---
title: Manage Certificates with DigiCert IoT Trust Manager Integration
slug: manage-certificates-with-digicert-iot-trust-manager-integration
docTags: 
createdAt: 2024-09-18T16:39:23.877Z
---

:::hint{type="info"}
**Note**: The DigiCert IoT Trust Manager integration is available for Manufacturing Connect 2.21.0 and later.
:::

In this use case, you will integrate DigiCert IoT Trust Manager with Manufacturing to manage certificates for all your edge devices.&#x20;

- First, you will set up the DigiCert IoT Trust Manager Integration from your Manufacturing Connect Admin Console.&#x20;
- Then, you will configure the Certificate Authority (CA) for both Manufacturing Connect and Manufacturing Connect Edge devices.&#x20;
- Finally, you will verify if the DigiCert certificates are applied to your Manufacturing Connect Edge devices.

# Before You Begin

- Ensure you have at least one Edge device activated in your Manufacturing Connect. See [Activate an Edge Device](docId\:M2dU1twvNe9kZ1he-r222) for more information.
- Ensure you have access to the DigiCert IoT Trust Manager to obtain the required configuration parameters. If you are not a DigiCert IoT Trust Manager customer, visit [https://www.digicert.com/device-trust-manager](https://www.digicert.com/device-trust-manager) to sign up.&#x20;

# Step 1: Access DigiCert IoT Trust Manager Integration&#x20;

**To access the DigiCert IoT Trust Manager integration pane:&#x20;**

1. Log in to the Manufacturing Connect Admin Console at the following URL: **https\://\[MC IP address]:8446**.
2. From the Navigation panel, select **Integration**.
   Integration's *Kafka* pane by default appears.
3. From Integration's navigation sub-panel, select **DigiCert**.
   Integration's *DigiCert&#x20;*&#x70;ane appears.
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/90tt0spdAopYegE5HDkGF_image.png" size="80" width="1236" height="714" position="center" caption="DigiCert pane" showCaption="true"}

You will see three fields for configuration: **URL**, **Profile ID**, and **Passcode**. By default, placeholder values will be in these fields. In the next step, you will retrieve these configuration parameters from the DigiCert IoT Trust Manager.

# Step 2: Set up Integration with DigiCert

**To retrieve the URL, Profile ID, and Passcode parameters from the DigiCert IoT Trust Manager, follow the steps below:**

1. Open a new browser and log in to your **DigiCert ONE&#x20;**&#x70;latform at [https://one.digicert.com.](https://one.digicert.com/)
2. Select *IoT Trust Manager* from the switcher icon at the top right corner.&#x20;
3. From the navigation panel, select **Enrollment configurations**.
   The *Enrollment profiles* page opens.
4. Click the desired **Enrollment profile name**. The *Enrollment profile details* page appears.
   **Note:**&#x20;
   1\. For this use case, the enrollment profile is already created. See [Create an enrollment profile](https://docs.digicert.com/en/iot-trust-manager/enrollment-profiles/create-enrollment-profiles/create-an-enrollment-profile.html) to learn more.&#x20;
   2\. Set up the enrollment profile method for REST API, as it is the integrated method with Manufacturing Connect.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/D4IJni9R3iq1c6on2uuwF_image.png)
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/0_-JVj8Bz-mOG1qsASbjr_image.png" size="60" width="771" height="458" position="center" caption="Certificate enrollment methods dialog box" showCaption="true"}
5. Configure the keypair generation settings to be used.
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/qMr3rarFgo9vS1zmp3wY2_image.png" size="60" width="690" height="324" position="center" caption="Keypair generation settings" showCaption="true"}
6. After creating the Enrollment Profile, edit the enrollment profile. Scroll to the bottom of the Enrollment Profile details page and create a passcode.&#x20;
   Copy and save this passcode to a secure location.&#x20;
   See also [Enrollment Passcodes](https://docs.digicert.com/en/iot-trust-manager/enrollment-passcodes.html) to generate the passcode for authenticating to the REST API.&#x20;
7. You can retrieve the *URL*, *Profile ID*, and *Passcode* parameters from the *Enrollment profile details* page as follows:
   - **URL:** This is the DigiCert server URL. Navigate to *API&#x20;*&#x73;ection and copy **Request URL** link.
     ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/y7za2LNooaM6FjE6gUfdS_image.png "Enrollment profile details page - API section")
   - **Profile ID:&#x20;**&#x43;opy this from the *Enrollment profile ID*.
     ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/xtJeJ4zAPemP3eAdzaUwr_image.png "Enrollment profile details page")
   - **Passcode:** This was generated and shown when you created the passcode above.&#x20;
8. Enter the retrieved parameters into the *DigiCert&#x20;*&#x49;ntegration fields in the Manufacturing Connect Admin Console.
9. Click **Save**.
   A confirmation message will appear indicating that the DigiCert settings are saved.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/IjJ6BBGgZCr1aZHCfVt7c_image.png "DigiCert Integration Page")

# Step 3: Set up Certificate Authority for Manufacturing Connect

**To set up the certificate authority for Manufacturing Connect:**

1. From the Manufacturing Connect Admin Console, navigate to **Settings&#x20;**>**&#x20;Entry Points**.
2. From the *Entry Points* panel, choose the **DigiCert&#x20;**&#x6F;ption.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/42jZA3peBJ9Ng4mDUvqp8_image.png "Entry Points Settings Page")
3. Click **Save**.
4. The *Page Reload Required* dialog box appears. Click **Yes,&#x20;**&#x61;nd refresh the page.
   SSL settings are saved and the page is reloaded after updating the certificate settings for proper system functioning.

# Step 4: Issue a certificate for Manufacturing Connect Edge from Manufacturing Connect User UI

**To issue a certificate for Manufacturing Connect Edge device from Manufacturing Connect User UI:**

1. Log in to Manufacturing Connect and navigate to **Certificates&#x20;**&#x74;ab.
   The list of current certificates for your edge devices along with their details appears.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/Mqyr0hqwiKXgxhxeAcEDn_image.png "Certificates tab")
2. To issue a new certificate, click the **Action&#x20;**&#x62;utton for an edge device and selec&#x74;**&#x20;Issue a new certificate**.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/SpDQUs4RzkB0-kufJ8pte_image.png "Certificates Management pane")
3. From the *Issue a new certificate&#x20;*&#x64;ialog box, configure the following:
   - **Certificate Authority:** From the dropdown menu, select **DigiCert IoT Trust Manager&#x20;**&#x61;s the new certificate authority.
   - (Optional) Keep default settings for the other fields.
4. Click **ISSUE CERTIFICATE**.&#x20;
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/ef7o58qX9BJ6UfRcwqfgE_image.png" size="50" width="953" height="948" position="center" caption="Issue a new certificate dialog box" showCaption="true"}

The certificate has been added to the Manufacturing Connect Edge device along with the issuer details.

# Step 5: Verify Certificate for Manufacturing Connect Edge Device

**To verify that the certificate has been added to the Manufacturing Connect Edge device:**

1. Navigate to the specific edge device instance where you applied the certificate and log in.
2. Go to **Systems&#x20;**> **Network&#x20;**&#x61;nd find the *Device Certificates* panel.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/hCQCuuC5V4vsI8mcP-lVA_image.png "Systems > Network  page")

You can verify the certificate details and ensure that the new certificate has been added.

:::hint{type="info"}
**Note:** Refresh the screen if necessary to see the updated certificate and issuer details. Reboot is required to see the certificate update on browser tab.&#x20;
:::

