Skip to main content

Understand the trust sources in DigiCert® ONE

A trust source is the certificate-authority service that issues certificates. The selected trust source determines whether the resulting certificates are publicly or privately trusted.

Choose the trust source based on the systems and users that need to recognize that trust:

  • Use CertCentral for public trust when certificates must be recognized by public browsers, operating systems, email clients, or other systems that use public trust stores. Use it when certificates must be recognized without separately installing or distributing your organization’s private CA certificate to the relying systems.

  • Use DigiCert Private CA for private trust when the relying systems are managed by your organization and can be configured to trust your private CA. Use it when your organization controls the relying systems and can configure them to trust your private CA.

Your environment can have one or both trust sources, depending on its configuration and certificate requirements.

Nota

Public trust does not mean that the certificate, service, or protected system is publicly accessible. It means that the certificate chains to a CA recognized by public trust stores.

Compare trust sources

Feature

CertCentral

DigiCert Private CA

Trust type

Public trust

Private trust

Recognition

Certificates are recognized by supported public trust stores

Certificates are recognized by systems configured to trust your private CA

Environment scope

Can serve multiple production environments

Restricted to one environment

Quantity

Multiple CertCentral accounts can be connected to one environment

No more than one Private CA per environment

Sharing

Can be shared across products and production environments

Cannot be shared with another environment but can be shared across products within the same environment

Common use

Public websites, externally distributed software, email, documents, and other public-trust workflows

Managed users, devices, servers, applications, services, and private PKI workflows

How products use trust sources

Trust sources can work on their own, where you are soley using it to download certificates and use it in external systems.

Alternatively, when a product workflow in your environment requires a certificate:

  1. You determine whether it requires public or private trust.

  2. The product requests the certificate from the appropriate trust source within the same environment.

  3. CertCentral or DigiCert Private CA issues the certificate.

  4. The product manages, distributes, installs, or uses the certificate as part of its workflow.

    Dica

    Not every product capability requests a certificate. The trust-source relationship applies to workflows that require certificate issuance.

Product workflow
       │
       ├── Public trust requested
       │       └── Request certificate from CertCentral
       │
       └── Private trust requested
               └── Request certificate from DigiCert Private CA