Set up DigiCert Trust Lifecycle Manager

Trust Lifecycle Manager is DigiCert's managed PKI platform. Its certificate profiles can take a SAN value straight from the SCEP request while holding the subject fixed, which is the combination Firezone needs.

Before you begin

You need a Trust Lifecycle Manager tenant with an issuing CA, and an MDM that enrolls certificates over SCEP.

1. Prepare the issuing CA

The issuing CA you select must have Allow CA to decrypt and sign SCEP packets enabled. A CA without it cannot serve SCEP enrollment at all.

2. Create the certificate profile

Go to Policies → Certificate profiles and select Create profile from template. Use Generic Device Certificate, or the Intune SCEP template if you provision through Intune.

On Primary options, set the enrollment method to SCEP and pick your issuing CA. Profile names are limited to 34 characters and should avoid special characters.

Then, under Subject DN and SAN fields, every field takes its value from either SCEP request or Fixed value. Set them as follows:

FieldSourceValue
Subject DN: Common NameFixed valuedev.firezone.device-trust
SAN: URIsSCEP requestSupplied by the MDM at enrollment

A profile must have at least one field whose value comes from the SCEP request. Firezone fixes the common name, so the URI SAN is the field that satisfies that requirement. Do not set both to Fixed value.

The URIs attribute (extensions.san.uris[]) accepts multiple values, so a certificate can carry both an MDM inventory ID and a serial number, which is what the provider guides ask for.

3. Collect the SCEP URL and challenge

After saving the profile, copy its SCEP Server URL.

For the challenge, the Authentication method chosen on Primary options decides what your MDM needs:

  • Dynamic enrollment code: the MDM integration supplies the code itself. In Jamf Pro this appears as the Dynamic-DigiCert Trust Lifecycle Manager challenge type.
  • Global enrollment code: set Challenge Type to Static and enter the enrollment code in both Challenge and Verify Challenge.

4. Configure your MDM's SCEP profile

Point the profile at the SCEP Server URL and challenge from step 3, then have it request a supported device identifier as a URI SAN, such as firezone://serial/C02ABC123. The provider guides for Intune, Iru and Jamf Pro give the variable syntax each one uses to populate it.

Note that DigiCert's own Jamf example sets the payload subject to CN=$SERIALNUMBER. Firezone needs the fixed common name instead, which the profile applies from step 2.

Inspect an issued certificate before deploying broadly, and confirm it carries both the fixed common name and the URI SAN with a real device value. A profile can look correct while the CA rewrites the subject or drops the requested SAN.

5. Collect the CA certificates

Export the root and intermediate CA certificates for your issuing CA. These are the files you add to Firezone.

Next step

Add the root and intermediate public certificates to Firezone as trust anchors, in step 2 of Set up Device Trust.


Need help? See all support options.