TLS termination on a single load balancer
In this scenario, a load balancer presents the TLS certificate to clients, decrypts the traffic, and forwards requests to backend servers over HTTP. DigiCert Trust Lifecycle Manager (TLM) can automate certificate management on supported load balancers through a DigiCert sensor installed on a separate host in the network. This helps centralize certificate inventory, lifecycle automation, and monitoring without requiring a DigiCert agent on the load balancer itself.
Trust Lifecycle Manager coordinates lifecycle management through a DigiCert sensor, which connects to the supported load balancer over the network.
Why this scenario matters
TLS termination centralizes client-facing certificate deployment at the load balancer. If a certificate bound to a listener or hostname expires or is replaced incorrectly, clients can no longer establish a trusted TLS session with the affected service. Public TLS certificate lifetimes are also getting shorter, with industry rules on a path toward a 47-day maximum validity period by 2029.
Certificate automation reduces the operational burden of repeated renewals and installations, but it does not eliminate the need for sound architecture and continuous monitoring. IT teams should still verify platform support, management connectivity, credentials, domain validation, certificate profiles, and whether TLS is also needed between the load balancer and backend servers. DigiCert can support the full lifecycle management of certificates on load balancers and web servers.
How DigiCert fits
Centralized lifecycle management
Use TLM to maintain certificate inventory, create automation profiles, manage lifecycle events, and monitor certificate status from a centralized console.
Sensor-based appliance automation
A DigiCert sensor runs on a separate supported host and manages supported network appliances over the network. No DigiCert agent is installed on the load balancer.
Automated domain validation
TLM DNS integrations can automate domain control validation during certificate lifecycle events when the issuing CA and certificate type require it.
Operational visibility
TLM can discover and monitor certificates on supported load balancers and provides lifecycle status and notification capabilities for connected environments.
At a glance
- Environment: one load balancer terminates client TLS. In this simplified scenario, backend servers receive HTTP from the load balancer, and HTTPS is supported if required.
- DigiCert deployment model: Trust Lifecycle Manager with a DigiCert sensor on a separate supported host, plus the appropriate appliance or cloud-service connector for the load balancer.
- Typical validation approach: automated DNS-based domain control validation through a TLM DNS integration when DCV is required. Validation requirements depend on the issuing CA and certificate type.
- What to verify before deployment: supported load balancer and version, sensor prerequisites and outbound connectivity, load-balancer management/API access and credentials, DNS integration requirements, certificate profile, and any backend TLS requirements.
Technical implementation details
The exact connector, supported versions, management ports, credentials, sensor placement, DNS integration requirements, and automation workflow vary by load balancer platform. For example, supported physical appliances include specific versions of F5 BIG-IP LTM, Citrix ADC, and A10, while supported cloud services include AWS load balancing, GCP, and CloudFront services.
- Supported systems — confirm currently tested load balancer platforms, cloud services, and versions.
- DigiCert sensors — understand the sensor role for network-based integrations and certificate automation on appliances and cloud services.
- Sensor system and network requirements — review supported sensor hosts and required outbound connectivity to DigiCert ONE and automation services.
- DNS integrations for domain validation — see how DNS integrations are assigned to automated systems to support domain control validation.
Frequently asked questions
Ready to evaluate your environment?
See how DigiCert Trust Lifecycle Manager can support certificate lifecycle automation across your enterprise.