---
title: Manage Certificates with DigiCert IoT Trust Manager Integration
slug: edgemanager/manage-certificates-with-digicert-iot-trust-manager-integration
docTags: 
createdAt: 2024-08-01T18:35:39.308Z
---

:::hint{type="info"}
**Note**: The DigiCert IoT Trust Manager integration is available for Litmus Edge Manager 2.21.0 and later.
:::

In this use case, you will integrate DigiCert IoT Trust Manager with Litmus Edge Manager (LEM) to manage certificates for all your edge devices.&#x20;

- First, you will set up the DigiCert IoT Trust Manager Integration from your Litmus Edge Manager Admin Console.&#x20;
- Then, you will configure the Certificate Authority (CA) for both Litmus Edge Manager and Litmus Edge (LE) devices.&#x20;
- Finally, you will verify if the DigiCert certificates are applied to your Litmus Edge devices.

# Before You Begin

- Ensure you have at least one Edge device activated in your Litmus Edge Manager. See [Activate an Edge Device](docId\:tDJ648wJgATVqzyx79UwB) for more information.
- Ensure you have access to the DigiCert IoT Trust Manager to obtain the required configuration parameters. If you are not a DigiCert IoT Trust Manager customer, visit [https://www.digicert.com/device-trust-manager](https://www.digicert.com/device-trust-manager) to sign up.&#x20;

# Step 1: Access DigiCert IoT Trust Manager Integration&#x20;

**To access the DigiCert IoT Trust Manager integration pane:&#x20;**

1. Log in to the Litmus Edge Manager Admin Console at the following URL: **https\://\[LEM IP address]:8446**.
2. From the Navigation panel, select **Integration**.
   Integration's *Kafka* pane by default appears.
3. From Integration's navigation sub-panel, select **DigiCert**.
   Integration'&#x73;*&#x20;DigiCert&#x20;*&#x70;ane appears.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/uvNWw2-L0ozYiP8jAP56j_image.png "DigiCert IoT Trust Manager Integration pane")

You will see three fields for configuration: **URL**, **Profile ID**, and **Passcode**. By default, placeholder values will be in these fields. In the next step, you will retrieve these configuration parameters from the DigiCert IoT Trust Manager.

# Step 2: Set up Integration with DigiCert

**To retrieve the URL, Profile ID, and Passcode parameters from the DigiCert IoT Trust Manager, follow the steps below:**

1. Open a new browser and log in to your **DigiCert ONE&#x20;**&#x70;latform at [https://one.digicert.com.](https://one.digicert.com/)
2. Select *IoT Trust Manager* from the switcher icon at the top right corner.&#x20;
3. From the navigation panel, select **Enrollment configurations**.
   The *Enrollment profiles* page opens.
4. Click the desired **Enrollment profile name**. The *Enrollment profile details* page appears.
   **Note:**&#x20;
   1\. For this use case, the enrollment profile is already created. See [Create an enrollment profile](https://docs.digicert.com/en/iot-trust-manager/enrollment-profiles/create-enrollment-profiles/create-an-enrollment-profile.html) to learn more.&#x20;
   2\. Set up the enrollment profile method for REST API, as it is the integrated method with Litmus Edge Manager.
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/0_-JVj8Bz-mOG1qsASbjr_image.png" size="60" width="771" height="458" position="center" caption="Certificate enrollment methods dialog box" showCaption="true"}
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/UNVpEkSuSgUHShwUnahJU_image.png "Enrollment profiles page")
5. Configure the keypair generation settings to be used.
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/qMr3rarFgo9vS1zmp3wY2_image.png" size="60" width="690" height="324" position="center" caption="Keypair generation settings" showCaption="true"}
6. After creating the Enrollment Profile, edit the enrollment profile. Scroll to the bottom of the Enrollment Profile details page and create a passcode. Copy and save this passcode to a secure location. See also [Enrollment Passcodes](https://docs.digicert.com/en/iot-trust-manager/enrollment-passcodes.html) to generate the passcode for authenticating to the REST API.&#x20;
7. You can retrieve the *URL*, *Profile ID*, and *Passcode* parameters from the *Enrollment profile details* page as follows:
   - **URL:** This is the DigiCert server URL. Navigate to *API&#x20;*&#x73;ection and copy **Request URL** link.
     ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/y7za2LNooaM6FjE6gUfdS_image.png "Enrollment profile details page - API section")
   - **Profile ID:&#x20;**&#x43;opy this from the *Enrollment profile ID*.
     ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/xtJeJ4zAPemP3eAdzaUwr_image.png "Enrollment profile details page")
   - **Passcode:** This was generated and shown when you created the passcode above.&#x20;
8. Enter the retrieved parameters into the *DigiCert&#x20;*&#x49;ntegration fields in the Litmus Edge Manager Admin Console.
9. Click **Save**.
   A confirmation message will appear indicating that the DigiCert settings are saved.
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/OCv2nla0_iZHk2KAKrFoZ_image.png" size="80" width="1472" height="1318" position="center" caption="DigiCert Integration Page" showCaption="true"}



# Step 3: Set up Certificate Authority for Litmus Edge Manager

**To set up the certificate authority for Litmus Edge Manager:**

1. From the Litmus Edge Manager Admin Console, navigate to **Settings&#x20;**>**&#x20;Domain/SSL**.
2. From the *SSL settings* panel, choose the **DigiCert&#x20;**&#x6F;ption.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/N7YsiL41qOa36WfyIqH6k_image.png "Domain/SSL Settings Page")
3. Click **Save**.
4. The *Page Reload Required* dialog box appears. Click **Yes,&#x20;**&#x61;nd refresh the page.
   SSL settings are saved and the page is reloaded after updating the certificate settings for proper system functioning.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/3ns5W8acqQlgodf0s-9N7_image.png "Page Reload Required dialog box")

# Step 4: Issue a certificate for Litmus Edge from Litmus Edge Manager User UI

**To issue a certificate for Litmus Edge device from Litmus Edge Manager User UI:**

1. Log in to Litmus Edge Manager and navigate to **Certificates&#x20;**&#x74;ab.
   The list of current certificates for your edge devices along with their details appears.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/wor5cS1D7MATTjOAUYzuD_image.png "Certificates tab")
2. To issue a new certificate, click the **Action&#x20;**&#x62;utton for an edge device and selec&#x74;**&#x20;Issue a new certificate**.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/GGqFNZ4h6Usw-8rHlAT6-_image.png "Certificates Management pane")
3. From the *Issue a new certificate&#x20;*&#x64;ialog box, configure the following:
   - **Certificate Authority:** From the dropdown menu, select **DigiCert IoT Trust Manager&#x20;**&#x61;s the new certificate authority.
   - (Optional) Keep default settings for the other fields.
4. Click **ISSUE CERTIFICATE**.&#x20;
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/xPkOg_15fwsV_wEmMcPSi_image.png" size="60" width="539" height="513" position="center" caption="Issue a new certificate dialog box" showCaption="true"}

The certificate has been added to the Litmus Edge device along with the issuer details.

![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/1xbvMltid-RiwVldShWP2_image.png "Certificates tab")

# Step 5: Verify Certificate for Litmus Edge Device

**To verify that the certificate has been added to the Litmus Edge device:**

1. Navigate to the specific edge device instance where you applied the certificate and log in.
2. Go to **Systems&#x20;**> **Network&#x20;**&#x61;nd find the *Device Certificates* panel.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/_zwi_rodp7M3kokbX3fqJ_image.png "Systems > Network  page")

You can verify the certificate details and ensure that the new certificate has been added.

:::hint{type="info"}
**Note:** Refresh the screen if necessary to see the updated certificate and issuer details. Reboot is required to see the certificate update on browser tab.&#x20;
:::

