Skip to main content

DigiCert

SecTrail CM integrates with the DigiCert API service to centrally manage ordering, renewal, and revocation of SSL/TLS certificates.

Connection Requirements​

RequirementDetailDescription
ProtocolREST API (HTTPS)DigiCert REST API is used
API Endpointhttps://www.digicert.com/services/v2/DigiCert API v2 service
AuthenticationAPI Key AuthenticationAuthentication with API Key
User PermissionDigiCert API AccessCertificate order, query, and management permission

Automatic Operations​

SecTrail CM automatically performs the following operations on DigiCert:

  1. Certificate Order: Creating a new SSL/TLS certificate request
  2. Order Query: Viewing the status of existing certificate orders
  3. Certificate Renewal: Renewing certificates about to expire
  4. Certificate Revocation: Revoking certificates that are no longer used or compromised
  5. Certificate Download: Automatic downloading of issued certificates

Configuration Steps​

1. Add DigiCert Profile​

Navigate to Integrations > DigiCert and click the Add New DigiCert Profile button:

Add DigiCert Profile

Enter the following information:

  • Name: Give a descriptive name for the profile
  • URL: DigiCert API endpoint address
    • https://www.digicert.com/services/v2/
  • API Key: Your DigiCert API key
  • Proxy: Proxy usage (Enable/Disable)

Click Submit button to save the profile.

API Key

You can create your DigiCert API key from the DigiCert account management panel. Ensure that the API key has sufficient permissions.

2. View DigiCert Accounts​

After adding a profile, it will be displayed in the Integrations > DigiCert list:

DigiCert Account List

The list screen displays the following information:

  • Name: Profile name
  • URL: API endpoint address
  • Domain Details: Associated domain information

Account Operations​

The following operations can be performed for each profile:

  • Refresh: Refresh profile information
  • Edit: Edit profile settings
  • Delete: Delete profile

View Certificate Orders​

After DigiCert integration, you can view all your certificate orders:

Navigate to Integrations > DigiCert > Orders:

DigiCert Orders

Order Information​

FieldDescription
Created AtCertificate request date and time
OrderDigiCert order number
Common NameDomain name where the certificate will be used
ProductCertificate product type (e.g., RapidSSL Standard DV)
StatusCertificate status (Issued, Expired, Renewed, Revoked)
DaysRemaining/elapsed validity period (in days)

Certificate Statuses​

  • Renewed: Certificate renewed and active
  • Expired: Certificate expired (negative day value)
  • Revoked: Certificate revoked
  • Issued: Certificate successfully issued and active

Certificate Management​

Download Certificate (Fetch)​

To download issued certificates:

  1. Navigate to Integrations > DigiCert > Orders
  2. Find the certificate you want to download
  3. Click Fetch Certificate button
  4. Certificate is automatically downloaded and added to the system
Automatic Download

Certificates issued by DigiCert can be automatically downloaded to the system. This feature eliminates the need for manual downloading.

Certificate Renewal (Renew)​

To renew certificates about to expire:

  1. Navigate to Integrations > DigiCert > Orders
  2. Find the certificate you want to renew
  3. Click Renew Certificate button
  4. Confirm the renewal
Renewal Timing

It is recommended to start renewing certificates at least 30 days before the expiration date. Negative values in the "Days" column indicate expired certificates.

Certificate Revocation (Revoke)​

To revoke compromised or no longer used certificates:

  1. Navigate to Integrations > DigiCert > Orders
  2. Find the certificate you want to revoke
  3. Click Revoke Certificate button
  4. Confirm the revocation
Revocation Process

Once a certificate is revoked, this action cannot be undone. A revoked certificate can no longer be used.