Trust Lifecycle Manager

BeyondTrust Password Safe

Beyond Trust Integration Hero

Integration overview

BeyondTrust customers use Password Safe to securely manage the credentials for privileged accounts that control critical devices, such as network infrastructure and application servers. These customers can use the BeyondTrust Connector from DigiCert to allow DigiCert Trust Lifecycle Manager (TLM) to securely automate the issuance, rotation, and revocation of TLS certificates on those critical devices using the appropriate privileged credentials.

Together, Trust Lifecycle Manager and Password Safe:

  1. Replace or harden password-based workflows with certificate-based admin access (mTLS) for vault-to-target, jump host, and session proxy connections
  2. Auto-renew appliance/web console and connector certificates to prevent outages under the upcoming 47-day TLS lifetime
  3. Provision short-lived client certs for admins, services, and connectors, with policy-driven rotation
  4. Maintain a unified, auditable certificate inventory

The result is fewer outages, stronger Zero Trust controls, faster incident response via instant revoke, and simpler compliance across PAM infrastructure.

The customer needs at least one active DigiCert sensor to securely establish and manage the connection to the Password Safe secrets manager instance. For fault-tolerant connectivity, multiple sensors can be used to manage the connector. If one of the sensors fails, the connector automatically fails over to another sensor.

What it does

Why it matters

How it integrates

Resources