Trust Lifecycle Manager as a puzzle: Assemble certificate automation according to your own infrastructure
Sep 17, 2026 | Jindřich Zechmeister
Certificate automation does not have to take just one predetermined form. DigiCert Trust Lifecycle Manager (TLM) acts as a central management layer that links certificate issuance, automatic domain validation and deployment to target systems. The configured process then ensures the issuance, regular renewal and distribution of certificates, minimising the need for repeated manual intervention.
TLM as the orchestrator of the entire process
Trust Lifecycle Manager is not just a tool for tracking used certificates. It functions as a central orchestrator of their lifecycle – connecting certification authorities, validation, issuance, and deployment of certificates to target systems.
The whole principle can be likened to a puzzle that an organization assembles according to its own infrastructure. First, they choose a certificate source, such as DigiCert, another public certification authority, or an internal Microsoft CA. Then they set the method for validating and issuing the certificate, and finally, determine the system into which the certificate should be deployed.
A simplified process might look like this: certification authority → TLM → validation via DNS → certificate issuance → deployment on a web server.
In another environment, TLM can connect a private certification authority with a network device, cloud service, or vault-type storage. It uses connectors to connect the individual parts of the infrastructure.
Information about certificates is concentrated in a central inventory, where the administrator monitors their status, validity, and location. TLM also coordinates their issuance, renewal, re-issuance, and deployment. Steps that the administrator would otherwise perform independently are thus connected into a single automated process.
It is enough to determine where the certificate should be obtained from, how it will be issued, and where it should be subsequently deployed. TLM manages the set procedure and can automatically repeat it during future renewals.
How to assemble automation in TLM
Automation in TLM can be likened to a puzzle made up of several connecting pieces. The administrator, based on the needs of their infrastructure, decides who will issue the certificate, how the necessary validation will occur, and where the certificate should be deployed. TLM connects these parts into one process and ensures its automatic repetition.
- Certificate source (Certification Authority) – first, it is necessary to choose the authority that will issue the certificate. Although TLM is a product of DigiCert, it is not limited to its certificates only. Using CA connectors, you can connect DigiCert CertCentral, Microsoft CA, AWS Private CA, Entrust, GlobalSign, Let’s Encrypt, Sectigo, or EJBCA. Thus, an organization can work with both public and private certification authorities from a single environment.
- Orchestration and central inventory – the center of the whole puzzle is TLM. In the central inventory, certificates can be searched, tracked, and monitored for their status and the endpoints where they are used. TLM also coordinates their issuance, renewal, re-issuance, and other operations. It thus has an overview of where to obtain the certificate, for which system it is intended, and what steps to follow.
- Automatic domain validation – before issuing a public TLS certificate, domain control or DCV must be validated. TLM supports DNS integrations for more than 150 providers, including Cloudflare, Azure DNS, Amazon Route 53, Google Cloud DNS, or CZECHIA.COM. Via DNS API, it can create the necessary validation record and complete the validation without manual administrator intervention. The same procedure can be used for future renewals of the certificate.
- Deployment into the target system – the last step is to determine where the issued certificate should be sent. The target could be a web or application server, load balancer, firewall, network device, cloud service, or secrets vault. Deployment can be automated using DigiCert agents, sensors, connectors, or supported protocols and APIs. Available integrations include AWS Certificate Manager, AWS load balancers, CloudFront, or Google Cloud Certificate Manager.
In a simpler environment, the whole process might look like this: certification authority → TLM → DNS validation → web server.
For internal infrastructure, individual pieces might be assembled like this: Microsoft CA → TLM → private certificate → firewall or internal server.
Once the administrator sets the entire process, TLM can use it for subsequent renewals. The issuance, validation, and deployment of the certificate are repeated automatically, eliminating the need to manually perform the same steps each time.
ACME remains one of the most important pieces
A notable role in automation is played by ACME (Automated Certificate Management Environment). This standardized protocol allows automating the issuance, validation, and renewal of certificates.
In a typical scenario, an ACME client installed on a web server, for example, sends a certificate request, performs the required validation, and then ensures its deployment. TLM offers its own ACME service with which compatible clients can communicate. This allows automating not only the first issuance of a certificate but also its regular renewal or re-issuance.
However, ACME is not the only option. TLM also supports other registration protocols and interfaces, such as SCEP, EST, CMP, or REST API. Thus, an organization can choose a method that suits specific devices and environments where ACME is not available or not suitable.
Connecting standardized protocols with agents, sensors, and connectors allows TLM to manage various parts of the certificate infrastructure. It is not just a tool for automatic HTTPS certificate renewal, but a platform for coordinating their entire lifecycle.
One setting for the entire certificate lifecycle
The main advantage of TLM is evident when the administrator connects the individual parts of the process into one workflow. They determine the certificate source, the method of its issuance and validation, and the target systems where it should be deployed. Once the procedure is created, TLM can use it repeatedly without the need to perform the same tasks manually.
Automation can include, for example:
- initial certificate issuance according to the set rules,
- domain validation via the connected DNS API,
- installation of the certificate on selected endpoints,
- timely renewal before its validity ends,
- reissuance or replacement of the certificate,
- monitoring certificates and related operations in the central inventory.
During renewal, the administrator no longer needs to manually reorder the certificate, create DNS validation records, download necessary files, or individually install them on the servers. TLM ensures the necessary steps according to the set workflow and delivers the new certificate to the designated place.
Thus, automation is not limited to extending the validity. It covers the entire process from issuance and validation through deployment to further renewal or replacement of the certificate. A properly configured workflow can therefore serve an organization throughout its lifecycle.
Why automation will become increasingly important
The need for automation is also growing in connection with the gradual reduction in the validity of public TLS certificates. While until recently a public TLS certificate could be valid for up to 398 days, since March 15, 2026, the maximum validity period according to CA/Browser Forum rules is gradually shortening:
- from March 15, 2026, to a maximum of 200 days,
- from March 15, 2027, to a maximum of 100 days,
- from March 15, 2029, to a maximum of 47 days.
As a result, certificates will need to be renewed, validated, and deployed much more frequently. For a single website, this process can still be managed manually. However, in an organization that manages hundreds of certificates on servers, load balancers, network devices, or cloud services, the workload and risk of human error quickly increase. Overlooking a single expiration can result in an unavailable service or a browser warning.
TLM, ACME, and other automation mechanisms will therefore play an increasingly important role. Instead of manually tracking individual certificates, they allow automating the entire process - from validation and issuance through deployment to timely renewal.
Automation according to your own infrastructure
Trust Lifecycle Manager can be viewed as an automation layer between certification authorities and systems that use certificates. The company does not need to adjust its infrastructure to a single method of issuing and deploying certificates.
Instead, they can build a process from the available pieces according to their own needs. They connect the used public or private CA, DNS provider, and then servers, clouds, load balancers, network devices, or vaults. TLM connects the individual parts into a common automated workflow.
A smaller environment might use, for example, ACME to automate certificate management on several servers. A larger company can combine multiple certification authorities, DNS APIs, agents, sensors, and cloud connectors. In both cases, the goal remains the same: to set up the process once and then automate the issuance, validation, deployment, and renewal of certificates.
With the design and deployment of the solution, SSLmarket, which offers DigiCert Trust Lifecycle Manager, can also assist and help choose a suitable form of automation based on the specific infrastructure. With the gradual shortening of TLS certificate validity, such an approach will become increasingly important.