Internal and air-gapped environments

Automate certificate lifecycles in isolated networks while preserving the network controls your security architecture requires.

DigiCert Trust Lifecycle Manager (TLM) supports two isolation models: a private, on-premises DigiCert ONE deployment for environments that must keep private certificate lifecycle operations inside the network boundary, and cloud-hosted TLM accessed through an approved proxy or DigiCert sensor when controlled outbound connectivity is permitted.

The appropriate architectural model depends on your actual isolation level, certificate trust requirements, and the deployment options supported for your account. If you require a fully managed on-premises deployment, contact DigiCert to speak with the extended DigiCert team and determine the best architecture for your environment.

How Digicert automation works

Fully disconnected environments keep private-trust lifecycle operations inside the boundary. Restricted environments can centralize cloud management through a controlled proxy path. Please speak to a DigiCert solutions architect to determine the optimal architecture for your specific needs.

Why this scenario matters

A truly disconnected network has no routable path to external services, whereas a restricted network allows controlled outbound connectivity through a proxy, DMZ, or sensor, and that distinction determines which certificate-management architecture is most viable.

Private-trust certificates are typically the best fit when issuance, renewal, and deployment must stay entirely within the network boundary. Public-trust certificates can still be used on isolated services, but issuance depends on an external CA and domain-validation process. In a true air gap, issuance or renewal must happen outside the boundary, and the certificate must be transferred through an approved process rather than managed end-to-end from inside the isolated network.

How DigiCert fits

At a glance

Technical implementation details

Exact network destinations, local trust-store requirements, supported operating systems, proxy configuration, CA connector prerequisites, and enrollment behavior vary by deployment. Confirm the current DigiCert documentation before designing firewall rules or implementation procedures, especially for private on-premises DigiCert ONE environments. Contact DigiCert to determine the best architecture for your environment.

Frequently asked questions

Can DigiCert automate certificates in an environment with no internet access?
Yes, for supported private on-premises DigiCert ONE deployments, private-trust certificate lifecycle operations can be performed against local DigiCert ONE services rather than the DigiCert-hosted cloud. Confirm that the deployment model, local Trust Lifecycle Manager services, CA design, and required agent or sensor trust settings are available for your environment by contacting a DigiCert representative.
Can DigiCert agents work when servers are not allowed direct internet access?
Yes, agents can be configured to connect through a customer-managed proxy or through a DigiCert sensor acting as a proxy. The proxy or sensor still needs the connectivity required for the selected DigiCert ONE environment. Individual managed servers do not need a direct path to the internet.
Are public CA certificates impossible to use in an air-gapped environment?
No, the key limitation is lifecycle connectivity, not whether a public certificate can technically be installed. Public-trust issuance and renewal depend on an external public CA and its validation process. In a truly disconnected network, those steps must occur outside the air gap, and the resulting certificate must be transferred through an approved process. That is different from fully automated in-boundary lifecycle management. Please contact a DigiCert representative for more information.

Ready to evaluate your environment?

See how DigiCert Trust Lifecycle Manager can support certificate lifecycle automation across your enterprise.

Explore DigiCert Trust Lifecycle Manager Talk to DigiCert