How-To Guides
Litmus Edge Manager Admin Cons...

Manage Certificates with DigiCert IoT Trust Manager Integration

8min

Note: The DigiCert IoT Trust Manager integration is available for Litmus Edge Manager 2.21.0 and later.

In this use case, you will integrate DigiCert IoT Trust Manager with Litmus Edge Manager (LEM) to manage certificates for all your edge devices.

  • First, you will set up the DigiCert IoT Trust Manager Integration from your Litmus Edge Manager Admin Console.
  • Then, you will configure the Certificate Authority (CA) for both Litmus Edge Manager and Litmus Edge (LE) devices.
  • Finally, you will verify if the DigiCert certificates are applied to your Litmus Edge devices.

Before You Begin

  • Ensure you have at least one Edge device activated in your Litmus Edge Manager. See Activate an Edge Device for more information.
  • Ensure you have access to the DigiCert IoT Trust Manager to obtain the required configuration parameters. If you are not a DigiCert IoT Trust Manager customer, visit https://www.digicert.com/device-trust-manager to sign up.

Step 1: Access DigiCert IoT Trust Manager Integration

To access the DigiCert IoT Trust Manager integration pane:

  1. Log in to the Litmus Edge Manager Admin Console at the following URL: https://[LEM IP address]:8446.
  2. From the Navigation panel, select Integration. Integration's Kafka pane by default appears.
  3. From Integration's navigation sub-panel, select DigiCert. Integration's DigiCert pane appears.

    DigiCert IoT Trust Manager Integration pane
    DigiCert IoT Trust Manager Integration pane
    

You will see three fields for configuration: URL, Profile ID, and Passcode. By default, placeholder values will be in these fields. In the next step, you will retrieve these configuration parameters from the DigiCert IoT Trust Manager.

Step 2: Set up Integration with DigiCert

To retrieve the URL, Profile ID, and Passcode parameters from the DigiCert IoT Trust Manager, follow the steps below:

  1. Open a new browser and log in to your DigiCert ONE platform at https://one.digicert.com.
  2. Select IoT Trust Manager from the switcher icon at the top right corner.
  3. From the navigation panel, select Enrollment configurations. The Enrollment profiles page opens.
  4. Click the desired Enrollment profile name. The Enrollment profile details page appears. Note: 1. For this use case, the enrollment profile is already created. See Create an enrollment profile to learn more. 2. Set up the enrollment profile method for REST API, as it is the integrated method with Litmus Edge Manager.

    Certificate enrollment methods dialog box
    Certificate enrollment methods dialog box
    
    Enrollment profiles page
    Enrollment profiles page
    
  5. Configure the keypair generation settings to be used.

    Keypair generation settings
    Keypair generation settings
    
  6. After creating the Enrollment Profile, edit the enrollment profile. Scroll to the bottom of the Enrollment Profile details page and create a passcode. Copy and save this passcode to a secure location. See also Enrollment Passcodes to generate the passcode for authenticating to the REST API.
  7. You can retrieve the URL, Profile ID, and Passcode parameters from the Enrollment profile details page as follows:
    • URL: This is the DigiCert server URL. Navigate to API section and copy Request URL link.

      Enrollment profile details page - API section
      Enrollment profile details page - API section
      
    • Profile ID: Copy this from the Enrollment profile ID.

      Enrollment profile details page
      Enrollment profile details page
      
    • Passcode: This was generated and shown when you created the passcode above.
  8. Enter the retrieved parameters into the DigiCert Integration fields in the Litmus Edge Manager Admin Console.
  9. Click Save. A confirmation message will appear indicating that the DigiCert settings are saved.

    DigiCert Integration Page
    DigiCert Integration Page
    



Step 3: Set up Certificate Authority for Litmus Edge Manager

To set up the certificate authority for Litmus Edge Manager:

  1. From the Litmus Edge Manager Admin Console, navigate to Settings > Domain/SSL.
  2. From the SSL settings panel, choose the DigiCert option.

    Domain/SSL Settings Page
    Domain/SSL Settings Page
    
  3. Click Save.
  4. The Page Reload Required dialog box appears. Click Yes, and refresh the page. SSL settings are saved and the page is reloaded after updating the certificate settings for proper system functioning.

    Page Reload Required dialog box
    Page Reload Required dialog box
    

Step 4: Issue a certificate for Litmus Edge from Litmus Edge Manager User UI

To issue a certificate for Litmus Edge device from Litmus Edge Manager User UI:

  1. Log in to Litmus Edge Manager and navigate to Certificates tab. The list of current certificates for your edge devices along with their details appears.

    Certificates tab
    Certificates tab
    
  2. To issue a new certificate, click the Action button for an edge device and select Issue a new certificate.

    Certificates Management pane
    Certificates Management pane
    
  3. From the Issue a new certificate dialog box, configure the following:
    • Certificate Authority: From the dropdown menu, select DigiCert IoT Trust Manager as the new certificate authority.
    • (Optional) Keep default settings for the other fields.
  4. Click ISSUE CERTIFICATE.

    Issue a new certificate dialog box
    Issue a new certificate dialog box
    

The certificate has been added to the Litmus Edge device along with the issuer details.

Certificates tab
Certificates tab


Step 5: Verify Certificate for Litmus Edge Device

To verify that the certificate has been added to the Litmus Edge device:

  1. Navigate to the specific edge device instance where you applied the certificate and log in.
  2. Go to Systems > Network and find the Device Certificates panel.

    Systems > Network  page
    Systems > Network page
    

You can verify the certificate details and ensure that the new certificate has been added.

Note: Refresh the screen if necessary to see the updated certificate and issuer details. Reboot is required to see the certificate update on browser tab.