Trust Lifecycle Manager
BeyondTrust Password Safe
Integration overview
BeyondTrust customers use Password Safe to securely manage the credentials for privileged accounts that control critical devices, such as network infrastructure and application servers. These customers can use the BeyondTrust Connector from DigiCert to allow DigiCert Trust Lifecycle Manager (TLM) to securely automate the issuance, rotation, and revocation of TLS certificates on those critical devices using the appropriate privileged credentials.
Together, Trust Lifecycle Manager and Password Safe:
- Replace or harden password-based workflows with certificate-based admin access (mTLS) for vault-to-target, jump host, and session proxy connections
- Auto-renew appliance/web console and connector certificates to prevent outages under the upcoming 47-day TLS lifetime
- Provision short-lived client certs for admins, services, and connectors, with policy-driven rotation
- Maintain a unified, auditable certificate inventory
The result is fewer outages, stronger Zero Trust controls, faster incident response via instant revoke, and simpler compliance across PAM infrastructure.
The customer needs at least one active DigiCert sensor to securely establish and manage the connection to the Password Safe secrets manager instance. For fault-tolerant connectivity, multiple sensors can be used to manage the connector. If one of the sensors fails, the connector automatically fails over to another sensor.
What it does
The integration between DigiCert Trust Lifecycle Manager and BeyondTrust Password Safe allows customers to automate certificate issuance, renewal, and replacement directly from a DigiCert-managed source to critical Password Safe-protected assets, like network load balancers, servers, and OT controllers. DigiCert retrieves the credentials from the PAM and logs into the device in order to perform certificate management.
Why it matters
- Improve security: Ensure all protected systems have valid, trusted, and compliant certificates with increased cryptographic agility.
- Protect critical assets: No need to share login credentials or API keys.
- Reduce downtime: Eliminate service disruptions due to misconfigured or expired certificates
- Decrease administrative effort: Automate renewals and deployment instead of relying on manual updates
How it integrates
- Uses the DigiCert sensor for secure communication with the Password Safe instance, either in the cloud or on-premises.
- Trust Lifecycle Manager acts as the control plane for certificate discovery, issuance, renewal, and deployment.
- No inbound network communications from the DigiCert cloud
Resources
- Step-by-Step TLM Configuration Demo
- Solution Brief
- DigiCert documentation: BeyondTrust connector
- DigiCert documentation: Support in TLM for secure credential retrieval from BeyondTrust vaults for authenticating AWS Certificate Manager (ACM) automation flows
- BeyondTrust and CyberArk secrets managers integration with Azure Key Vault
- Blog: DigiCert + BeyondTrust: Integrated secrets and PKI management for security and compliance