Trust Lifecycle Manager: Certificate Management as a Jigsaw Puzzle

29 Jul 2026 | Jindřich Zechmeister

Certificate management follows the same old pattern in many organizations: an Excel spreadsheet tracking expiration dates, email reminders nobody reads, and the occasional panic when a certificate expires on a production service no one even knew existed. DigiCert Trust Lifecycle Manager (TLM) changes that story—and perhaps the best way to understand how is through a simple metaphor: it works like building blocks. Instead of a single rigid tool that forces you into a predefined workflow, you get a set of flexible components that can be assembled into exactly the solution you need for each use case.

The Core of the Puzzle: Orchestrator and Discovery Agent

DigiCert Trust Lifecycle Manager is a platform for centralized certificate management that covers their entire lifecycle — from issuance through deployment, monitoring, renewal to revocation. Instead of dozens of portals, manual requests, and Excel sheets, you get a single place from which you can see and manage certificates across the entire organization, whether it concerns internal servers, publicly accessible websites, cloud infrastructure, or network devices. And that's why, at the heart of this platform, stand two key components.

Automation Orchestrator is the brain of the entire system. It defines the rules — who, what, when, and how certificates are issued, renewed, and deployed — and then TLM takes care of the entire lifecycle by itself, without the need for manual interventions.

Discovery Agent is the eyes of the entire system. It combs through your infrastructure looking for certificates you might not even be aware of — forgotten, manually issued, issued outside company policy. Thanks to this, TLM becomes not only a tool for automation but also a central overview of what is actually running on your network.

This pair is the foundation – but the real power comes when you start composing individual automations yourself.

Three Pieces You Choose for Each Automation

For each individual automation in TLM, you incrementally compose three layers:

1. Certificate Source

You are not tied to a single certificate authority. You choose where the certificates are coming from:

Private CA – for internal services, internal PKI, where you don't want (or can't) go outside.

Public CA – where you need a certificate trusted for the public internet.

Both can be combined within a single platform according to the needs of a specific project or team.

2. Certificate Profile

You determine what certificates should be issued within the given automation — what type, what parameters, what validity, what policy. The profile acts as a template that automation uses repeatedly and consistently, so there is no chance two administrators would issue certificates with different parameters "depending on their mood".

3. Deployment Method

This is the piece where it is most decided how "maintenance-free" the automation will be. TLM offers several paths, and each is suitable for a different situation.

Agent is installed directly on the server and takes care of the entire certificate lifecycle locally — monitors expiration, requests the certificate itself, deploys it to the correct storage, and in case of need, restarts or alerts dependent services for a restart. It is the most direct and reliable option for servers where you can afford to install the agent (IIS, Apache, Nginx, Tomcat, and others).

Sensor is an option for situations where installing a full-fledged agent is not desirable or possible — typically for network devices, appliances, load balancers, or legacy systems. The sensor primarily discovers and monitors certificates; deployment then occurs through the appropriate connector or API without the need to install anything on the target system.

PFX Export is the simplest and most versatile route — TLM generates a package with the certificate and private key, which you download or is automatically delivered (e.g., to storage, a shared drive, or a script). It is suitable where you want to link deployment with your own automation or CI/CD pipeline, or where an agent or sensor does not make sense.

SCEP/EST cover the world of network devices and client endpoints — firewalls, routers, VPN concentrators, printers, IoT devices, mobile devices managed via MDM. The device requests the certificate itself through a standardized protocol, TLM automatically issues it based on the defined profile and hands it back without any manual intervention from an administrator.

ACME is then the choice for modern, DevOps-oriented environments — allowing fully automated certificate issuance and renewal through standard ACME clients, similar to how you are used to from public CAs but connected to your organization's policies and profiles.

API and Integrations complete the picture for cases where you want to embed deployment directly into your own tools, orchestration platforms, or internal portals.

Thanks to this breadth of options, the exact deployment method is chosen for each server or device that corresponds to its nature — without compromises like "we have to do it manually because the tool only supports one path".

Three simple choices — source, profile, deployment — and you have automation tailored precisely to the specific server, application, or team. No automation needs to look the same as a previous one.

Expanding Pieces: Connectors

The basic functionality (agent, sensor) can be further expanded with connectors that integrate TLM with other systems in your infrastructure.

MS CA – integration with Microsoft Certificate Authority if you are already running an internal PKI in a Microsoft environment.

Public Clouds – native connectors for Azure, AWS, and Google Cloud, enabling certificate management directly where your cloud infrastructure is actually running.

Thanks to connectors, TLM doesn't act like an isolated tool next to your infrastructure, but as a layer that naturally integrates with it — whether you have internal PKI, multicloud, or both.

Domain Validation that You Simply Don’t Have to Deal With

One of the most annoying parts of managing public certificates is domain control validation (DCV). TLM removes this pain by supporting DCV automation through more than 160 DNS providers — including Czech Zoner. Just connect a DNS account, and domain validation occurs fully automatically, without manual record insertion and without waiting to see if the DCV was really successful.

Why the Puzzle Metaphor Fits

The strength of the DigiCert Trust Lifecycle Manager is not that it does one thing exceedingly well. It is that it gives you pieces — certificate sources, profiles, deployment methods, connectors, automated DCV — from which you can assemble exactly what your environment needs. A small company with a few servers and a large enterprise with a multicloud infrastructure and thousands of certificates can thus use the same platform, just with differently assembled pieces.

The result is a system that grows with you: you start with simple automation for a few servers and gradually add connectors, profiles, and certificate sources according to how your infrastructure evolves — without the need to change the platform or start from scratch.

Want to find out how certificate automation with DigiCert Trust Lifecycle Manager would look in your environment? Contact us at SSLmarket.com, we would be happy to show you how to tailor this puzzle for you.


Ing. Jindřich Zechmeister
TLS certificate specialist
Certificated Sales Expert Plus
e-mail: jindrich.zechmeister(at)zoner.com