [Record configuration and management](https://docs.digicert.com/en/digicert-dns/features-and-functions/record-configuration-and-management.html): A feature that enables users to configure, manage, and retrieve the DNS record types of both primary and secondary domains. - [Reporting and analysis](https://docs.digicert.com/en/digicert-dns/features-and-functions/reporting-and-analysis.html): A feature that provides users with detailed insights into domain activity, usage statistics, and billing, enabling improved decision-making and operational efficiency. - [Resource and resource group management](https://docs.digicert.com/en/digicert-dns/features-and-functions/resource-and-resource-group-management.html): A feature that enables users to manage and organize resources and resource groups, streamlining administration and enforcing policies. - [User and user group management](https://docs.digicert.com/en/digicert-dns/features-and-functions/user-and-user-group-management.html): A feature that enables the management of users, user groups, and user roles, supporting fine-grained access control and centralized administrative oversight. - [Zone transfer management](https://docs.digicert.com/en/digicert-dns/features-and-functions/zone-transfer-management.html): A feature that enables users to control DNS zone transfers with greater precision and security. The primary IP set, managed by DigiCert® DNS, represents the authoritative servers that hold the original zone data. The… - [API integration](https://docs.digicert.com/en/digicert-dns/api-integration.html): This section provides two essential resources - the API guide and its validation messaging - to help you authenticate, configure, and use the DigiCert® DNS API. - [API guide](https://docs.digicert.com/en/digicert-dns/api-integration/api-guide.html): This guide provides step-by-step instructions for testing DigiCert® DNS's API endpoints using an API key generated within the DigiCert® DNS platform. Follow the procedure in order, or start at Step 2 if you already have… - [Validation messaging](https://docs.digicert.com/en/digicert-dns/api-integration/validation-messaging.html): This document provides API validation messages for DNS and infrastructure components, supplementing endpoint testing. Items are organized by function to facilitate easier reference and navigation. - [Release notes](https://docs.digicert.com/en/digicert-dns/release-notes.html): This document summarizes the DigiCert® DNS development lifecycle and provides a versioned archive of release notes covering features, improvements, fixes, and known issues. - [GA 1.4.0](https://docs.digicert.com/en/digicert-dns/release-notes/ga-1-4-0.html): DigiCert® is pleased to announce the release of DigiCert® DNS GA 1.4.0. - [GA 1.3.0](https://docs.digicert.com/en/digicert-dns/release-notes/ga-1-3-0.html): DigiCert® is pleased to announce the release of DigiCert® DNS GA 1.3.0. - [GA 1.2.0](https://docs.digicert.com/en/digicert-dns/release-notes/ga-1-2-0.html): DigiCert® is pleased to announce the release of DigiCert® DNS GA 1.2.0. - [GA 1.1.0](https://docs.digicert.com/en/digicert-dns/release-notes/ga-1-1-0.html): DigiCert® is pleased to announce the release of DigiCert® DNS GA 1.1.0. - [GA 1.0.0](https://docs.digicert.com/en/digicert-dns/release-notes/ga-1-0-0.html): DigiCert® is pleased to announce the release of DigiCert® DNS GA 1.0.0. - [Support](https://docs.digicert.com/en/digicert-dns/support.html): This section serves as your primary resource for resolving issues, seeking assistance, and ensuring the smooth operation of DigiCert® DNS. Whether you require direct help from our team or are troubleshooting an error… - [Contact us](https://docs.digicert.com/en/digicert-dns/support/contact-us.html): Need faster support? Account-wide support packages are available for purchase, giving you access to prioritized assistance and enhanced support resources. Click here for more details and pricing information. - [Troubleshooting guide](https://docs.digicert.com/en/digicert-dns/support/troubleshooting-guide.html): This section helps you diagnose and resolve issues with DigiCert® DNS. Select an error code below to view a detailed article on its cause and resolution. ## Trust Lifecycle Manager - [Trust Lifecycle Manager](https://docs.digicert.com/en/trust-lifecycle-manager.html): DigiCert® Trust Lifecycle Manager is a unified digital trust solution that integrates CA-agnostic certificate management and PKI services. Trust Lifecycle Manager brings together: - [Get started](https://docs.digicert.com/en/trust-lifecycle-manager/get-started.html): Information to help you learn about and start using DigiCert® Trust Lifecycle Manager. - [Overview](https://docs.digicert.com/en/trust-lifecycle-manager/get-started/overview.html): Learn more about DigiCert® Trust Lifecycle Manager. - [Quick start guides](https://docs.digicert.com/en/trust-lifecycle-manager/get-started/quick-start-guides.html): The following guides help you get up and running with DigiCert® Trust Lifecycle Manager. - [Trust Architecture Playbook](https://docs.digicert.com/en/trust-lifecycle-manager/get-started/trust-architecture-playbook.html): The DigiCert® Trust Architecture Playbook is a roadmap of best practices to help organizations modernize their PKI through the DigiCert® ONE platform, using DigiCert® Trust Lifecycle Manager to unify lifecycle… - [Set up your account](https://docs.digicert.com/en/trust-lifecycle-manager/set-up-your-account.html): To prepare your working environment in DigiCert® Trust Lifecycle Manager, set up users and API access, verify your licenses (seats), and customize your account settings and metadata. - [Users and access](https://docs.digicert.com/en/trust-lifecycle-manager/set-up-your-account/users-and-access.html): Each person or service that accesses DigiCert® Trust Lifecycle Manager needs a valid user account with associated permissions that control which functions they can access. - [Seats](https://docs.digicert.com/en/trust-lifecycle-manager/set-up-your-account/seats.html): DigiCert® Trust Lifecycle Manager uses seats as a licensing unit. This section covers the tools used to monitor and manage the seat licenses in your account. - [Business units](https://docs.digicert.com/en/trust-lifecycle-manager/set-up-your-account/business-units.html): Use business units to segment your organization’s certificate issuance and management. - [Certificate metadata](https://docs.digicert.com/en/trust-lifecycle-manager/set-up-your-account/certificate-metadata.html): Certificate metadata helps you identify, organize, and manage certificates in your DigiCert® Trust Lifecycle Manager inventory by adding business context beyond what's included in the certificates themselves. You can… - [Assignment rules](https://docs.digicert.com/en/trust-lifecycle-manager/set-up-your-account/assignment-rules-for-certificates-and-account-resources.html): With the Rules feature in DigiCert® Trust Lifecycle Manager, you can define rules for the automatic assignment of metadata and administrative fields to certificates and DigiCert agents in your account. Set up rules in… - [Trust anchors](https://docs.digicert.com/en/trust-lifecycle-manager/set-up-your-account/trust-anchors.html): A trust anchor is a root or intermediate CA certificate that a system trusts and uses as the basis for verifying other certificates. To view current trust anchors in your account, go to Inventory > Trust stores > CA… - [Self-service portal](https://docs.digicert.com/en/trust-lifecycle-manager/set-up-your-account/self-service-portal.html): With the self-service portal for DigiCert® Trust Lifecycle Manager, end users can download, manage, or enroll their own certificates from their web browser. Enable the self-service portal so users can help themselves… - [Other settings](https://docs.digicert.com/en/trust-lifecycle-manager/set-up-your-account/other-settings.html): Additional account-level settings are available from the Account > Settings page in DigiCert® Trust Lifecycle Manager. - [Build your inventory and ecosystem](https://docs.digicert.com/en/trust-lifecycle-manager/build-your-inventory-and-ecosystem.html): Use these tools to populate your inventory and connect systems for discovery, automation, and management. DigiCert® Trust Lifecycle Manager is CA agnostic and enables you to unify digital trust assets and services… - [Deploy and manage agents](https://docs.digicert.com/en/trust-lifecycle-manager/build-your-inventory-and-ecosystem/deploy-and-manage-agents.html): The DigiCert® agent software is DigiCert’s native client for discovering and managing certificates on servers. You need to install an agent on each server system to use the following features in DigiCert® Trust… - [Deploy and manage sensors](https://docs.digicert.com/en/trust-lifecycle-manager/build-your-inventory-and-ecosystem/deploy-and-manage-sensors.html): The DigiCert® sensor software is DigiCert’s native gateway application for enabling network-based integrations, discovery, proxy, and automation services. You need at least one sensor installed on your network to use… - [Add connectors](https://docs.digicert.com/en/trust-lifecycle-manager/build-your-inventory-and-ecosystem/connectors.html): Connectors are pre-built integrations for connecting systems and services to your management ecosystem in DigiCert® Trust Lifecycle Manager. Select the connector types below for details about each. - [Set up custom plugins](https://docs.digicert.com/en/trust-lifecycle-manager/build-your-inventory-and-ecosystem/plugins.html): Plugins are an extensibility feature for developing custom connectors for DigiCert® Trust Lifecycle Manager. If there's no native connector for a particular platform, you can use a custom plugin to integrate and manage… - [Use discovery tools](https://docs.digicert.com/en/trust-lifecycle-manager/build-your-inventory-and-ecosystem/discovery-tools.html): Discovery is a core feature of DigiCert® Trust Lifecycle Manager that's built into the same tools used for certificate lifecycle management. For example: - [Import externally issued certificates using the API](https://docs.digicert.com/en/trust-lifecycle-manager/build-your-inventory-and-ecosystem/import-externally-issued-certificates-using-the-api.html): How to use the REST API to import your existing certificates from third-party (external) CA systems into DigiCert® Trust Lifecycle Manager. - [Monitor assets to prevent downtime](https://docs.digicert.com/en/trust-lifecycle-manager/monitor-assets-to-prevent-downtime.html): Use the monitoring and notification tools in DigiCert® Trust Lifecycle Manager to track important lifecycle events for your inventory and ensure you always have valid certificates installed on your systems. - [Dashboard](https://docs.digicert.com/en/trust-lifecycle-manager/monitor-assets-to-prevent-downtime/dashboard.html): The Dashboard provides a visual overview of your DigiCert® Trust Lifecycle Manager account with integrated shortcuts to help manage your account resources and inventory. Dashboard shortcuts launch pre-filtered views of… - [Inventory functions](https://docs.digicert.com/en/trust-lifecycle-manager/monitor-assets-to-prevent-downtime/inventory.html): The Inventory page is the central location for monitoring and managing all your digital trust assets in DigiCert® Trust Lifecycle Manager. - [Access certificates with LDAP](https://docs.digicert.com/en/trust-lifecycle-manager/monitor-assets-to-prevent-downtime/access-certificates-with-ldap.html): DigiCert® Trust Lifecycle Manager and CA Manager each have a database that hosts their certificate and Certificate Revocation List (CRL) data. To access this data, you can enable LDAP searches for your certificate… - [Reporting and auditing](https://docs.digicert.com/en/trust-lifecycle-manager/monitor-assets-to-prevent-downtime/reporting-and-auditing.html): The Reporting menu in DigiCert® Trust Lifecycle Manager provides access to detailed usage reports and event logs for your account. - [AI-powered inventory analysis](https://docs.digicert.com/en/trust-lifecycle-manager/monitor-assets-to-prevent-downtime/ai-powered-inventory-analysis.html): Use the AI tools described here to analyze the inventory data in your DigiCert® Trust Lifecycle Manager account and identify anomalies or issues requiring attention, helping you maintain a consistent and stable… - [Notifications and alerts](https://docs.digicert.com/en/trust-lifecycle-manager/monitor-assets-to-prevent-downtime/notifications-and-alerts.html): DigiCert® Trust Lifecycle Manager helps you manage notifications and alerts for important certificate and system events. These features help you stay informed about activities that may require attention. - [Define policies to ensure compliance](https://docs.digicert.com/en/trust-lifecycle-manager/define-policies-to-ensure-compliance.html): DigiCert® Trust Lifecycle Manager uses templates and profiles to enforce consistent certificate use and help you comply with organizational policies plus industry standards such as NIST, FIPS, and the CA/Browser Forum… - [Base templates](https://docs.digicert.com/en/trust-lifecycle-manager/define-policies-to-ensure-compliance/certificate-templates.html): The base template is where the configuration of a certificate starts in DigiCert® Trust Lifecycle Manager. Base templates are used to create certificate profiles, which in turn are used to issue certificates. - [Certificate profiles](https://docs.digicert.com/en/trust-lifecycle-manager/define-policies-to-ensure-compliance/certificate-profiles.html): To enroll certificates through DigiCert® Trust Lifecycle Manager, you first need to create certificate profiles. A certificate profile defines the general configuration options for each type of certificate you can… - [Prepare enrollment codes for authentication](https://docs.digicert.com/en/trust-lifecycle-manager/define-policies-to-ensure-compliance/prepare-enrollment-codes-for-authentication.html): For certificate profiles that use the Enrollment Code authentication method, you must register the allowed enrollment codes in DigiCert® Trust Lifecycle Manager before users can enroll certificates from those profiles. - [Enroll and manage certificates](https://docs.digicert.com/en/trust-lifecycle-manager/enroll-and-manage-certificates.html): DigiCert® Trust Lifecycle Manager provides many different methods for enrolling certificates in your account. You configure the allowed enrollment methods in your certificate profiles, then use those enrollment methods… - [DigiCert Trust Assistant](https://docs.digicert.com/en/trust-lifecycle-manager/enroll-and-manage-certificates/digicert-trust-assistant.html): DigiCert® Trust Assistant is a cross-platform desktop application designed for seamless key management and certificate lifecycle operations. It enables users to generate keys and Certificate Signing Requests (CSRs)… - [Web self-service options](https://docs.digicert.com/en/trust-lifecycle-manager/enroll-and-manage-certificates/web-self-service-options.html): DigiCert® Trust Lifecycle Manager provides the ability for users to request certificates via web-based enrollment URLs, or to view and manage their existing certificates through a web self-service portal. - [Enrollment protocols and APIs](https://docs.digicert.com/en/trust-lifecycle-manager/enroll-and-manage-certificates/enrollment-protocols-and-apis.html): DigiCert® Trust Lifecycle Manager supports the following certificate enrollment protocols, plus API-based enrollments. Select the links to learn more about each enrollment type. - [Autoenrollment Server](https://docs.digicert.com/en/trust-lifecycle-manager/enroll-and-manage-certificates/autoenrollment-server.html): DigiCert® Autoenrollment Server automates certificate deployment and renewal for users and/or computers within an Active Directory (AD) domain. Supported client operating systems track the validity of issued… - [Post-quantum cryptography (PQC)](https://docs.digicert.com/en/trust-lifecycle-manager/enroll-and-manage-certificates/post-quantum-cryptography-pqc.html): Use DigiCert® Trust Lifecycle Manager to issue and manage (revoke, suspend/resume, or escrow/recover) private post-quantum cryptography (PQC) certificates using the ML-DSA or SLH-DSA algorithms. You can also use network… - [Enrollment how-to guides](https://docs.digicert.com/en/trust-lifecycle-manager/enroll-and-manage-certificates/enrollment-how-to-guides.html): The following how-to guides provide instructions for select certificate types and enrollment scenarios. - [Manage enrollment requests](https://docs.digicert.com/en/trust-lifecycle-manager/enroll-and-manage-certificates/manage-enrollment-requests.html): The Inventory > Enrollments page in DigiCert® Trust Lifecycle Manager includes data about requests to enroll certificates in your account, with options to manage enrollments for the Enrollment Code or Manual Approval… - [Manage certificates in inventory](https://docs.digicert.com/en/trust-lifecycle-manager/enroll-and-manage-certificates/manage-certificates-in-inventory.html): The Inventory > Certificates page includes data about all the certificates issued, discovered, or imported in your account, with options to manage certificates and related assets. - [Automate management of certificates](https://docs.digicert.com/en/trust-lifecycle-manager/automate-management-of-certificates.html): The automation features for DigiCert® Trust Lifecycle Manager simplify every phase of certificate lifecycle management from the initial certificate request to installation and renewals. Use these tools to reduce TLS… - [Managed automation solution](https://docs.digicert.com/en/trust-lifecycle-manager/automate-management-of-certificates/managed-automation-solution.html): Managed automation is DigiCert's comprehensive solution for automating certificates on servers, network appliances, cloud services, and vaults. It works in conjunction with the inventory functions in DigiCert® Trust… - [ACME automation service](https://docs.digicert.com/en/trust-lifecycle-manager/automate-management-of-certificates/acme-automation-service.html): Automatic Certificate Management Environment (ACME) is an industry-standard protocol designed to reduce TLS administration costs by coordinating certificate lifecycle events between certificate authorities and host… - [Infrastructure automation](https://docs.digicert.com/en/trust-lifecycle-manager/automate-management-of-certificates/infrastructure-automation.html): DigiCert® Trust Lifecycle Manager can issue and deliver certificates to your DevOps platforms via its ACME service or REST API. - [Trust stores management](https://docs.digicert.com/en/trust-lifecycle-manager/automate-management-of-certificates/trust-stores-management.html): The Inventory > Trust stores page in DigiCert® Trust Lifecycle Manager is a centralized location for defining, distributing, and managing trusted CA certificates across your environment. It gives you a single interface… - [Integration guides](https://docs.digicert.com/en/trust-lifecycle-manager/integration-guides.html): Instructions and comprehensive guides for integrating different vendors and platforms with your DigiCert® Trust Lifecycle Manager ecosystem. - [Citrix FAS](https://docs.digicert.com/en/trust-lifecycle-manager/integration-guides/citrix-fas-integration.html): This guide covers all the steps needed to integrate Citrix FAS with DigiCert® Trust Lifecycle Manager, using DigiCert Autoenrollment Server for certificate provisioning. - [F5 BIG-IP LTM](https://docs.digicert.com/en/trust-lifecycle-manager/integration-guides/f5-big-ip-ltm-integration.html): This guide covers all the steps needed to connect and manage an F5 BIG-IP Local Traffic Manager (LTM) network appliance using DigiCert® Trust Lifecycle Manager. - [HashiCorp Vault](https://docs.digicert.com/en/trust-lifecycle-manager/integration-guides/hashicorp-vault.html): Connect DigiCert® Trust Lifecycle Manager to your HashiCorp Vault instance to issue and manage your certificates. - [Jamf Pro](https://docs.digicert.com/en/trust-lifecycle-manager/integration-guides/jamf-pro-integration.html): DigiCert® Trust Lifecycle Manager facilitates certificate issuance through your Jamf Pro mobile device management (MDM) environment, using the following integration methods. Select the links for detailed guides about… - [Microsoft CA server](https://docs.digicert.com/en/trust-lifecycle-manager/integration-guides/microsoft-ca-server-integration.html): This guide covers the complete process needed to set up a Microsoft CA server integration using a CA connector in DigiCert® Trust Lifecycle Manager. - [Microsoft Intune](https://docs.digicert.com/en/trust-lifecycle-manager/integration-guides/intune-scep-integration.html) - [ServiceNow](https://docs.digicert.com/en/trust-lifecycle-manager/integration-guides/servicenow-integration.html): DigiCert® ONE Trust Lifecycle Manager integrates with ServiceNow using an app available from the ServiceNow Store: - [Windows Hello for Business](https://docs.digicert.com/en/trust-lifecycle-manager/integration-guides/windows-hello-for-business-integration.html) - [Workspace ONE](https://docs.digicert.com/en/trust-lifecycle-manager/integration-guides/workspace-one-integration.html): DigiCert® Trust Lifecycle Manager facilitates certificate issuance through your Workspace ONE unified endpoint management (UEM) environment. This integration uses the REST API service of Trust Lifecycle Manager to… - [Troubleshooting](https://docs.digicert.com/en/trust-lifecycle-manager/troubleshooting.html): This section provides troubleshooting help for DigiCert® Trust Lifecycle Manager and links to other pages for more information. Use the search and navigation functions to find additional troubleshooting topics. Most… - [Troubleshoot SAML](https://docs.digicert.com/en/trust-lifecycle-manager/troubleshooting/troubleshoot-saml.html): This is not a comprehensive list, only a selection of most commonly encountered error messages. - [Other troubleshooting links](https://docs.digicert.com/en/trust-lifecycle-manager/troubleshooting/other-troubleshooting-links.html): Use the below links for additional troubleshooting help with DigiCert® Trust Lifecycle Manager and related tools and features. - [Release notes](https://docs.digicert.com/en/trust-lifecycle-manager/trust-lifecycle-manager-release-notes.html): For maintenance schedules and older releases, visit the What's new section of this website. ## Software Trust Manager - [Software Trust Manager](https://docs.digicert.com/en/software-trust-manager.html): DigiCert® Software Trust Manager is a digital trust solution that protects the integrity of software-based products across the supply chain. Software Trust achieves this through threat and vulnerability detection… - [Get started](https://docs.digicert.com/en/software-trust-manager/get-started.html): You must have a DigiCert® ONE account to access DigiCert® Software Trust Manager. If you don't currently have access to DigiCert ONE, contact your account administrator to provide you with credentials or request a… - [Overview](https://docs.digicert.com/en/software-trust-manager/get-started/overview.html): Learn more about DigiCert® Software Trust Manager. - [Requirements](https://docs.digicert.com/en/software-trust-manager/get-started/requirements.html): DigiCert® requires two-factor authentication (2FA) for all DigiCert® Software Trust Manager users. This requirement applies to signing activities and to DigiCert® ONE-based actions, such as keypair and certificate… - [Quick start guides](https://docs.digicert.com/en/software-trust-manager/get-started/quick-start-guides.html): The following guides help you to get started with DigiCert® Software Trust Manager, based on the user role that you're assigned: - [Set up your account](https://docs.digicert.com/en/software-trust-manager/account.html): Learn how to set up and manage your DigiCert® Software Trust Manager account. - [Dashboard](https://docs.digicert.com/en/software-trust-manager/account/dashboard.html): The Dashboard page showcases an overview of various Software Trust concepts and resources, which are based on configurable filter settings. - [Users](https://docs.digicert.com/en/software-trust-manager/account/users.html): Use DigiCert® Account Manager to add and manage users in your DigiCert® ONE account. Users have permission-based access, allowing you to control what users can see and do inside DigiCert ONE. - [Account settings](https://docs.digicert.com/en/software-trust-manager/account/account-settings.html): Use Account settings to manage the code signing process, allowing you to tailor your experience to meet your specific needs. Fine-tune your keypair management, configure release settings, personalize your CSV report… - [Teams](https://docs.digicert.com/en/software-trust-manager/account/teams.html): To use this feature, you must enable teams on your account. To learn more, see Enable Teams. - [Notifications](https://docs.digicert.com/en/software-trust-manager/account/notifications.html): Notifications let you personalize email preferences for monitoring your production signature units and production HSM units consumption. - [User groups](https://docs.digicert.com/en/software-trust-manager/account/user-groups.html): Select users to form a group, and then map relevant resources to them. - [Projects](https://docs.digicert.com/en/software-trust-manager/account/projects.html): Projects provide teams with a structured and collaborative environment to manage threat detection scans and releases for a specific software development project. - [Trust anchor certificates](https://docs.digicert.com/en/software-trust-manager/account/trust-anchor-certificates.html): Use trust anchor certificates to manage your root and intermediate (ICA) certificates. - [Connectors](https://docs.digicert.com/en/software-trust-manager/connectors.html): The DigiCert® Software Trust Manager Integrations feature lets you connect your Trust Lifecycle account with our partners ReversingLabs and Fossa for Threat Detection. - [Enable connectors](https://docs.digicert.com/en/software-trust-manager/connectors/enable-connectors.html): If DigiCert® hosts your account, then contact your account manager to enable these connectors. - [CertCentral integration](https://docs.digicert.com/en/software-trust-manager/connectors/certcentral-integration.html): Strict CA/B forum guidelines govern publicly trusted code signing certificates, and a third-party trusted certificate authority like DigiCert® validates them. - [ReversingLabs integration](https://docs.digicert.com/en/software-trust-manager/connectors/reversinglabs-integration.html): Threat detection integrates with ReversingLabs to scan your software for malware, vulnerabilities, secrets, and more. - [FOSSA integration](https://docs.digicert.com/en/software-trust-manager/connectors/fossa-integration.html): Threat detection integrates with FOSSA to manage your open source components. FOSSA plugs into your development workflow to help your team automatically track, manage, and remediate issues with the open source you use. - [Certificates](https://docs.digicert.com/en/software-trust-manager/certificates.html): The DigiCert® Software Trust Manager certificates feature allows you to view all code signing certificates in your account. - [Types of certificates](https://docs.digicert.com/en/software-trust-manager/certificates/certificates-types.html): You can generate public or private code signing certificates in DigiCert® Software Trust Manager. - [Certificate templates](https://docs.digicert.com/en/software-trust-manager/certificates/certificate-templates.html): Certificate templates simplify certificate generation by preconfiguring allowable fields and values. - [Certificate profiles](https://docs.digicert.com/en/software-trust-manager/certificates/certificate-profiles.html): Certificate profiles are mandatory and simplify certificate generation by preconfiguring values for all certificate options in DigiCert® Software Trust Manager. - [CertCentral orders](https://docs.digicert.com/en/software-trust-manager/certificates/certcentral-orders.html): CertCentral orders allow you to view all publicly trusted code signing certificates issued in your CertCentral account. - [Manage certificates](https://docs.digicert.com/en/software-trust-manager/certificates/manage-certificates.html) - [Certificate troubleshooting](https://docs.digicert.com/en/software-trust-manager/certificates/certificate-troubleshooting.html): If your certificate failed to create, then you'll see the following error message: - [Keypairs](https://docs.digicert.com/en/software-trust-manager/keypairs.html): A keypair consists of a public key and its corresponding private key. The public key is used to encrypt data, and only the matching private key can decrypt it, establishing a secure, encrypted connection. - [Standard keypairs](https://docs.digicert.com/en/software-trust-manager/keypairs/keypairs.html) - [Key rotations](https://docs.digicert.com/en/software-trust-manager/keypairs/key-rotations.html): Key rotations let you cycle through 2–10 keys and certificates. This feature enhances security by automatically replacing keys after a set period of time, and after each signing. As a result, no two consecutive signings… - [Keypair profiles](https://docs.digicert.com/en/software-trust-manager/keypairs/keypair-profiles.html): Keypair profiles simplify keypair generation by preconfiguring values for all keypair options. - [GPG keypairs](https://docs.digicert.com/en/software-trust-manager/keypairs/gpg-keypairs.html): GPG keys are different from other private keys because each GPG key includes a master key and corresponding subkeys. While there are no technical differences between a master key and subkey, the responsibilities of… - [Releases and release windows](https://docs.digicert.com/en/software-trust-manager/releases.html): The DigiCert® Software Trust Manager release feature offers key security by confining their use to specific approved timeframes, sometimes referred to as "release windows." Within these defined timeframes, you have… - [Create a release (release window)](https://docs.digicert.com/en/software-trust-manager/releases/create-release.html): To perform this action, you must have a user role that contains the Request release window permission. - [Update a release (release window)](https://docs.digicert.com/en/software-trust-manager/releases/update-release.html): In the Software Trust menu, go to Releases > Releases. - [Approval procedure for offline releases](https://docs.digicert.com/en/software-trust-manager/releases/approval-procedure-for-offline-releases.html): Review the following approval procedure when teams is enabled on your account and a user requests to create an offline release. - [Compare releases and baselines](https://docs.digicert.com/en/software-trust-manager/releases/release-comparison-and-baselines.html): By comparing your latest release to your baseline release you can confirm that multiple releases have matching code and ensure that no bad actors or software have injected malicious code into your releases. - [Threat detection](https://docs.digicert.com/en/software-trust-manager/threat-detection.html): Threat detection enhances the security of your software supply chain by scanning your software for vulnerabilities using the Signing Manager Controller (SMCTL) interface. - [Software Binary Analysis](https://docs.digicert.com/en/software-trust-manager/threat-detection/static-binary-analysis.html): Depending on your threat detection service tiers, some features may not be available. To learn what features are included in your service tier, see Static binary analysis (SBA) features. - [Software Composition Analysis](https://docs.digicert.com/en/software-trust-manager/threat-detection/software-composition-analysis.html): FOSSA integration with DigiCert® Software Trust Manager scans open-source components to help your team to track, manage, and remediate issues. - [Best practices for Common Vulnerabilities and Exposures (CVE)](https://docs.digicert.com/en/software-trust-manager/threat-detection/best-practices-for-common-vulnerabilities-and-exposures.html) - [Client tools](https://docs.digicert.com/en/software-trust-manager/client-tools.html): The DigiCert ONE Clients app provides a centralized location to manage all of your DigiCert ONE client tools. It automates installation, configuration and, updates to reduce manual effort, minimize errors, and ensures… - [Unsure which client tools you need?](https://docs.digicert.com/en/software-trust-manager/client-tools/unsure-which-client-tools-you-need.html): The recommended way to sign is using SMCTL, which is DigiCert® Software Trust Manager's command line interface (CLI) and supports multiple ways to sign software using keys stored in Software Trust Manager… - [Install your client tools with DigiCert ONE Clients (recommended)](https://docs.digicert.com/en/software-trust-manager/client-tools/digicert-one-clients.html): Use the DigiCert ONE Clients app to download and manage DigiCert® Software Trust Manager client tools. - [Client tool compatibility](https://docs.digicert.com/en/software-trust-manager/client-tools/client-tool-compatibility.html): The following operating systems are compatible with DigiCert® Software Trust Manager client tools: - [Cryptographic libraries and frameworks](https://docs.digicert.com/en/software-trust-manager/client-tools/cryptographic-libraries-and-frameworks.html): When your private key is stored in DigiCert® Software Trust Manager, a cryptographic library or framework generates a hash of the file you want to sign. The hash is sent to Software Trust Manager, where your private key… - [Signing tools](https://docs.digicert.com/en/software-trust-manager/client-tools/signing-tools.html): DigiCert® Software Trust Manager offers simplified signing solutions in the form of Signing Manager Controller (SMCTL) a command line interface (CLI) and DigiCert® Click-to-sign a graphic user interface (GUI). DigiCert… - [Tool packages](https://docs.digicert.com/en/software-trust-manager/client-tools/tool-packages.html): DigiCert® Software Trust Manager tool packages bundles all the client tools you may require for signing on your operating system. - [Command line interface](https://docs.digicert.com/en/software-trust-manager/client-tools/command-line-interface.html): DigiCert® Signing Manager Controller (SMCTL) is a Command Line Interface (CLI) that facilitates manual and automated private key management, certificate management, and signing with or without the need for human… - [Customize tool settings](https://docs.digicert.com/en/software-trust-manager/client-tools/customize-tool-settings.html): This documentation describes the environment variables used to configureDigiCert® Software Trust Manager client tools . These variables control how tools authenticate, connect to services, handle Transport Layer… - [Signing code with DigiCert and third-party tools](https://docs.digicert.com/en/software-trust-manager/code-signing.html): Use third-party tools to sign your software while keeping your private key securely managed by Software Trust Manager. You can streamline the process with DigiCert®'s client tools or sign directly using a supported… - [Sign with DigiCert signing tools](https://docs.digicert.com/en/software-trust-manager/code-signing/sign-with-digicert-signing-tools.html): DigiCert® Software Trust Manager provides two simplified signing solutions: - [Sign with third-party signing tools](https://docs.digicert.com/en/software-trust-manager/code-signing/sign-with-third-party-signing-tools.html): Sign directly with third-party signing tools while your private key remains securely stored in Software Trust Manager. - [CI/CD integrations and deployment pipelines](https://docs.digicert.com/en/software-trust-manager/ci-cd-integrations-and-deployment-pipelines.html): Integrate DigiCert® Software Trust Manager into continuous integration and continuous deployment (CI/CD) pipelines. CI/CD integrations automate and streamline the software development and deployment process. CI/CD… - [Plugins](https://docs.digicert.com/en/software-trust-manager/ci-cd-integrations-and-deployment-pipelines/plugins.html): DigiCert® Software Trust Manager plugins are pre-built software components or extensions that integrate with a specific CI/CD tool or platform. Plugins can extend the capabilities of the CI/CD tool and provide access to… - [Script integrations](https://docs.digicert.com/en/software-trust-manager/ci-cd-integrations-and-deployment-pipelines/scripts.html): DigiCert® Software Trust Manager script integrations provide instructions on how to write custom scripts to define the steps and actions of the CI/CD process. Script integrations offer greater flexibility but require… - [Logs](https://docs.digicert.com/en/software-trust-manager/logs.html): Revieing logs allows you to expedite remediation by reviewing the history of all actions taken within your account. - [Audit logs](https://docs.digicert.com/en/software-trust-manager/logs/audit-logs.html): Audit logs contain the following information: - [Signature logs](https://docs.digicert.com/en/software-trust-manager/logs/signature-logs.html): Signature logs provides a list of signature events, including: - [Manage logs](https://docs.digicert.com/en/software-trust-manager/logs/manage-logs.html) - [Troubleshoot](https://docs.digicert.com/en/software-trust-manager/troubleshoot.html): If you are unable to locate the necessary troubleshooting information, you can submit feedback via the Provide feedback link at the bottom of each page in this website. - [Identify general errors](https://docs.digicert.com/en/software-trust-manager/troubleshoot/troubleshoot-general-errors.html): General troubleshooting is used when basic actions failed, such as: - [Identify signing errors](https://docs.digicert.com/en/software-trust-manager/troubleshoot/troubleshoot-signing-errors.html): If you encounter errors while working with DigiCert® Software Trust Manager client tools, follow the methods below. - [Healthcheck errors and solutions](https://docs.digicert.com/en/software-trust-manager/troubleshoot/healthcheck-errors-and-solutions.html): If the healthcheck command fails, review the troubleshooting steps. - [Apksigner errors and solutions](https://docs.digicert.com/en/software-trust-manager/troubleshoot/apksigner-errors-and-solutions.html): The following errors may occur while signing with Apksigner: - [Binary signing errors and solutions for GitLab CI/CD](https://docs.digicert.com/en/software-trust-manager/troubleshoot/binary-signing-errors-and-solutions-for-gitlab-ci-cd.html): The following errors may occur during Binary signing for GitLab CI/CD. - [Common errors and solutions](https://docs.digicert.com/en/software-trust-manager/troubleshoot/errors-and-solutions.html): Failed to sign errors generally have a status_code=403. Below are some errors that commonly occur when signing fails. - [Apple signing errors and solutions](https://docs.digicert.com/en/software-trust-manager/troubleshoot/apple-signing-errors-and-solutions.html): The following errors may occur during Apple signing. - [Podman errors and solutions](https://docs.digicert.com/en/software-trust-manager/troubleshoot/container-signing-errors-and-solutions.html): The following errors may occur during container signing. - [Docker errors and solutions](https://docs.digicert.com/en/software-trust-manager/troubleshoot/docker-errors-and-solutions.html): The following errors may occur when using Docker. - [GPG errors and solutions](https://docs.digicert.com/en/software-trust-manager/troubleshoot/gpg-signing-errors-and-solutions.html): The following errors may occur during GPG signing. - [Jarsigner errors and solutions](https://docs.digicert.com/en/software-trust-manager/troubleshoot/jarsigner-errors-and-solutions.html): The following errors may occur while signing with Jarsigner. - [JCE errors and solutions](https://docs.digicert.com/en/software-trust-manager/troubleshoot/jce-errors-and-solutions.html): The following errors may occur while signing with the JCE library. - [Jenkins errors and solutions](https://docs.digicert.com/en/software-trust-manager/troubleshoot/jenkins-errors-and-solutions.html): The following errors may occur while using Jenkins for CI/CD integration. - [Mage errors and solutions](https://docs.digicert.com/en/software-trust-manager/troubleshoot/mage-errors-and-solutions.html): When you sign a manifest file using mage, two signature units are consumed. This is because two hash signatures are created for different types of content within the manifest: - [Nuget errors and solutions](https://docs.digicert.com/en/software-trust-manager/troubleshoot/nuget-errors-and-solutions.html): If you encounter an error not listed here, refer to NuGet errors and warnings. - [SBOM signing errors and solutions](https://docs.digicert.com/en/software-trust-manager/troubleshoot/sbom-signing-errors-and-solutions.html): The following errors may occur during SBOM signing. - [SignTool errors and solutions](https://docs.digicert.com/en/software-trust-manager/troubleshoot/signtool-errors-and-solutions.html): The following errors may occur while signing with Signtool. - [Threat detection errors and solutions](https://docs.digicert.com/en/software-trust-manager/troubleshoot/threat-detection-errors-and-solutions.html): The following errors may occur for threat detection commands. - [msix signing errors and solutions with EV code signing certificates](https://docs.digicert.com/en/software-trust-manager/troubleshoot/msix-signing-errors-and-solutions-with-ev-code-signing-certificates.html): When signing .msix packages using an Extended Validation (EV) code signing certificate, you may encounter an error caused by certificate subject fields that do not match the package manifest. - [Release notes](https://docs.digicert.com/en/software-trust-manager/software-trust-manager-release-notes.html): For maintenance schedules and older releases, visit the What's new section of this website. ## DigiCert KeyLocker - [DigiCert KeyLocker](https://docs.digicert.com/en/digicert-keylocker.html): DigiCert® KeyLocker is a cloud‐based solution that generates and provides FIPS 140-2 level 3 compliant private key storage for your code signing certificates. KeyLocker is an automated alternative to manually generating… - [Get started](https://docs.digicert.com/en/digicert-keylocker/get-started.html): The following guides assist you to get started with DigiCert® KeyLocker based on the user role that you were assigned. - [Lead guide](https://docs.digicert.com/en/digicert-keylocker/get-started/lead-guide.html): The KeyLocker Lead is the account administrator responsible for managing assets, users, and is able to sign with the key stored DigiCert® KeyLocker. - [Signer guide](https://docs.digicert.com/en/digicert-keylocker/get-started/signer-guide.html): The DigiCert® KeyLocker Signer is an account user responsible for signing with a key stored in KeyLocker. - [Overview](https://docs.digicert.com/en/digicert-keylocker/overview.html): Learn more about DigiCert® KeyLocker. - [Benefits](https://docs.digicert.com/en/digicert-keylocker/overview/benefits.html): DigiCert® KeyLocker removes the need for you to manually generate your private key, generate your CSR, and compliantly store the private key associated with your code signing certificate. DigiCert® KeyLocker automates… - [Licensing](https://docs.digicert.com/en/digicert-keylocker/overview/licensing.html): DigiCert® KeyLocker certificates have a standard DigiCert® KeyLocker service fee regardless of the validity period of the certificate. This fee entitles you to a limit of one signer and 1,000 signatures per certificate… - [Buy and request a DigiCert® KeyLocker certificate](https://docs.digicert.com/en/digicert-keylocker/overview/access.html): DigiCert® KeyLocker can only be used for code signing certificates ordered in CertCentral. When you request a code signing certificate in CertCentral, your KeyLocker account is instantly created to generate and store… - [Compatible operating systems](https://docs.digicert.com/en/digicert-keylocker/overview/compatible-operating-systems.html): Review the operating systems compatible with DigiCert® KeyLocker: - [Compatible signing tools and file types](https://docs.digicert.com/en/digicert-keylocker/overview/compatible-signing-tools.html): DigiCert® KeyLocker offers simplified signing solutions via Signing Manager Controller (SMCTL) a command-line interface (CLI) and DigiCert® Click-to-sign a graphic user interface (GUI). - [Users](https://docs.digicert.com/en/digicert-keylocker/overview/users.html): Use DigiCert® Account Manager to add and manage users in your DigiCert® ONE account. Users have permission-based access, allowing you to control what users can see and do inside DigiCert ONE. - [Requirements](https://docs.digicert.com/en/digicert-keylocker/overview/requirements.html): DigiCert® requires two-factor authentication (2FA) for all DigiCert® KeyLocker users. This requirement applies to signing activities and to DigiCert® ONE-based actions, such as keypair and certificate generation. - [Secure credentials](https://docs.digicert.com/en/digicert-keylocker/overview/secure-credentials.html): To effectively use DigiCert® KeyLocker client tools, you must configure your environment variables correctly. - [Sign in to the platform](https://docs.digicert.com/en/digicert-keylocker/overview/sign-in-url.html): Use this documentation to find the correct sign in URL for your account. The URL you use depends on: - [Certificates](https://docs.digicert.com/en/digicert-keylocker/certificates.html): The DigiCert® KeyLocker certificates feature allows you to view and manage all publicly trusted code signing certificates that rely on KeyLocker key storage. - [View certificates](https://docs.digicert.com/en/digicert-keylocker/certificates/view-certificates.html): To perform this action, you must have a user role that contains the View certificate permission. - [Identify designated signer for the certificate](https://docs.digicert.com/en/digicert-keylocker/certificates/locate-designated-signer-for-certificate.html): To identify the designated signer for your KeyLocker certificate: - [Assign signer to a certificate](https://docs.digicert.com/en/digicert-keylocker/certificates/add-signer.html): To add a designated signer for your KeyLocker certificate: - [Update signer for a certificate](https://docs.digicert.com/en/digicert-keylocker/certificates/update-signer.html): To update the designated signer for your KeyLocker certificate: - [Download certificate](https://docs.digicert.com/en/digicert-keylocker/certificates/download-certificate.html): To perform this action, you must have a user role that contains the View certificate permission. - [Locate certificate fingerprint/thumbprint](https://docs.digicert.com/en/digicert-keylocker/certificates/locate-certificate-fingerprint-thumbprint.html): To perform this action, you must have a user role that contains the View certificate permission. - [Revoke certificate](https://docs.digicert.com/en/digicert-keylocker/certificates/revoke-certificate.html): To perform this action, you must have a user role that contains the Revoke certificate permission. - [Sync certificate](https://docs.digicert.com/en/digicert-keylocker/certificates/sync-certificate.html): To perform this action, you must have a user role that contains the View certificate permission. - [Bulk actions](https://docs.digicert.com/en/digicert-keylocker/certificates/bulk-actions.html): Use Bulk actions to sync or revoke multiple certificates. - [Assign KeyLocker certificate signer](https://docs.digicert.com/en/digicert-keylocker/certificates/assign-keylocker-certificate-signer.html): As of March 19, 2024, only one signer can be designated per KeyLocker certificate. An account user with the KeyLocker lead role can update the designated signer at any time during the certificate lifecycle. - [Keypairs](https://docs.digicert.com/en/digicert-keylocker/keypairs.html): A keypair consists of a public key and its corresponding private key. The public key is used to encrypt data, and only the matching private key can decrypt it, establishing a secure, encrypted connection. - [Keypair generation](https://docs.digicert.com/en/digicert-keylocker/keypairs/keypair-generation.html): When you request a certificate in CertCentral, DigiCert® KeyLocker automatically generates a keypair with the following parameters on a FIPS 140-2 level 3 compliant hardware security module (HSM). - [View keypair](https://docs.digicert.com/en/digicert-keylocker/keypairs/view-keypair.html): To perform this action, you must have a user role that contains the View keypair permission. - [Locate keypair alias](https://docs.digicert.com/en/digicert-keylocker/keypairs/locate-keypair-alias.html): You can find the keypair alias via DigiCert® KeyLocker or Signing Manager Controller (SMCTL). - [KeyLocker signatures](https://docs.digicert.com/en/digicert-keylocker/keylocker-signatures.html): A DigiCert® KeyLocker subscription includes a package of 1,000 signatures assigned to a single Code Signing certificate using the KeyLocker provisioning method. Once assigned, signatures cannot be transferred or… - [Buy more KeyLocker signatures](https://docs.digicert.com/en/digicert-keylocker/keylocker-signatures/buy-more-keylocker-signatures.html): You can add KeyLocker signatures to a Code Signing certificate to replenish a low volume or to prepare for future needs. - [Client tools](https://docs.digicert.com/en/digicert-keylocker/client-tools.html): The DigiCert ONE Clients app provides a centralized location to manage all of your DigiCert ONE client tools. It automates installation, configuration and, updates to reduce manual effort, minimize errors, and ensures… - [Unsure which client tools you need?](https://docs.digicert.com/en/digicert-keylocker/client-tools/unsure-which-client-tools-you-need.html): The recommended way to sign is using SMCTL, which is DigiCert® KeyLocker's command line interface (CLI) and supports multiple ways to sign software using keys stored in KeyLocker. Alternatively, you can continue using… - [Install your client tools with DigiCert ONE Clients (recommended)](https://docs.digicert.com/en/digicert-keylocker/client-tools/digicert-one-clients.html): Use the DigiCert ONE Clients app to download and manage DigiCert® KeyLocker client tools. - [Client tool compatibility](https://docs.digicert.com/en/digicert-keylocker/client-tools/client-tool-compatibility.html): The following operating systems are compatible with DigiCert® KeyLocker client tools: - [Cryptographic libraries and frameworks](https://docs.digicert.com/en/digicert-keylocker/client-tools/cryptographic-libraries-and-frameworks.html): When your private key is stored in DigiCert® KeyLocker, a cryptographic library or framework generates a hash of the file you want to sign. The hash is sent to DigiCert® KeyLocker, where your private key signs it. The… - [Signing tools](https://docs.digicert.com/en/digicert-keylocker/client-tools/signing-tools.html): DigiCert® KeyLocker offers simplified signing solutions in the form of Signing Manager Controller (SMCTL) a command line interface (CLI) and DigiCert® Click-to-sign a graphic user interface (GUI). DigiCert signing tools… - [Tool packages](https://docs.digicert.com/en/digicert-keylocker/client-tools/tool-packages.html): DigiCert® KeyLocker tool packages bundles all the client tools you may require for signing on your operating system. - [Command line interface](https://docs.digicert.com/en/digicert-keylocker/client-tools/command-line-interface.html): DigiCert® Signing Manager Controller (SMCTL) is a Command Line Interface (CLI) that facilitates manual and automated private key management, certificate management, and signing with or without the need for human… - [Customize tool settings](https://docs.digicert.com/en/digicert-keylocker/client-tools/customize-tool-settings.html): This documentation describes the environment variables used to configureDigiCert® KeyLocker client tools. These variables control how tools authenticate, connect to services, handle Transport Layer Security (TLS), and… - [Signing code with DigiCert and third-party tools](https://docs.digicert.com/en/digicert-keylocker/code-signing.html): Use third-party tools to sign your software while keeping your private key securely managed by DigiCert® KeyLocker. You can streamline the process with DigiCert®'s client tools or sign directly using a supported… - [Sign with DigiCert signing tools](https://docs.digicert.com/en/digicert-keylocker/code-signing/sign-with-digicert-signing-tools.html): DigiCert® KeyLocker provides two simplified signing solutions: - [Sign with third-party signing tools](https://docs.digicert.com/en/digicert-keylocker/code-signing/sign-with-third-party-signing-tools.html): Sign directly with third-party signing tools while your private key remains securely stored in DigiCert® KeyLocker. - [CI/CD integrations and deployment pipelines](https://docs.digicert.com/en/digicert-keylocker/ci-cd-integrations-and-deployment-pipelines.html): Integrate DigiCert® KeyLocker into continuous integration and continuous deployment (CI/CD) pipelines. CI/CD integrations automate and streamline the software development and deployment process. CI/CD plugins and script… - [Plugins](https://docs.digicert.com/en/digicert-keylocker/ci-cd-integrations-and-deployment-pipelines/plugins.html): DigiCert® KeyLocker plugins are pre-built software components or extensions that integrate with a specific CI/CD tool or platform. Plugins can extend the capabilities of the CI/CD tool and provide access to more… - [Script integrations](https://docs.digicert.com/en/digicert-keylocker/ci-cd-integrations-and-deployment-pipelines/scripts.html): DigiCert® KeyLocker script integrations provide instructions on how to write custom scripts to define the steps and actions of the CI/CD process. Script integrations offer greater flexibility but require more technical… - [Signing Manager Controller (SMCTL) command manual](https://docs.digicert.com/en/digicert-keylocker/smctl-command-manual.html): Signing Manager CTL (SMCTL) is a Command Line Interface (CLI) that facilitates manual and automated private key management, certificate management, and signing with or without the need for human intervention. - [Healthcheck commands](https://docs.digicert.com/en/digicert-keylocker/smctl-command-manual/healthcheck.html): Use this command to check if your and signing tools were configured correctly in SMCTL. - [Certificates commands](https://docs.digicert.com/en/digicert-keylocker/smctl-command-manual/manage-certificates.html): This section covers commands that you use in SMCTL to manage certificates. - [Credential commands](https://docs.digicert.com/en/digicert-keylocker/smctl-command-manual/manage-credentials.html): This section covers commands that you use in SMCTL to manage credentials for the operating system credential store. These commands are: save and delete credentials. - [Standard keypair commands](https://docs.digicert.com/en/digicert-keylocker/smctl-command-manual/manage-keypairs.html): This section covers commands that you use in SMCTL to manage keypairs. These commands are: describe, generate, list, import, suspend, unsuspend, update, update access, manage keypair profiles, and generate certificate… - [Sign binary commands](https://docs.digicert.com/en/digicert-keylocker/smctl-command-manual/manage-signatures.html): Learn how to use SMCTL commands to manage signatures (sign, verify signature, remove signature), using flags to define the command parameters. - [User account commands](https://docs.digicert.com/en/digicert-keylocker/smctl-command-manual/manage-user-accounts.html): Use these commands to identify the accounts your username is associated with and switch your primary account. - [Windows store and KSP commands](https://docs.digicert.com/en/digicert-keylocker/smctl-command-manual/manage-commands-for-windows.html): This section covers commands that you use in SMCTL to manage commands for Windows. - [Troubleshoot](https://docs.digicert.com/en/digicert-keylocker/troubleshoot.html): Select one of the articles below to based on the type of error you have encountered and follow the instructions to resolve. - [Identify general errors](https://docs.digicert.com/en/digicert-keylocker/troubleshoot/troubleshoot-general-errors.html): General troubleshooting is used when basic actions failed, such as: - [Identify signing errors](https://docs.digicert.com/en/digicert-keylocker/troubleshoot/troubleshoot-signing-errors.html): If you encounter errors while working with DigiCert® KeyLocker client tools, follow the methods below. - [Healthcheck errors and solutions](https://docs.digicert.com/en/digicert-keylocker/troubleshoot/healthcheck-errors-and-solutions.html): If the healthcheck command fails, review the troubleshooting steps. - [Common errors and solutions](https://docs.digicert.com/en/digicert-keylocker/troubleshoot/errors-and-solutions.html): Failed to sign errors generally have a status_code=403. Below are some errors that commonly occur when signing fails. - [Docker errors and solutions](https://docs.digicert.com/en/digicert-keylocker/troubleshoot/docker-errors-and-solutions.html): The following errors may occur when using Docker. - [GPG errors and solutions](https://docs.digicert.com/en/digicert-keylocker/troubleshoot/gpg-signing-errors-and-solutions.html): The following errors may occur during GPG signing. - [Jarsigner errors and solutions](https://docs.digicert.com/en/digicert-keylocker/troubleshoot/jarsigner-errors-and-solutions.html): The following errors may occur while signing with Jarsigner. - [JCE errors and solutions](https://docs.digicert.com/en/digicert-keylocker/troubleshoot/jce-errors-and-solutions.html): The following errors may occur while signing with the JCE library. - [Mage errors and solutions](https://docs.digicert.com/en/digicert-keylocker/troubleshoot/mage-errors-and-solutions.html): When you sign a manifest file using mage, two signature units are consumed. This is because two hash signatures are created for different types of content within the manifest: - [Nuget errors and solutions](https://docs.digicert.com/en/digicert-keylocker/troubleshoot/nuget-errors-and-solutions.html): If you encounter an error not listed here, refer to NuGet errors and warnings. - [SignTool errors and solutions](https://docs.digicert.com/en/digicert-keylocker/troubleshoot/signtool-errors-and-solutions.html): The following errors may occur while signing with Signtool. - [Release notes](https://docs.digicert.com/en/digicert-keylocker/digicert-keylocker-release-notes.html): For maintenance schedules and older releases, visit the What's new section of this website. ## Device Trust Manager - [Device Trust Manager](https://docs.digicert.com/en/device-trust-manager.html): DigiCert® Device Trust Manager is a comprehensive security platform that delivers end-to-end protection for IoT devices. By handling the critical security infrastructure, Device Trust Manager enables OEMs to focus on… - [Get started](https://docs.digicert.com/en/device-trust-manager/get-started.html): You must have a DigiCert account to access DigiCert® Device Trust Manager. If you don’t currently have access to DigiCert account, contact your administrator to provide you with the credentials. - [Sign in](https://docs.digicert.com/en/device-trust-manager/get-started/sign-in.html): Sign in to DigiCert ONE. - [Overview](https://docs.digicert.com/en/device-trust-manager/get-started/overview.html): Get familiar with DigiCert® Device Trust Manager benefits, architecture, and plans. - [Quick start guides](https://docs.digicert.com/en/device-trust-manager/get-started/quick-start-guides.html): The following guides help you to get started with DigiCert® Device Trust Manager, based on the user role that you are assigned. For a detailed breakdown of permissions associated with each role in Device Trust Manager… - [Concepts](https://docs.digicert.com/en/device-trust-manager/get-started/concepts.html): DigiCert® Device Trust Manager uses several key concepts, each of which plays a critical role in managing and securing IoT devices. These concepts work together to provide granular control over device operations… - [Configure Device Trust Manager](https://docs.digicert.com/en/device-trust-manager/configure-device-trust-manager.html): Follow each section in this set up and configuration guide to start managing your IoT devices using DigiCert® Device Trust Manager. - [Part 1: Initial access and setup](https://docs.digicert.com/en/device-trust-manager/configure-device-trust-manager/initial-access-and-setup.html): Initial access and setup is your first step in establishing secure, managed access to DigiCert® Device Trust Manager. This section walks you through the foundational setup of your account, including your initial sign-in… - [Part 2: Configure Device Trust Manager](https://docs.digicert.com/en/device-trust-manager/configure-device-trust-manager/part-2--configure-device-trust-manager.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Part 3: Set up device management](https://docs.digicert.com/en/device-trust-manager/configure-device-trust-manager/part-3--set-up-device-management.html): To perform this action, you must have a user role that contains the Solution administrator or Device creator permission. - [Part 4: Connect a Linux device](https://docs.digicert.com/en/device-trust-manager/configure-device-trust-manager/part-4--connect-a-linux-device.html): To perform this action, you must have a user role that contains the Device administrator or Device creator permission. - [Part 5: Deploy a device update](https://docs.digicert.com/en/device-trust-manager/configure-device-trust-manager/deploy-a-device-update.html): To perform this action, you must have a user role that contains the Device administrator permission. - [Part 6: Create a cloud platform policy](https://docs.digicert.com/en/device-trust-manager/configure-device-trust-manager/create-a-cloud-platform-policy.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Division management](https://docs.digicert.com/en/device-trust-manager/division-management.html): A division in DigiCert® Device Trust Manager creates isolated environments within an account. It enables you to categorize users, resources, and policies according to defined criteria or organizational structure. - [Create a division](https://docs.digicert.com/en/device-trust-manager/division-management/create-a-division.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Assign users to a division](https://docs.digicert.com/en/device-trust-manager/division-management/assign-users-to-a-division.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Remove users from an assigned division](https://docs.digicert.com/en/device-trust-manager/division-management/remove-users-assigned-to-division.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Modify a division](https://docs.digicert.com/en/device-trust-manager/division-management/modify-a-division.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Disable and enable a division](https://docs.digicert.com/en/device-trust-manager/division-management/disable-enable-a-division.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Delete a division](https://docs.digicert.com/en/device-trust-manager/division-management/delete-a-division.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Authentication policy management](https://docs.digicert.com/en/device-trust-manager/authentication-policy-management.html): An authentication policy in DigiCert® Device Trust Manager defines the credentials and methods that devices can use when requesting certificates through different protocols, such as SCEP, EST, and REST. Authentication… - [Create an authentication policy](https://docs.digicert.com/en/device-trust-manager/authentication-policy-management/create-an-authentication-policy.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [View authentication policy details](https://docs.digicert.com/en/device-trust-manager/authentication-policy-management/view-authentication-policy-details.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Add credentials to an authentication policy](https://docs.digicert.com/en/device-trust-manager/authentication-policy-management/add-credentials-to-an-authentication-policy.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Disable and enable an authentication policy](https://docs.digicert.com/en/device-trust-manager/authentication-policy-management/disable-enable-an-authentication-policy.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Delete an authentication policy](https://docs.digicert.com/en/device-trust-manager/authentication-policy-management/delete-an-authentication-policy.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Certificate management](https://docs.digicert.com/en/device-trust-manager/certificate-management.html): Certificate management defines how certificates, including bootstrap certificates and operational certificates, are issued, renewed, and revoked for devices. It outlines the protocols for certificate management… - [Certificates](https://docs.digicert.com/en/device-trust-manager/certificate-management/certificates.html): In DigiCert® Device Trust Manager, certificates are used to establish device identities, authenticate devices, and secure communications. Certificates are issued to devices throughout their lifecycle for two primary… - [Certificate settings](https://docs.digicert.com/en/device-trust-manager/certificate-management/certificate-settings.html) - [Issuing CAs](https://docs.digicert.com/en/device-trust-manager/certificate-management/issuing-cas.html): An Issuing CA in DigiCert® Device Trust Manager is a Certificate Authority (CA) assigned to your account that is used for signing and issuing x.509 certificates to devices. These signed certificates can be either… - [Trust bundles](https://docs.digicert.com/en/device-trust-manager/certificate-management/trust-bundles.html): A trust bundle is a collection of digital certificates used to verify the authenticity and integrity of various entities in digital communication. It includes root Certificate Authorities (CAs), intermediate CAs, code… - [Registered values](https://docs.digicert.com/en/device-trust-manager/certificate-management/registered-values.html): Registered values are a sophisticated feature designed to enhance the security and integrity of certificate issuance processes. - [OCSP groups](https://docs.digicert.com/en/device-trust-manager/certificate-management/ocsp-groups.html): OCSP groups enable you to organize and manage certificates for Online Certificate Status Protocol (OCSP) validation. You can create certificate groups, assign or remove certificates, and update or delete certificate… - [Alerts](https://docs.digicert.com/en/device-trust-manager/certificate-management/alerts.html): Alerts in DigiCert® Device Trust Manager provides automated email and webhook notifications triggered by certificate management thresholds and activity patterns. You can configure alerts based on certificate issuance… - [Cloud platform policy management](https://docs.digicert.com/en/device-trust-manager/cloud-platform-policy-management.html): The cloud platform policy in DigiCert® Device Trust Manager defines the configuration required to automatically onboard and offboard devices to and from the OEM's preferred IoT platform, such as Azure Event Grid, AWS… - [Create a cloud platform policy](https://docs.digicert.com/en/device-trust-manager/cloud-platform-policy-management/create-a-cloud-platform-policy.html): Onboard your device with Azure Event Grid MQTT Broker. - [Modify a cloud platform policy](https://docs.digicert.com/en/device-trust-manager/cloud-platform-policy-management/modify-a-cloud-platform-policy.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [View cloud platform policy details](https://docs.digicert.com/en/device-trust-manager/cloud-platform-policy-management/view-cloud-platform-policies.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Disable and enable a cloud platform policy](https://docs.digicert.com/en/device-trust-manager/cloud-platform-policy-management/disable-enable-a-cloud-platform-policy.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Delete a cloud platform policy](https://docs.digicert.com/en/device-trust-manager/cloud-platform-policy-management/delete-a-cloud-platform-policy.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Device management](https://docs.digicert.com/en/device-trust-manager/device-management.html): Learn how to manage your devices in DigiCert® Device Trust Manager. - [Device groups](https://docs.digicert.com/en/device-trust-manager/device-management/device-groups.html): A device group is an organizational unit in DigiCert® Device Trust Manager that streamlines device management by grouping devices for policy application, updates, and configurations. - [Devices](https://docs.digicert.com/en/device-trust-manager/device-management/devices.html): A device, also called an IoT device or simply an asset, is a connected physical unit or product equipped with sensors, chips, and connectivity features such as BLE (Bluetooth Low Energy) and/or Wi-Fi. These are… - [Update management](https://docs.digicert.com/en/device-trust-manager/update-management.html): Learn how to effectively plan, deploy, and monitor software updates across your device groups in DigiCert® Device Trust Manager. - [Artifact management](https://docs.digicert.com/en/device-trust-manager/update-management/artifact-management.html): An artifact is a package that contains everything required to deploy and update to a device and can include software, firmware, metadata, and handling scripts. These scripts ensure that updates are deployed reliably… - [Release management](https://docs.digicert.com/en/device-trust-manager/update-management/release-management.html): A release is a software update package in DigiCert® Device Trust Manager that consists of one or more artifacts. Acting as a container for these artifacts, a release enables controlled and efficient updates to be… - [Deployment management](https://docs.digicert.com/en/device-trust-manager/update-management/deployment-management.html): A deployment delivers releases (software updates) to device groups. A deployment represents the server-side model that manages device updates. Once a deployment is created, DigiCert® Device Trust Manager rolls out the… - [Dashboard](https://docs.digicert.com/en/device-trust-manager/dashboard.html): The Dashboard provides a visual overview of your DigiCert® Device Trust Manager account and displays information for the following asset types: - [Reports and audit logs](https://docs.digicert.com/en/device-trust-manager/reports-and-audit-logs.html): The Reports and Audit logs function in DigiCert® Device Trust Manager lists detailed audit log events for your account: - [Jobs](https://docs.digicert.com/en/device-trust-manager/jobs.html): In DigiCert® Device Trust Manager, Jobs are long-running operations that perform batch tasks, such as registering multiple devices or processing deployments. Jobs are tracked and managed using various statuses that… - [Register multiple devices](https://docs.digicert.com/en/device-trust-manager/jobs/register-multiple-devices--jobs-.html): To perform this action, you must have a user role that contains the Solution administrator, Device creator, or Device administrator permission. - [Request batch certificates for managed devices](https://docs.digicert.com/en/device-trust-manager/jobs/request-batch-certificates-for-managed-devices--jobs-.html): To perform this action, you must have a user role that contains the Device administrator permission. - [Request a batch certificate for unmanaged devices](https://docs.digicert.com/en/device-trust-manager/jobs/request-a-batch-certificate-for-unmanaged-devices--jobs-.html): To perform this action, you must have a user role that contains the Device administrator permission. - [Import certificates](https://docs.digicert.com/en/device-trust-manager/jobs/import-certificates--jobs-.html): Use this workflow to import existing certificates into a certificate management policy. - [Integrations](https://docs.digicert.com/en/device-trust-manager/integrations.html) - [CA Connectors](https://docs.digicert.com/en/device-trust-manager/integrations/ca-connectors.html): CA connectors allow you to issue certificates from external CA services while still using DigiCert® Device Trust Manager as your central platform for certificate requests and management. - [DigiCert gateway](https://docs.digicert.com/en/device-trust-manager/integrations/digicert-gateway.html): DigiCert gateway is a lightweight, on-premises proxy service that enables secure and controlled certificate enrollment for devices operating behind firewalls or in isolated networks. - [Blueprints](https://docs.digicert.com/en/device-trust-manager/blueprints.html): Blueprints are ready-to-use, preconfigured workflows that allow you to use Device Trust Manager without manual setup. Blueprints are especially useful for testing scenarios, since they let you quickly validate Device… - [Issue device certificates](https://docs.digicert.com/en/device-trust-manager/blueprints/issue-device-certificates.html): Use blueprints to issue device certificates through a preconfigured workflow. - [Issue device certificates using the EST protocol](https://docs.digicert.com/en/device-trust-manager/blueprints/issue-device-certificates-using-the-est-protocol.html): Use blueprints to issue device certificates using the EST protocol. - [Tutorials](https://docs.digicert.com/en/device-trust-manager/tutorials.html): Learn to make the most of DigiCert® Device Trust Manager with these detailed tutorials. - [Build and package a software update](https://docs.digicert.com/en/device-trust-manager/tutorials/build-and-package-a-software-update.html): In this tutorial, we’ll walk through building a simple “Hello World” application in C and packaging it as a Debian .deb package. This serves as an introduction to creating software updates that you can later deploy to… - [Configure and use EST](https://docs.digicert.com/en/device-trust-manager/tutorials/configure-and-use-est.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Configure and use REST](https://docs.digicert.com/en/device-trust-manager/tutorials/configure-and-use-rest.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Configure and use SCEP](https://docs.digicert.com/en/device-trust-manager/tutorials/configure-and-use-scep.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Generate and manage TPM-protected keys in Windows using PowerShell](https://docs.digicert.com/en/device-trust-manager/tutorials/generate-and-manage-tpm-protected-keys-in-windows-using-powershell.html): Storing private keys in a Trusted Platform Module (TPM) is a secure and reliable way to protect cryptographic operations on a Windows 11 device. - [Integrate manufacturing systems](https://docs.digicert.com/en/device-trust-manager/tutorials/integrate-manufacturing-systems.html): You can manage certificates and devices directly through Device Trust Manager. For automated workflows, Device Trust Manager also provides APIs that let you integrate with your manufacturing systems. This enables you to… - [Integrate TrustEdge into devices](https://docs.digicert.com/en/device-trust-manager/tutorials/integrate-trustedge-into-devices.html): This tutorial explains how to use TrustEdge to secure IoT device communications over SSL/TLS with MQTT. - [Integrate with Microsoft Azure IoT Hub](https://docs.digicert.com/en/device-trust-manager/tutorials/integrate-with-microsoft-azure-iot-hub.html): Microsoft Azure IoT Hub is a popular messaging service for connecting devices to cloud-based IoT solutions. Devices can send or receive messages from IoT Hub using the MQTT 3.1.1 protocol. - [Issue C2PA claim signing certificates](https://docs.digicert.com/en/device-trust-manager/tutorials/issue-c2pa-claim-signing-certificates.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Integrate with certificate issuance APIs](https://docs.digicert.com/en/device-trust-manager/tutorials/integrate-with-certificate-issuance-apis.html): DigiCert® ONE Device Trust Manager offers two main categories of APIs: - [Integrate with Management REST APIs](https://docs.digicert.com/en/device-trust-manager/tutorials/integrate-with-management-rest-apis.html): DigiCert® ONE Device Trust Manager APIs fall into two categories: - [Issue CSA Matter certificates](https://docs.digicert.com/en/device-trust-manager/tutorials/issue-csa-matter-certificates.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Issue Intermediate CA certificates](https://docs.digicert.com/en/device-trust-manager/tutorials/issue-intermediate-ca-certificates.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Just-in-time registration and provisioning](https://docs.digicert.com/en/device-trust-manager/tutorials/just-in-time-registration-and-provisioning.html): To perform this action, you must have a user role that contains the Solution administrator permission. - [Register multiple devices using a batch job](https://docs.digicert.com/en/device-trust-manager/tutorials/register-multiple-devices-using-a-batch-job.html): Use the DigiCert® Device Trust Manager REST API to register multiple devices in a single batch job. - [Troubleshoot](https://docs.digicert.com/en/device-trust-manager/troubleshoot.html): When encountering issues in DigiCert® Device Trust Manager, the built-in audit and device logging services are essential tools for diagnosing and resolving problems. - [Compliance](https://docs.digicert.com/en/device-trust-manager/compliance.html): Get familiar with how DigiCert® Device Trust Manager helps OEMs comply with the growing list of IoT cybersecurity regulations worldwide. - [References](https://docs.digicert.com/en/device-trust-manager/references.html) - [CSV format for batch certificate enrollment](https://docs.digicert.com/en/device-trust-manager/references/csv-format-for-batch-certificate-enrollment.html): Batch certificate enrollment in DigiCert® Device Trust Manager enables you to submit multiple certificate requests in a single job using a CSV file. This reference details the required CSV structure to ensure successful… - [CSV format for registering multiple devices](https://docs.digicert.com/en/device-trust-manager/references/csv-format-for-registering-multiple-devices.html): Batch device registration in DigiCert® Device Trust Manager allows you to register multiple devices and issue bootstrap certificates in a single job using a CSV file. This reference details the required CSV structure to… - [Subject directory attributes (SDA)](https://docs.digicert.com/en/device-trust-manager/references/subject-directory-attributes--sda-.html): DigiCert® Device Trust Manager supports the subject directory attributes (SDA) certificate extension. - [Supported PKI Key Types and Signature Algorithms](https://docs.digicert.com/en/device-trust-manager/references/supported-pki-key-types-and-signature-algorithms.html): DigiCert® Device Trust Manager supports various cryptographic key types and signature algorithms for certificate issuance. This article details the supported key types and their corresponding signature algorithms. - [Swagger REST API](https://docs.digicert.com/en/device-trust-manager/references/swagger-rest-api.html): The Swagger REST API documentation is integrated into Device Trust Manager, making it easier to view, understand, and test available APIs in one place. The DigiCert® Device Trust Manager REST API improves overall… - [Release notes](https://docs.digicert.com/en/device-trust-manager/device-trust-manager-release-notes.html): For maintenance schedules and older releases, visit the What's new section of this website. ## IoT Trust Manager - [IoT Trust Manager](https://docs.digicert.com/en/iot-trust-manager.html): We’re transitioning IoT Trust Manager to an enhanced Device Trust Manager! - [Get started](https://docs.digicert.com/en/iot-trust-manager/get-started.html): DigiCert® IoT Trust Manager uses modern PKI to meet the requirements of your IoT device deployments. In DigiCert® IoT Trust Manager, you manage certificates for your devices, device records, certificate profiles… - [Users, API tokens, and service users](https://docs.digicert.com/en/iot-trust-manager/get-started/users--api-tokens--and-service-users.html): Once a system admin sets up your initial admin account, you are ready to get started. A common area to get started is in Account Manager is where you add and manage users for DigiCert® IoT Trust Manager. It is also… - [Create divisions](https://docs.digicert.com/en/iot-trust-manager/get-started/create-divisions.html): When you open DigiCert® IoT Trust Manager for the first time, we use your account name to create a default division. You only need one division for DigiCert® IoT Trust Manager. However, adding more divisions can be… - [Assign users to divisions](https://docs.digicert.com/en/iot-trust-manager/get-started/assign-users-to-divisions.html): Divisions allow you to control further what users can see and do within DigiCert® IoT Trust Manager. When you add a user to a division, they can only see the items listed below based on the division you assigned them to: - [Request your first certificate for an IoT device](https://docs.digicert.com/en/iot-trust-manager/get-started/request-your-first-certificate-for-an-iot-device.html): IoT device deployments vary significantly between organizations, manufacturers, assembly lines, and devices. Because of these variations, DigiCert® IoT Trust Manager allows you to configure your IoT device certificate… - [Configure SCEP enrollment](https://docs.digicert.com/en/iot-trust-manager/get-started/configure-scep-enrollment.html): The Simple Certificate Enrollment Protocol (SCEP) facilitates automated certificate issuance and management for IoT devices. This guide covers the necessary steps to configure SCEP in DigiCert® IoT Trust Manager. - [The evolution of IoT Trust Manager](https://docs.digicert.com/en/iot-trust-manager/get-started/the-evolution-of-iot-trust-manager.html): Since DigiCert® acquired Mocana in 2022, we have been investing in our IoT solutions to ensure we help connected product manufacturers build secure devices and ensure compliance with industry regulations. These include: - [Divisions](https://docs.digicert.com/en/iot-trust-manager/divisions.html): Divisions in DigiCert® IoT Trust Manager offer enhanced user visibility and activity control. By assigning users to a specific division, they can only see and interact with items within that division. - [Create a division](https://docs.digicert.com/en/iot-trust-manager/divisions/create-a-division.html): The first time you open DigiCert® IoT Trust Manager, we use your account name to create a default division for you. DigiCert® IoT Trust Manager only requires one division. However, adding divisions may be helpful to… - [Edit a division](https://docs.digicert.com/en/iot-trust-manager/divisions/edit-a-division.html): If needed, you can update the name and description of a division in your account. - [Disable and enable a division](https://docs.digicert.com/en/iot-trust-manager/divisions/disable-and-enable-a-division.html): If you don't need to use a division but plan to use it again later, you can disable it. By default, disabled divisions are hidden on the Divisions page. When you are ready to use a division again, you can enable it. All… - [Delete and restore a division](https://docs.digicert.com/en/iot-trust-manager/divisions/delete-and-restore-a-division.html): If you create a division by mistake or no longer need the division, you can delete it. By default, deleted divisions are hidden on the Divisions page. If you delete a division by mistake, you can restore it. - [Assign a user to a division](https://docs.digicert.com/en/iot-trust-manager/divisions/assign-a-user-to-a-division.html): Divisions allow you to control further what users can see and do within DigiCert® IoT Trust Manager. When you add a user to a division, they can only see the items listed below based on the division you assigned them to. - [Remove a user from a division](https://docs.digicert.com/en/iot-trust-manager/divisions/remove-a-user-from-a-division.html): After you remove users from a division, what they can access depends on the number of divisions they are assigned to. - [Assign issuing CA to a division](https://docs.digicert.com/en/iot-trust-manager/divisions/assign-issuing-ca-to-a-division.html): Assign an issuing CA to one or more divisions to limit which division subunits in your account can use the issuing CA in certificate enrollment workflows. - [Customizable certificate issuance process](https://docs.digicert.com/en/iot-trust-manager/customizable-certificate-issuance-process.html): IoT device deployments vary significantly between organizations, manufacturers, assembly lines, and devices. Because of these variations, DigiCert® IoT Trust Manager allows you to configure your IoT device certificate… - [Five-step certificate issuance process](https://docs.digicert.com/en/iot-trust-manager/customizable-certificate-issuance-process/five-step-certificate-issuance-process.html): DigiCert® IoT Trust Manager has a five-step process for getting your IoT device certificates. - [Step 1: Create your certificate templates](https://docs.digicert.com/en/iot-trust-manager/customizable-certificate-issuance-process/step-1--create-your-certificate-templates.html): The certificate template is where the customization of a certificate starts. Certificate templates provide the first step in the configuration of base certificate properties. - [Step 2: Create your device profiles](https://docs.digicert.com/en/iot-trust-manager/customizable-certificate-issuance-process/step-2--create-your-device-profiles.html): The device profile is where you configure what a device record will look like and the device settings regarding a device's ability to access DigiCert® IoT Trust Manager's device-specific endpoints directly. For example… - [Step 3: Create your certificate profiles](https://docs.digicert.com/en/iot-trust-manager/customizable-certificate-issuance-process/step-3--create-your-certificate-profiles.html): The certificate profile is where you configure and customize the certificates for your devices and what they will look like. It is also where you set up the certificate details for your devices. - [Step 4: Create your enrollment profiles](https://docs.digicert.com/en/iot-trust-manager/customizable-certificate-issuance-process/step-4--create-your-enrollment-profiles.html): The enrollment profile is where you customize the certificate request form for your IoT device certificate deployments. When creating an enrollment profile, you can configure required fields, optional fields, default… - [Step 5: Request a certificate](https://docs.digicert.com/en/iot-trust-manager/customizable-certificate-issuance-process/step-5--request-a-certificate.html): The customized request form is where all the work—certificate templates, device profiles, certificate profiles, and enrollment profiles—pays off. Once the initial process is in place, repeat step five to get more… - [Certificate templates](https://docs.digicert.com/en/iot-trust-manager/certificate-templates.html): A Certificate Template in DigiCert® IoT Trust Manager provides the basic settings and essential components for creating certificates. Using this template, you get the configurations and patterns needed to issue… - [Certificate template structure](https://docs.digicert.com/en/iot-trust-manager/certificate-templates/certificate-template-structure.html): Possible values - [Create JSON formatted certificate templates](https://docs.digicert.com/en/iot-trust-manager/certificate-templates/create-json-formatted-certificate-templates.html): Use these instructions to create your JSON formatted certificate templates. - [Create a certificate template](https://docs.digicert.com/en/iot-trust-manager/certificate-templates/create-a-certificate-template.html): Before creating certificate templates, understand the following: - [Edit a certificate template](https://docs.digicert.com/en/iot-trust-manager/certificate-templates/edit-a-certificate-template.html): If needed, you can update the JSON formatted certificate template. You must be a system administrator with DigiCert® IoT Trust Manager permissions to edit certificate templates. - [Clone a certificate template](https://docs.digicert.com/en/iot-trust-manager/certificate-templates/clone-a-certificate-template.html): Instead of creating another template from scratch, you can clone a template and modify it as needed. - [Disable and enable a certificate template](https://docs.digicert.com/en/iot-trust-manager/certificate-templates/disable-and-enable-a-certificate-template.html): If a certificate template is no longer needed but may be needed again, you can disable it. Disabling a certificate template removes it from dropdowns on forms where template data is required, such as creating a… - [Delete and restore a certificate template](https://docs.digicert.com/en/iot-trust-manager/certificate-templates/delete-and-restore-a-certificate-template.html): If a certificate template is no longer needed, you can delete it. Deleting a certificate template removes it from forms where template data is required, such as creating a certificate profile. It also removes it from… - [Certificate profiles](https://docs.digicert.com/en/iot-trust-manager/certificate-profiles.html): In DigiCert® IoT Trust Manager, Certificate Profiles are used to define criteria for components and their values in a certificate. It aims to create consistent certificates with a focus on security and compatibility. - [Create a certificate profile](https://docs.digicert.com/en/iot-trust-manager/certificate-profiles/create-a-certificate-profile.html): Before you create a certificate profile, you need at least one certificate template. See Step 1: Create your certificate templates. - [Edit a certificate profile](https://docs.digicert.com/en/iot-trust-manager/certificate-profiles/edit-a-certificate-profile.html): After you create a certificate profile, you can update it as needed to meet the needs of your IoT device deployment. - [Clone a certificate profile](https://docs.digicert.com/en/iot-trust-manager/certificate-profiles/clone-a-certificate-profile.html): Instead of creating another certificate profile from the same template from scratch, you can clone the profile and modify it as needed. - [Disable and enable a certificate profile](https://docs.digicert.com/en/iot-trust-manager/certificate-profiles/disable-and-enable-a-certificate-profile.html): If a certificate profile is no longer needed but may be needed again, you can disable it. Disabling a certificate profile removes it from forms requiring a certificate profile, such as creating an enrollment profile. - [Delete and restore a certificate profile](https://docs.digicert.com/en/iot-trust-manager/certificate-profiles/delete-and-restore-a-certificate-profile.html): If a certificate profile is no longer needed, you can delete it. Deleting a certificate profile removes it from dropdowns on forms requiring a certificate profile, such as creating an enrollment profile. It also removes… - [Certificate requests](https://docs.digicert.com/en/iot-trust-manager/certificate-requests.html): DigiCert® IoT Trust Manager does not have a standardized certificate request form. Instead, you customize the certificate request forms to meet your IoT device deployment needs when configuring the certificate template… - [Before you begin](https://docs.digicert.com/en/iot-trust-manager/certificate-requests/before-you-begin.html): Before you request a certificate, you need at least one enrollment profile. See Step 4: Create your enrollment profiles. - [Request a certificate for an IoT device](https://docs.digicert.com/en/iot-trust-manager/certificate-requests/request-a-certificate-for-an-iot-device.html): These instructions are for requesting a certificate from within DigiCert® IoT Trust Manager in DigiCert ONE®. - [Submit batch certificate request with CSRs](https://docs.digicert.com/en/iot-trust-manager/certificate-requests/submit-batch-certificate-request-with-csrs.html): DigiCert® IoT Trust Manager supports batch certificate requests—also known as batch jobs—as an efficient means to request and receive hundreds or thousands of certificates for a common enrollment profile. In a batch… - [Submit certificate batch request with DigiCert ONE-generated keys](https://docs.digicert.com/en/iot-trust-manager/certificate-requests/submit-batch-certificate-request-with-digicert-one-generated-keys.html): DigiCert® IoT Trust Manager supports batch certificate requests—also known as batch jobs—as an efficient means to request and receive hundreds or thousands of certificates for a common enrollment profile. In a batch… - [Pick up a certificate batch](https://docs.digicert.com/en/iot-trust-manager/certificate-requests/pick-up-a-certificate-batch.html): Certificates generated for batch certificate requests are zipped and available for download through the DigiCert ONE portal. - [Trust bundles](https://docs.digicert.com/en/iot-trust-manager/trust-bundles.html): A trust bundle is a collection of digital certificates used to verify the authenticity and integrity of various entities in digital communication. It includes root Certificate Authorities (CAs), intermediate CAs, code… - [Get started with trust bundles](https://docs.digicert.com/en/iot-trust-manager/trust-bundles/get-started-with-trust-bundles.html): To see all trust bundles in your account: - [Manage trust bundles](https://docs.digicert.com/en/iot-trust-manager/trust-bundles/manage-trust-bundles.html): To modify a trust bundle: - [Download a trust bundle](https://docs.digicert.com/en/iot-trust-manager/trust-bundles/download-a-trust-bundle.html): In DigiCert ONE, in the Manager menu (top right), select DigiCert® IoT Trust Manager. - [Registered values](https://docs.digicert.com/en/iot-trust-manager/registered-values.html): Registered values are a sophisticated feature designed to enhance the security and integrity of certificate issuance processes. - [Get started with registered values](https://docs.digicert.com/en/iot-trust-manager/registered-values/get-started-with-registered-values.html): Make sure you understand the following DigiCert IoT Trust Manager concepts and components: - [Manage registered values](https://docs.digicert.com/en/iot-trust-manager/registered-values/manage-registered-values.html): In DigiCert ONE, in the Manager menu (top right), select DigiCert® IoT Trust Manager. - [Device profiles](https://docs.digicert.com/en/iot-trust-manager/device-profiles.html): A Device profile in DigiCert® IoT Trust Manager provides a structure for how device records are displayed and specifies which API endpoints a device can access. For instance, it might allow a device to view or update… - [Create a device profile](https://docs.digicert.com/en/iot-trust-manager/device-profiles/create-a-device-profile.html): In DigiCert ONE®, in the Manager menu (top right), select DigiCert® IoT Trust Manager. - [Edit a device profile](https://docs.digicert.com/en/iot-trust-manager/device-profiles/edit-a-device-profile.html): After creating a device profile, update it as needed to meet the needs of your devices. - [Delete and restore a device profile](https://docs.digicert.com/en/iot-trust-manager/device-profiles/delete-and-restore-a-device-profile.html): If a device profile is no longer needed, you can delete it. Deleting a device profile removes it from forms requiring a certificate profile, such as creating an enrollment profile. It also removes it from the list of… - [Devices](https://docs.digicert.com/en/iot-trust-manager/devices.html): After setting up a device profile, the next step is to create specific device records. Device records in DigiCert® IoT Trust Manager allows you to change details of an individual device's profile without needing to… - [Create a device](https://docs.digicert.com/en/iot-trust-manager/devices/create-a-device.html): Before creating a device, you need at least one device profile. See Device profiles. - [Edit a device](https://docs.digicert.com/en/iot-trust-manager/devices/edit-a-device.html): After creating a device, update the device record as needed to meet the device's needs. - [Disable and enable a device](https://docs.digicert.com/en/iot-trust-manager/devices/disable-and-enable-a-device.html): If a device is no longer needed but may be needed again, you can disable it. Disabling a device removes it from the list of active devices on the Device management page. - [Delete and restore a device](https://docs.digicert.com/en/iot-trust-manager/devices/delete-and-restore-a-device.html): If a device is no longer needed, you can delete it. Deleting a device removes it from the list of active devices on the Device management page. - [Enrollment profiles](https://docs.digicert.com/en/iot-trust-manager/enrollment-profiles.html): When preparing for DigiCert® IoT Trust Manager device certificate operations, you'll need an enrollment profile. This profile acts as your tailored form for certificate requests. As you set it up, you'll set necessary… - [Enrollment methods](https://docs.digicert.com/en/iot-trust-manager/enrollment-profiles/enrollment-methods.html): When you create an enrollment profile, you choose the certificate enrollment method used for the profile. You can only use one enrollment method for an enrollment profile. However, you can select one or more options for… - [Create enrollment profiles](https://docs.digicert.com/en/iot-trust-manager/enrollment-profiles/create-enrollment-profiles.html) - [Edit an enrollment profile](https://docs.digicert.com/en/iot-trust-manager/enrollment-profiles/edit-an-enrollment-profile.html): After you create an enrollment profile, you can update it as needed to meet the needs of your IoT device deployment. - [Edit enrollment profile device field mappings](https://docs.digicert.com/en/iot-trust-manager/enrollment-profiles/edit-enrollment-profile-device-field-mappings.html): After you create an enrollment profile, you can update its device field mappings as needed to meet the needs of your IoT device deployment. - [Add device authentication to an enrollment profile](https://docs.digicert.com/en/iot-trust-manager/enrollment-profiles/add-device-authentication-to-an-enrollment-profile.html) - [Disable and enable enrollment profiles](https://docs.digicert.com/en/iot-trust-manager/enrollment-profiles/disable-and-enable-enrollment-profiles.html): If an enrollment profile is no longer needed but may be needed again, you can disable it. Disabling an enrollment profile removes it from forms requiring an enrollment profile and the list of active profiles on the… - [Delete and restore enrollment profiles](https://docs.digicert.com/en/iot-trust-manager/enrollment-profiles/delete-and-restore-enrollment-profiles.html): If an enrollment profile is no longer needed, you can delete it. Deleting an enrollment profile removes it from forms requiring an enrollment profile, such as requesting a certificate. It also removes it from the list… - [Enrollment passcodes](https://docs.digicert.com/en/iot-trust-manager/enrollment-passcodes.html): Enrollment passcodes allow you to control how often a device or manufacture can use an enrollment profile when requesting certificates (new and renewals) using the Request a certificate and Renew a certificate endpoints. - [Create enrollment passcodes](https://docs.digicert.com/en/iot-trust-manager/enrollment-passcodes/create-enrollment-passcodes.html) - [Edit enrollment passcodes](https://docs.digicert.com/en/iot-trust-manager/enrollment-passcodes/edit-enrollment-passcodes.html): After creating an enrollment passcode, update it as needed to meet the needs of your IoT device deployments using it. - [Disable and enable enrollment passcodes](https://docs.digicert.com/en/iot-trust-manager/enrollment-passcodes/disable-and-enable-enrollment-passcodes.html): If an enrollment passcode is no longer needed but may be needed again, you can disable it. Disabling an enrollment passcode disables the ability to use the passcode credential to enroll for certificates. It also removes… - [Delete and restore enrollment passcodes](https://docs.digicert.com/en/iot-trust-manager/enrollment-passcodes/delete-and-restore-enrollment-passcodes.html): If an enrollment passcode is no longer needed, you can delete it. Deleting an enrollment passcode removes the ability to use the passcode credential to enroll for certificates. It also removes the passcode from the… - [Reports](https://docs.digicert.com/en/iot-trust-manager/reports.html): Raw report data can be generated as a comma-separated value file (CSV) for these objects in DigiCert® IoT Trust Manager: - [Download table data as a report](https://docs.digicert.com/en/iot-trust-manager/reports/download-table-data-as-a-report.html): For 10,000 or fewer records, quickly download all data as currently displayed in visible columns and any filters applied. - [Create a report](https://docs.digicert.com/en/iot-trust-manager/reports/create-a-report.html): Schedule a report when there are more than 10,000 records to export. - [Update a report](https://docs.digicert.com/en/iot-trust-manager/reports/update-a-report.html): Change a report name or scheduled run time. - [Pick up a report](https://docs.digicert.com/en/iot-trust-manager/reports/pick-up-a-report.html): Download a report after its scheduled run. - [Run a report now](https://docs.digicert.com/en/iot-trust-manager/reports/run-a-report-now.html): A saved report can be run immediately to get the most current data for a one-time report or report scheduled for later. The column and filter configuration for the report matches the saved report. - [View audit logs](https://docs.digicert.com/en/iot-trust-manager/reports/view-audit-logs.html): View audit logs for the history of actions and events in your DigiCert® IoT Trust Manager account. - [Integrations](https://docs.digicert.com/en/iot-trust-manager/integrations.html) - [Set up a DigiCert gateway](https://docs.digicert.com/en/iot-trust-manager/integrations/set-up-a-digicert-gateway.html): DigiCert gateways are designed to enable secure and efficient certificate management for devices where direct internet access is limited. It acts as a proxy, connecting isolated devices to DigiCert's digital certificate… - [Set up a CA connector for CertCentral](https://docs.digicert.com/en/iot-trust-manager/integrations/set-up-a-ca-connector-for-certcentral.html): Connect DigiCert® IoT Trust Manager to CertCentral to issue certificates using DigiCert's public CAs. - [Set up a CA connector for EJBCA](https://docs.digicert.com/en/iot-trust-manager/integrations/set-up-a-ca-connector-for-ejbca.html): Connect DigiCert® IoT Trust Manager to your EJBCA server to issue certificates from your CAs. - [Release notes](https://docs.digicert.com/en/iot-trust-manager/iot-trust-manager-release-notes.html): For maintenance schedules and older releases, visit the What's new section of this website. ## Content Trust Manager - [Content Trust Manager](https://docs.digicert.com/en/content-trust-manager.html): Content Trust Manager helps organizations protect the authenticity and integrity of documents and digital media while preserving their provenance. It provides trusted electronic seals, digital signatures, and media… - [Sign documents](https://docs.digicert.com/en/content-trust-manager/sign-documents.html): Sign documents with a digital signature or electronic seal to confirm authenticity, integrity, and origin. When you sign a document, the system adds a cryptographic signature using a trusted certificate. This links the… - [Get started](https://docs.digicert.com/en/content-trust-manager/sign-documents/get-started.html): Information to help you learn about and start using Content Trust Manager's document signing. - [Set up your account](https://docs.digicert.com/en/content-trust-manager/sign-documents/set-up-your-account.html): Manage your account to keep your users, credentials, and signing resources up to date in Content Trust Manager. Use account management features to control access, manage credentials, and review seat usage across your… - [Manage your account](https://docs.digicert.com/en/content-trust-manager/sign-documents/manage-your-account.html): Manage your account to keep your users, credentials, and signing resources up to date in Content Trust Manager. Use account management features to control access, manage credentials, and review seat usage across your… - [Monitor and report activity](https://docs.digicert.com/en/content-trust-manager/sign-documents/monitor-and-report-activity.html): Monitor and report activity to track signing events, review system usage, and maintain visibility across your Content Trust Manager account. Reporting tools help you review audit logs, generate reports, and monitor… - [Client tools](https://docs.digicert.com/en/content-trust-manager/sign-documents/client-tools.html): Client tools are applications used with Content Trust Manager to provide enhanced document signing features and functionality. Download Client tools from the Resources > Client tools page. - [Sign media](https://docs.digicert.com/en/content-trust-manager/sign-media.html): Content Trust Manager includes a media signing feature that lets you embed C2PA Content Credentials into media files. - [Get started](https://docs.digicert.com/en/content-trust-manager/sign-media/get-started.html): Information to help you learn about and start using Content Trust Manager's media signing. - [Set up your account](https://docs.digicert.com/en/content-trust-manager/sign-media/set-up-your-account.html): Learn how to set up and manage your Content Trust Manager media signing account. Your account gives you access to signing tools, user roles, and resources that support secure media signing workflows. - [Sign and verify media](https://docs.digicert.com/en/content-trust-manager/sign-media/sign-and-verify-media.html): Sign and verify media in Content Trust Manager. This helps protect the authenticity and integrity of your digital content. Use media signing tools to sign content in the browser or through code-based workflows. You can… - [Monitor and report signatures](https://docs.digicert.com/en/content-trust-manager/sign-media/monitor-and-report-signatures.html): Monitor and report signatures to track signing activity and review media signing data in Content Trust Manager. Reporting tools help you monitor signed content, review signing events, and generate reports from a… - [Integration guides](https://docs.digicert.com/en/content-trust-manager/integration-guides.html): Instructions and comprehensive guides for integrating different vendors and platforms with your DigiCert® Content Trust Manager ecosystem. - [CertCentral](https://docs.digicert.com/en/content-trust-manager/integration-guides/certcentral.html) - [true-Sign V](https://docs.digicert.com/en/content-trust-manager/integration-guides/true-sign-v.html): true-Sign V is a software solution that allows you to electronically sign documents with Content Trust Manager. It allows you to securely add signatures or sign documents on your computer using applications such as… - [Adobe](https://docs.digicert.com/en/content-trust-manager/integration-guides/adobe.html) - [DocuSign](https://docs.digicert.com/en/content-trust-manager/integration-guides/docusign.html) - [SigningHub](https://docs.digicert.com/en/content-trust-manager/integration-guides/signinghub.html) - [Go>Sign Mobile](https://docs.digicert.com/en/content-trust-manager/integration-guides/go-sign-mobile.html): Ascertia Go>Sign Mobile application lets you securely authorize and approve the signing of documents in the European Union (EU) and Switzerland (CH). - [Release notes](https://docs.digicert.com/en/content-trust-manager/content-trust-manager-release-notes.html): For maintenance schedules and older releases, visit the What's new section of this website. ## Quantum Central - [Quantum Central](https://docs.digicert.com/en/quantum-central.html): Welcome to the preview of DigiCert® Quantum Central. - [Get started](https://docs.digicert.com/en/quantum-central/get-started.html): DigiCert® Quantum Central helps you begin post-quantum cryptography readiness by giving you visibility into cryptographic assets, their status, and areas that may need governance or migration planning. - [Sign up for Quantum Central](https://docs.digicert.com/en/quantum-central/get-started/sign-up-for-quantum-central.html): Signing up for DigiCert® Quantum Central is as easy as creating an email account. - [Build your inventory](https://docs.digicert.com/en/quantum-central/get-started/build-your-inventory.html): A reliable cryptographic inventory is the foundation for post-quantum readiness. Before you can assess risk, plan remediation, or apply governance, you need visibility into the cryptographic assets in your environment… - [Check cryptographic posture](https://docs.digicert.com/en/quantum-central/check-crypto-posture.html): After you import cryptographic assets into Quantum Central, use the dashboard, inventory, violations, and visualizations to understand your current cryptographic posture. These views help you identify where cryptography… - [What's on your dashboard](https://docs.digicert.com/en/quantum-central/check-crypto-posture/read-your-dashboard.html): The DigiCert Quantum Central dashboard provides a high-level view of your post-quantum cryptography (PQC) posture. Use it to review key status indicators, identify areas that may need attention, and decide where to… - [Review your inventory](https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-your-inventory.html): DigiCert® Quantum Central provides a detailed view of the cryptographic assets in your environment on the Inventory page. - [Get AI-powered insights about your assets](https://docs.digicert.com/en/quantum-central/check-crypto-posture/get-ai-powered-insights-about-your-assets.html): Use DigiCert® Quantum Central AI Assist to understand your cryptographic posture and remediation requirements. - [Review policy violations](https://docs.digicert.com/en/quantum-central/check-crypto-posture/review-policy-violations.html): The Violations feature is on the roadmap. - [Understand visualizations](https://docs.digicert.com/en/quantum-central/check-crypto-posture/understand-visualizations.html): The Visualize feature is on the roadmap. - [Govern cryptographic assets](https://docs.digicert.com/en/quantum-central/govern-crypto-assets.html): Use DigiCert® Quantum Central to turn cryptographic visibility into governed actions. Configure settings, apply policies, follow recommendations, and create remediation tasks so your teams can manage cryptographic risk… - [Configure product settings](https://docs.digicert.com/en/quantum-central/govern-crypto-assets/configure-product-settings.html): The Product Settings page is on the roadmap. - [Define cryptographic policies](https://docs.digicert.com/en/quantum-central/govern-crypto-assets/define-crypto-policies.html): The Policies page is on the roadmap. - [Track and prioritize cryptographic remediation tasks](https://docs.digicert.com/en/quantum-central/track-and-prioritize-crypto-remediation-tasks.html): You can integrate DigiCert Quantum Central to your Jira, ServiceNow, and GitHub instances to create tasks for your cryptographic roadmap. - [Track cryptographic remediation tasks](https://docs.digicert.com/en/quantum-central/track-and-prioritize-crypto-remediation-tasks/track-crypto-remediation-tasks.html): The Tracking page is on the roadmap. - [Set up Quantum Central integrations](https://docs.digicert.com/en/quantum-central/set-up-quantum-central-integrations.html): Quantum Central helps you bring cryptographic remediation into the workflows you already use. Currently you can connect with Trust Lifecycle Manager and Atlassian Jira - [Integrate Trust Lifecycle Manager](https://docs.digicert.com/en/quantum-central/set-up-quantum-central-integrations/integrate-trust-lifecycle-manager.html): If you use DigiCert® Trust Lifecycle Manager, connect it to Quantum Central to import certificates and TLS endpoints into the Quantum Central cryptographic inventory. - [Integrate Atlassian Jira](https://docs.digicert.com/en/quantum-central/set-up-quantum-central-integrations/integrate-atlassian-jira.html): If you use Atlassian Jira, you can create remediation tasks in Jira from Quantum Central. - [Frequently asked questions](https://docs.digicert.com/en/quantum-central/frequently-asked-questions.html) - [What is included in the preview?](https://docs.digicert.com/en/quantum-central/frequently-asked-questions/what-is-included-in-the-preview-.html): A single-user workspace, default quantum-safe rules and cryptographic policies, certificate and TLS endpoint inventory, dashboards, and the inventory-aware AI assistant. Preview workspaces are subject to community… - [How many cryptographic assets can Quantum Central support?](https://docs.digicert.com/en/quantum-central/frequently-asked-questions/how-many-cryptographic-assets-can-quantum-central-support-.html): For the Preview there is no limit on the number of cryptographic assets. However, there is a maximum limit of 10,000 certificates that can be imported from DigiCert Trust Lifecycle Manager. - [Is the preview free?](https://docs.digicert.com/en/quantum-central/frequently-asked-questions/is-the-preview-free-.html): Yes, the Quantum Central preview is free. Once Quantum Central comes out of preview, paid subscription plans will be available. - [What is the roadmap for Quantum Central?](https://docs.digicert.com/en/quantum-central/frequently-asked-questions/what-is-the-roadmap-for-quantum-central-.html): We have many exciting features planned for Quantum Central such as: - [Do I need DigiCert Trust Lifecycle Manager?](https://docs.digicert.com/en/quantum-central/frequently-asked-questions/do-i-need-digicert-trust-lifecycle-manager-.html): No. You can get started by manually scanning your own public TLS endpoints and your partners/vendors. - [How is the AI model trained?](https://docs.digicert.com/en/quantum-central/frequently-asked-questions/how-is-the-ai-model-trained-.html): The AI model is a custom trained model that is trained on a curated set of trusted internet PQC sources, such as NIST, BSI, IETF, and others. - [What are the PQC dates and milestones for my country or the standards body that I work with?](https://docs.digicert.com/en/quantum-central/frequently-asked-questions/what-are-the-pqc-dates-and-milestones-for-my-country-or-the-standards-body-that-i-work-with-.html): Use this table to find PQC regulatory guidance, standards, and migration milestones relevant to your region, industry, or organization. - [How do I get support or give feedback?](https://docs.digicert.com/en/quantum-central/frequently-asked-questions/how-do-i-get-support-or-give-feedback-.html): During the preview you can get support and provide feedback by joining the Quantum Central Slack workspace. - [Release notes](https://docs.digicert.com/en/quantum-central/quantum-central-release-notes.html): For maintenance schedules and older releases, visit the What's new section of this website. ## Optional Supplementary sections (release notes, change logs, platform tools) that can be skipped when a shorter context is needed. - [What's new](https://docs.digicert.com/en/whats-new.html): DigiCert Quantum Central is now in preview - [Change log](https://docs.digicert.com/en/whats-new/change-log.html): See what's happening in CertCentral, such as new features, improvements, and bug fixes. We also log significant upcoming industry changes and other events that may affect your digital trust processes. - [CertCentral](https://docs.digicert.com/en/whats-new/change-log/certcentral-change-log.html): Important update: Google Chrome updated their root program requirements extending the timeline for removing the Client Authentication extended key usage (EKU) from public TLS certificates. - [Older changes](https://docs.digicert.com/en/whats-new/change-log/older-changes.html) - [Release notes](https://docs.digicert.com/en/whats-new/release-notes.html): Learn about new features, enhancements, fixes, and known issues for our DigiCert ONE product suite organized by product and release date. - [DigiCert ONE Platform](https://docs.digicert.com/en/whats-new/release-notes/digicert-one-platform-release-notes.html): DigiCert ONE is a unified suite of digital trust products that allow you to deploy and manage multiple PKI solutions in any environment. These release notes provide information about: - [Trust Lifecycle Manager](https://docs.digicert.com/en/whats-new/release-notes/trust-lifecycle-manager-release-notes.html): DigiCert® ONE version: 1.13108.3 | Trust Lifecycle Manager: 1.6075.0 - [Device Trust Manager](https://docs.digicert.com/en/whats-new/release-notes/device-trust-manager-release-notes.html): Users with account-scoped access can now view, clone, and edit certificate templates in Device Trust Manager. - [IoT Trust Manager](https://docs.digicert.com/en/whats-new/release-notes/iot-trust-manager-release-notes.html): DigiCert® ONE version: 1.11805.0 | IoT Trust Manager: 1.903.0 - [Content Trust Manager](https://docs.digicert.com/en/whats-new/release-notes/content-trust-manager-release-notes.html): DigiCert® ONE version: 1.13108.4 | Content Trust Manager: 1.1585.2 - [Software Trust Manager](https://docs.digicert.com/en/whats-new/release-notes/software-trust-manager-release-notes.html): DigiCert® ONE version: 1.13108.5 | Software Trust Manager: 1.1353.0 - [DigiCert KeyLocker](https://docs.digicert.com/en/whats-new/release-notes/digicert-keylocker-release-notes.html): DigiCert® ONE version: 1.12877.24 | DigiCert KeyLocker: 1.1332.0 - [Account Manager](https://docs.digicert.com/en/whats-new/release-notes/account-manager-release-notes.html): As of May 2025, Account Manager release content will move to the DigiCert ONE Platform release notes. - [DigiCert Private CA](https://docs.digicert.com/en/whats-new/release-notes/ca-manager-release-notes.html): DigiCert® ONE version: 1.xxxx.x | DigiCert® Private CA: 1.1127.0 - [Ultra Security](https://docs.digicert.com/en/whats-new/release-notes/ultra-security-release-notes.html): Ultra Security Version: 2026-04-17 - [Quantum Central](https://docs.digicert.com/en/whats-new/release-notes/quantum-central-release-notes.html): DigiCert® ONE version: NA | Quantum Central: Preview - [Older releases](https://docs.digicert.com/en/whats-new/release-notes/older-releases.html) - [Maintenance schedules](https://docs.digicert.com/en/whats-new/digicert-maintenance-schedules.html): DigiCert schedules the maintenance windows for our services each year to make planning your certificate, services, and platform-related tasks easier. - [DigiCert Europe 2026 maintenance schedule](https://docs.digicert.com/en/whats-new/digicert-maintenance-schedules/digicert-europe-2026-maintenance-schedule.html): To make it easier to plan your certificate and service-related tasks, here’s the DigiCert Europe 2026 maintenance schedule. We update the schedule as new maintenance information becomes available. For example, if there… - [DigiCert global 2026 maintenance schedule](https://docs.digicert.com/en/whats-new/digicert-maintenance-schedules/digicert-global-2026-maintenance-schedule.html): To make it easier to plan your certificate and service-related tasks, here’s the DigiCert global 2026 maintenance schedule. We update the schedule as new maintenance information becomes available. For example, if there… - [DigiCert 2026年メンテナンススケジュール](https://docs.digicert.com/en/whats-new/digicert-maintenance-schedules/digicert-global-2026-maintenance-schedule--jp.html): このページでは、証明書、サービス、およびプラットフォームに関連する作業を計画しやすくするために2026 年度におけるすべてのメンテナンススケジュールの最新情報をご案内いたします。 - [Older maintenance schedules](https://docs.digicert.com/en/whats-new/digicert-maintenance-schedules/older-maintenance-schedules.html)