What it does

  • Enables automated certificate issuance and renewal using the CertCentral ACME Automation Client or any third-party ACME client (e.g., Certbot) for supported endpoints.

  • In CertCentral, customers can add ACME credentials and use them to automate DigiCert TLS certificate issuance and renewal via ACME. 

  • In Trust Lifecycle Manager, customers define certificate profiles, generate ACME credentials, and then use ACME clients to initiate issuance and renewals from DigiCert and third-party Certificate Authorities, private or public.

  • Trust Lifecycle Manager’s inventory and policy controls allow visibility and management of ACME-issued certificates
    in a central UI. 

  • Supports DevOps automation via ACME


Why it matters

  • Lower administrative burden: Automate short-lived TLS certificate renewal cycles (e.g. 200-, 100-, 47-day certificate validity, 10-day domain control validity) across heterogeneous infrastructure.
  • Reduced outage risk: Minimize downtime from errors or expired/missed certificate renewals.
  • Broad protocol support: Use a single ACME approach across web, load balancers, containers, and cloud workloads.
  • Extended flexibility via Trust Lifecycle Manager: Manage ACME workflows for both DigiCert and third-party CAs, with policy, inventory, and lifecycle visibility.