Skip to main content

Part 2: Configure Device Trust Manager

Now that initial access is set up, the next step is to configure DigiCert® Device Trust Manager for secure device management. This guide will help you create divisions, define authentication policies, and set up certificate profiles.

Objectives

  • Create divisions to organize devices by business needs.

  • Set up authentication policies to manage device access.

  • Configure certificate profiles and management policies for certificate issuance.

Before you begin

To start initial configuration of Device Trust Manager, complete the following steps:

Step 1: Create a division and configure Rendezvous zones

Divisions allow you to create subtenants within a Device Trust Manager account. This allows you to manage devices according to criteria such as location, function, or business unit.

Note

Device Trust Manager Rendezvous provides distinct zones, called Device Rendezvous Zones (DRZs), that are located across the globe to reduce latency and improve response times based on device proximity. After creating a division, a primary and secondary zone for Rendezvous can be configured.

  1. Sign in to DigiCert® ONE as a Solution Administrator.

  2. In DigiCert ONE, in the Manager menu (grid at top right), select Device Trust.

  3. In the Device Trust Manager menu, select Divisions.

  4. On the Divisions page, select Create new division.

  5. Enter a Name and, optionally, a description.

  6. Select Create new division to save.

  7. On the Divisions page, select the created division to view its details.

  8. On the Division details page, expand the Rendezvous zones assigned to division section.

  9. On the Primary zone tab, choose a Rendezvous zone from the dropdown and select Add zone.

  10. (Optional) On the Secondary zone tab, select a backup Rendezvous zone and select Add zone.

Step 2: Create an authentication policy

Authentication policies serve as a sort of container for multiple credentials, including passcodes, authentication certificates, and authentication CAs.

Tip

A single authentication policy can be assigned to multiple device groups and certificate management policies.

  1. In the Device Trust Manager menu, select Authentication policy.

  2. Select Create authentication policy.

  3. Enter a Name and, optionally, a description.

  4. Select Create new authentication policy to save.

Step 3: Add a passcode to an authentication policy

Passcodes are one of the methods that can be used for device authentication and certificate requests using protocols such as SCEP, EST, and CMPv2. Authentication methods are assigned to authentication policies.

  1. In the Device Trust Manager menu, select Authentication policy > Passcodes.

  2. Select Create passcode.

  3. Enter a Name and, optionally, a description.

  4. Under Assign or create an authentication policy, choose the policy created in Step 2: Create an authentication policy.

  5. If necessary, configure additional passcode settings, such as usage restrictions.

  6. Select Create passcode to save.

Important

When using a passcode for API authentication, make sure to set the header to x-passcode instead of x-api-key.

Step 4: Create a certificate profile

Certificate profiles define essential settings for certificate issuance. You can set default values for subject distinguished names, customize the certificate validity period, and enable or disable specific extensions as needed.

  1. In the Device Trust Manager menu, select Certificate management > Certificate profiles.

  2. Select Create certificate profile.

  3. Enter a Name for the certificate profile.

  4. Use DigiCert ONE as the CA source, or choose one from the list.

  5. Under Template, select either End entity or Intermediate CA, depending on your needs.

  6. Choose a certificate template that the certificate profile will use. Configurable custom field options are loaded based on the chosen template.

    Note

  7. Select if All divisions can use the certificate profile or only Specific divisions.

  8. Configure custom field options as required. For example, default values or renewal settings.

  9. Select Create to save the certificate profile.

Step 5: Create a certificate management policy

Certificate management policies link components and protocols that determine certificate issuance and management settings.

  1. In the Device Trust Manager menu, select Certificate management > Certificate management policies.

  2. Select Create certificate management policy.

  3. On the General settings step:

    1. Enter a Name for the policy.

    2. Select the Division created in Step 1: Create a division and configure Rendezvous zones.

    3. Select whether certificates issued with this policy will be associated with a device group or not.

    4. For Certificate management methods, select the protocols permitted by this policy. For example, Single certificate request through portal and API, SCEP, and EST.

      Note

      The selected certificate management methods must align with the settings in the certificate profiles. If there are no certificate profiles that support the chosen protocols, you won’t be able to create the certificate management policy.

    5. Select Next.

  4. On the Certificate settings step:

    1. Choose a certificate profile to use with this policy.

    2. Choose the issuing CA that will be used to sign certificates.

    3. For Keypair generation settings, select who will generate keypairs: the device, DigiCert​​®​​, or both.

      • Local keypair generation: The device generates the keypair locally for certificate issuance.

      • Server-side keypair generation: DigiCert​​®​​ generates the keypair for certificate issuance. When selecting this option, specify the default key type and size, such as RSA 2048 or P-256.

      • Allow the requestor to select local or server-side keypair generation at the time of their certificate request: Provides flexibility by enabling the device or client to choose either local or server-side keypair generation based on their needs at the time of the request. When selecting this option, specify the default key type and size, such as RSA 2048 or P-256.

    4. Select Next.

  5. On the Certificate management method settings step:

    1. Under Single certificate request through portal and API:

      • Change any of the default portal and API certificate request settings as needed.

    2. Select Next.

  6. On the Usage restrictions (optional) step:

    1. Unless specific usage restrictions are required, leave the default values as they are.

    2. Select Finish to complete the setup and save the certificate management policy.

Review your progress

At this stage, Device Trust Manager is configured with divisions, authentication policies, and certificate management policies. You should now have:

  • A division created to organize devices and other entities

  • Authentication policies and passcodes set up for secure access

  • Certificate profiles and management policies defined for controlled certificate issuance

What’s next?

Continue to Part 3: Set up device management to configure your device management structure.