TLS termination on a single load balancer

In this scenario, a load balancer presents the TLS certificate to clients, decrypts the traffic, and forwards requests to backend servers over HTTP. DigiCert Trust Lifecycle Manager (TLM) can automate certificate management on supported load balancers through a DigiCert sensor installed on a separate host in the network. This helps centralize certificate inventory, lifecycle automation, and monitoring without requiring a DigiCert agent on the load balancer itself.

TLS termination on a single load balancer diagram

Trust Lifecycle Manager coordinates lifecycle management through a DigiCert sensor, which connects to the supported load balancer over the network.

Why this scenario matters

TLS termination centralizes client-facing certificate deployment at the load balancer. If a certificate bound to a listener or hostname expires or is replaced incorrectly, clients can no longer establish a trusted TLS session with the affected service. Public TLS certificate lifetimes are also getting shorter, with industry rules on a path toward a 47-day maximum validity period by 2029.

Certificate automation reduces the operational burden of repeated renewals and installations, but it does not eliminate the need for sound architecture and continuous monitoring. IT teams should still verify platform support, management connectivity, credentials, domain validation, certificate profiles, and whether TLS is also needed between the load balancer and backend servers. DigiCert can support the full lifecycle management of certificates on load balancers and web servers.

How DigiCert fits

Centralized lifecycle management

Use TLM to maintain certificate inventory, create automation profiles, manage lifecycle events, and monitor certificate status from a centralized console.

Sensor-based appliance automation

A DigiCert sensor runs on a separate supported host and manages supported network appliances over the network. No DigiCert agent is installed on the load balancer.

Automated domain validation

TLM DNS integrations can automate domain control validation during certificate lifecycle events when the issuing CA and certificate type require it.

Operational visibility

TLM can discover and monitor certificates on supported load balancers and provides lifecycle status and notification capabilities for connected environments.

At a glance

Technical implementation details

The exact connector, supported versions, management ports, credentials, sensor placement, DNS integration requirements, and automation workflow vary by load balancer platform. For example, supported physical appliances include specific versions of F5 BIG-IP LTM, Citrix ADC, and A10, while supported cloud services include AWS load balancing, GCP, and CloudFront services.

Frequently asked questions

Can DigiCert automate certificates on a load balancer?
Yes, Trust Lifecycle Manager supports managed certificate automation for supported network appliances and web servers. For network appliances, a DigiCert sensor on a separate host provides the network-based integration used to discover and manage certificates.
Does DigiCert software have to run on the load balancer?
Not for supported sensor-managed network appliances. The DigiCert sensor runs on a separate supported host and connects to the load balancer using the platform-specific management interface or API.
How is domain validation handled for automated public TLS certificates?
When domain control validation is required, Trust Lifecycle Manager can use a configured DNS integration to automate the DNS challenge for the fully qualified domain name in the certificate request. Requirements vary by issuing CA and certificate type.
What if the backend servers also use TLS?
Then this is no longer a certificate-at-the-load-balancer-only design. The backend TLS connections also need certificates and lifecycle management. DigiCert can readily support certificate automation for the load balancers and backend web servers.

Ready to evaluate your environment?

See how DigiCert Trust Lifecycle Manager can support certificate lifecycle automation across your enterprise.

Explore DigiCert Trust Lifecycle Manager Talk to DigiCert