What it does
- Enables automated certificate issuance and renewal using the CertCentral ACME Automation Client or any third-party ACME client (e.g., Certbot) for supported endpoints.
- In CertCentral, customers can add ACME credentials and use them to automate DigiCert TLS certificate issuance and renewal via ACME.
- In Trust Lifecycle Manager, customers define certificate profiles, generate ACME credentials, and then use ACME clients to initiate issuance and renewals from DigiCert and third-party Certificate Authorities, private or public.
- Trust Lifecycle Manager’s inventory and policy controls allow visibility and management of ACME-issued certificates
in a central UI.
- Supports DevOps automation via ACME
Why it matters
- Lower administrative burden: Automate short-lived TLS certificate renewal cycles (e.g. 200-, 100-, 47-day certificate validity, 10-day domain control validity) across heterogeneous infrastructure.
- Reduced outage risk: Minimize downtime from errors or expired/missed certificate renewals.
- Broad protocol support: Use a single ACME approach across web, load balancers, containers, and cloud workloads.
- Extended flexibility via Trust Lifecycle Manager: Manage ACME workflows for both DigiCert and third-party CAs, with policy, inventory, and lifecycle visibility.
Resources
Trust Lifecycle Manager: ACME Automation Overview
Learn more
CertCentral: Guided TLS/SSL certificate lifecycle automation
Learn more
DigiCert ACME Client Technical Reference
Learn more