Trust Lifecycle Manager

BeyondTrust Password Safe

Beyond Trust Integration Hero

Integration overview

BeyondTrust customers use Password Safe to securely manage the credentials for privileged accounts that control critical devices, such as network infrastructure and application servers. These customers can use the BeyondTrust Connector from DigiCert to allow DigiCert Trust Lifecycle Manager (TLM) to securely automate the issuance, rotation, and revocation of TLS certificates on those critical devices using the appropriate privileged credentials.

Together, Trust Lifecycle Manager and Password Safe:

  1. Replace or harden password-based workflows with certificate-based admin access (mTLS) for vault-to-target, jump host, and session proxy connections
  2. Auto-renew appliance/web console and connector certificates to prevent outages under the upcoming 47-day TLS lifetime
  3. Provision short-lived client certs for admins, services, and connectors, with policy-driven rotation
  4. Maintain a unified, auditable certificate inventory

The result is fewer outages, stronger Zero Trust controls, faster incident response via instant revoke, and simpler compliance across PAM infrastructure.

The customer needs at least one active DigiCert sensor to securely establish and manage the connection to the Password Safe secrets manager instance. For fault-tolerant connectivity, multiple sensors can be used to manage the connector. If one of the sensors fails, the connector automatically fails over to another sensor.

What it does

The integration between DigiCert Trust Lifecycle Manager and BeyondTrust Password Safe allows customers to automate certificate issuance, renewal, and replacement directly from a DigiCert-managed source to critical Password Safe-protected assets, like network load balancers, servers, and OT controllers. DigiCert retrieves the credentials from the PAM and logs into the device in order to perform certificate management.

Why it matters

How it integrates

Resources