Automating Certificate Management with Digicert
By F5 DevCentral Community
Key Concepts
- PKI (Public Key Infrastructure): The framework of roles, policies, hardware, and software needed to create, manage, distribute, use, store, and revoke digital certificates.
- Certificate Lifecycle Management (CLM): The end-to-end process of managing digital certificates from issuance and deployment to renewal and revocation.
- Domain Control Validation (DCV): The process of proving ownership or control over a domain, which is a prerequisite for certificate issuance.
- Connectors: Software components within the DigiCert ONE platform that interface with external infrastructure (like F5 BIG-IP or Microsoft PKI) to pull inventory and automate tasks.
- Network Sensors: Strategically deployed agents that facilitate communication between the DigiCert platform and the enterprise network to perform discovery and automation.
- Algorithm Agility: The ability of a PKI platform to adapt to different cryptographic algorithms (RSA, ECC, and Post-Quantum Cryptography) without requiring a complete infrastructure overhaul.
- Trust Lifecycle Manager (TLM): The central dashboard/platform used for inventory management, certificate status monitoring, and automation orchestration.
1. The Challenge: Shortened Certificate Lifespans
The industry is shifting toward significantly shorter certificate expiration periods. This trend creates two primary pain points:
- Operational Velocity: Manual processes for certificate renewal and domain revalidation are no longer sustainable. Traditional methods of coordinating between PKI and DNS teams are too slow and prone to breaking.
- Visibility Gaps: Organizations often lack a unified view of their cryptographic assets, leading to expired certificates and service outages.
2. The Three-Phase Methodology
DigiCert advocates for a structured approach to managing the certificate landscape:
- Discovery: Identifying all existing certificates and crypto assets across the infrastructure. "You don't know what you know until you know everything."
- Administration: Centralizing the management of these assets, including identifying duplicates and monitoring key pairs across multiple sockets.
- Automation: Implementing "wash, rinse, repeat" workflows to handle renewals and deployments without manual intervention.
3. Integration Framework: F5 BIG-IP and DigiCert ONE
The integration between F5 BIG-IP and DigiCert ONE is designed to reduce the reliance on custom scripts and manual administrative tasks.
- Deployment: The process involves deploying network sensors that communicate outbound to the DigiCert platform. This allows for a "one-to-many" model where a single sensor can manage multiple appliances and services.
- Workflow:
- The sensor queries the F5 BIG-IP for inventory and status.
- When a renewal is needed, the platform triggers the creation of a key pair and CSR (Certificate Signing Request).
- DigiCert handles the domain revalidation on the backend.
- Once validated, the certificate is pushed back to the F5, which installs it automatically.
- Efficiency: This process can be deployed in production environments in as little as 30–40 minutes.
4. Post-Quantum Cryptography (PQC) and Modernization
Addressing the evolution of encryption, DigiCert emphasizes Algorithm Agility:
- Phased Adoption: Rather than forcing an immediate transition, the platform allows for a phased model where customers can test PQC in private environments.
- Flexibility: The platform supports existing standards (RSA, ECC) while remaining ready to integrate new hierarchies as they emerge. Administrators can update policies within the platform to adopt new algorithms without re-architecting their entire deployment.
5. Organizational Silos and Governance
A significant hurdle in large enterprises is the disconnect between teams (e.g., DNS, PKI, and Legal).
- Business Units: To manage internal politics and security, DigiCert ONE allows for the creation of "business units" within the account. This acts as a "white picket fence," ensuring teams only have visibility into the assets relevant to their specific domain while maintaining centralized oversight.
- Centralized Control: The goal is to move away from "everything admins" (where one person controls all infrastructure to prevent loss of control) toward a managed, role-based automation model.
6. Notable Quotes
- "Automation has two sides of the same coin. It has the certificate piece... but during that you have the revalidation piece and that can stop the process." — Frank Agto Machado
- "I tell customers, you'll get an inventory whether you like it or not because we're going to start talking to things." — Frank Agto Machado
- "We don't want to eliminate you going to your F5 to check the status of a cert, but we do check the installation at the end." — Frank Agto Machado
Synthesis and Conclusion
The transition to automated certificate management is no longer optional due to the shortening of certificate lifespans. By utilizing a combination of network sensors and connectors, organizations can bridge the gap between their infrastructure (like F5 BIG-IP) and their certificate authority. The key takeaway is that successful PKI management requires a shift from manual, siloed tasks to a unified, automated lifecycle that prioritizes discovery, centralized administration, and the flexibility to adapt to future cryptographic standards like Post-Quantum Cryptography.
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.
Related Videos

Quantum Risk And Bitcoin: Preparing For A Post-Quantum World
ARK Invest

Everything You Trust Online Could Break — F5 Labs on Q-Day
F5 DevCentral Community

Agentic Attackers, LLM Leaderboards, and Q-Day: A Conversation with F5 Labs
F5 DevCentral Community

One App at a Time: DigiCert's Practical Playbook for the Post-Quantum Transition
F5 DevCentral Community

Keyfactor on Cryptographic Discovery: Why Knowing What You Have Is Step One
F5 DevCentral Community

What Quantum Safe Is and Why We Need It to Stay Secure
John Savill's Technical Training

Low-Latency Security for Time-Critical Grid Communication with Shabnam Saderi, Research Assistant
Canadian Institute for Cybersecurity (CIC)