Understand the products in DigiCert ONE
DigiCert products provide capabilities for digital-trust, certificate-issuance, and infrastructure workflows. Products are enabled or connected within an environment.
Products can perform different roles:
CertCentral and DigiCert® Private CA issue certificates. For ease of reference these two products will be referred to as trust sources.
All other products provide workflows for managing, automating, securing, or applying digital trust.
Products that act as trust sources
These products are the certificate-authority service that issue certificates. The presence of these products in your environment also determines whether you can request certificates that are publicly or privately trusted.
Select the trust source based on the systems and users that need to recognize that trust:
Use CertCentral when your certificates need to be recognized by public browsers, operating systems, email clients, or other systems that use public trust stores. Use it when certificates must be recognized without separately installing or distributing your organization’s private CA certificate to the relying systems.
Use DigiCert® Private CA when the relying systems are managed by your organization and can be configured to trust your private CA. Use it when your organization controls the relying systems and can configure them to trust your private CA.
Your environment can have one or both trust sources, depending on its configuration and certificate requirements.
Opmerking
Public trust doesn’t mean that the certificate, service, or protected system is publicly accessible. It means that the certificate chains to a CA recognized by public trust stores.
Compare trust sources
Feature | CertCentral | DigiCert® Private CA |
|---|---|---|
Trust type | Public trust | Private trust |
Recognition | Certificates are recognized by supported public trust stores | Certificates are recognized by systems configured to trust your private CA |
Environment scope | Can serve multiple production environments | Restricted to one environment |
Quantity | Multiple CertCentral accounts can be connected to one environment | No more than one Private CA per environment |
Sharing | Can be shared across products and production environments | Can’t be shared with another environment but can be shared across products within the same environment |
Common use | Public websites, externally distributed software, email, documents, and other public-trust workflows | Managed users, devices, servers, applications, services, and private PKI workflows |
Products that act as trust workflows
These products provide capabilities for specific digital-trust and infrastructure workflows. Products are enabled and configured within an environment.
Select products based on the workflows you need to support:
Use Trust Lifecycle Manager to discover, monitor, automate, and govern certificates across your environments.
Use Software Trust Manager to secure code signing, releases, and software supply chain workflows.
Use Device Trust Manager to establish and manage trusted device identities throughout the device lifecycle.
Use Content Trust Manager to protect the authenticity, integrity, and provenance of documents and digital media.
Use DigiCert® DNS to manage authoritative DNS for availability, performance, resiliency, and traffic routing.
An environment can include one or more products. Select the combination that supports your workflows and operational requirements.
Opmerking
Products and trust sources serve different roles. Trust sources issue certificates or establish trusted identities. Products provide the capabilities and workflows used to manage, automate, secure, or apply digital trust.
Where products fit in DigiCert ONE
DigiCert account
│
├── Account settings
│
├── Environment: US hosted region
│ │
│ └── Products
│ │
│ ├── Trust sources
│ │ ├── CertCentral
│ │ └── DigiCert Private CA
│ │
│ └── Trust workflows
│ ├── Trust Lifecycle Manager
│ ├── Software Trust Manager
│ ├── Content Trust Manager
│ ├── Device Trust Manager
│ └── DigiCert DNS
│
└── Environment: EU hosted region
│
└── Products
│
├── Trust sources
│ └── DigiCert Private CA
│
└── Trust workflows
├── Trust Lifecycle Manager
├── Software Trust Manager
├── Content Trust Manager
├── Device Trust Manager
└── DigiCert DNSA DigiCert® account can contain multiple environments, such as production and demo. Each environment contains the trust sources and, and or DigiCert ONE products used in that environment. Trust sources establish where the trust originates. DigiCert ONE products get certificates from the trust source, if you request a publicly trusted certificate the product gets the certificate from a CertCentral instance in the same environment and if you request a privately trusted certificate it gets it from DigiCert® Private CA.
How workflows use trust sources
Trust sources can work on their own, where you’re solely using it to download certificates and use it in external systems.
Alternatively, when a product workflow in your environment requires a certificate:
You determine whether you require a public or private trust certificate.
The product requests the certificate from the appropriate trust source within the same environment.
CertCentral or DigiCert® Private CA issues the certificate.
The product manages, distributes, installs, or uses the certificate as part of its workflow.
Tip
Not every product capability requests a certificate. The trust-source relationship applies to workflows that require certificate issuance.
Trust workflow
│
├── Public trust requested
│ └── Request certificate from CertCentral
│
└── Private trust requested
└── Request certificate from DigiCert Private CA