Set up DigiCert Trust Lifecycle Manager
Trust Lifecycle Manager is DigiCert's managed PKI platform. Its certificate profiles can take a SAN value straight from the SCEP request while holding the subject fixed, which is the combination Firezone needs.
Before you begin
You need a Trust Lifecycle Manager tenant with an issuing CA, and an MDM that enrolls certificates over SCEP.
1. Prepare the issuing CA
The issuing CA you select must have Allow CA to decrypt and sign SCEP packets enabled. A CA without it cannot serve SCEP enrollment at all.
2. Create the certificate profile
Go to Policies → Certificate profiles and select Create profile from template. Use Generic Device Certificate, or the Intune SCEP template if you provision through Intune.
On Primary options, set the enrollment method to SCEP and pick your issuing CA. Profile names are limited to 34 characters and should avoid special characters.
Then, under Subject DN and SAN fields, every field takes its value from either SCEP request or Fixed value. Set them as follows:
| Field | Source | Value |
|---|---|---|
| Subject DN: Common Name | Fixed value | dev.firezone.device-trust |
| SAN: URIs | SCEP request | Supplied by the MDM at enrollment |
A profile must have at least one field whose value comes from the SCEP request. Firezone fixes the common name, so the URI SAN is the field that satisfies that requirement. Do not set both to Fixed value.
The URIs attribute
(extensions.san.uris[])
accepts multiple values, so a certificate can carry both an MDM inventory ID
and a serial number, which is what the provider guides ask for.
3. Collect the SCEP URL and challenge
After saving the profile, copy its SCEP Server URL.
For the challenge, the Authentication method chosen on Primary options decides what your MDM needs:
- Dynamic enrollment code: the MDM integration supplies the code itself. In Jamf Pro this appears as the Dynamic-DigiCert Trust Lifecycle Manager challenge type.
- Global enrollment code: set Challenge Type to Static and enter the enrollment code in both Challenge and Verify Challenge.
4. Configure your MDM's SCEP profile
Point the profile at the SCEP Server URL and challenge from step 3, then have
it request a supported
device identifier as a URI
SAN, such as firezone://serial/C02ABC123. The provider guides for
Intune, Iru and
Jamf Pro give the variable syntax each one uses to
populate it.
Note that DigiCert's own Jamf example sets the payload subject to
CN=$SERIALNUMBER. Firezone needs the fixed common name instead, which the
profile applies from step 2.
Inspect an issued certificate before deploying broadly, and confirm it carries both the fixed common name and the URI SAN with a real device value. A profile can look correct while the CA rewrites the subject or drops the requested SAN.
5. Collect the CA certificates
Export the root and intermediate CA certificates for your issuing CA. These are the files you add to Firezone.
Next step
Add the root and intermediate public certificates to Firezone as trust anchors, in step 2 of Set up Device Trust.
Need help? See all support options.