DigiCert ONE IoT Trust
Configure DigiCert ONE IoT Trust enrollment, choose an authentication method, request a device certificate, and review its status.
DigiCert ONE IoT Trust provides certificate enrollment and renewal for SIA Connect. Use it to request and manage a device certificate that can be used by other SIA Connect features for certificate-based authentication.
The Edge Portal configuration supports passcode, API key, and certificate-based enrollment authentication.
Before you begin
Prepare the following information in DigiCert ONE IoT Trust Manager:
- An active DigiCert ONE account with access to IoT Trust Manager
- The DigiCert ONE account identifier
- An enrollment profile ID
- A device name for this SIA Connect installation
- The authentication credential required by the enrollment profile
The authentication method selected in the Edge Portal must match the method configured for the DigiCert enrollment profile.
SIA Connect generates the Certificate Signing Request and key pair used for the issued certificate. Configure the enrollment profile so the device can provide the CSR or public key. See Device enrollment into DigiCert ONE IoT Trust Manager for certificate management for DigiCert ONE enrollment-profile preparation.
Open DigiCert ONE IoT Trust
- Sign in to the Edge Portal.
- Expand Tools in the sidebar.
- Select DigiCert ONE IoT Trust.
- Open the DigiCert ONE IoT Trust configuration if the configuration form is not already shown.
The page contains Account settings for enrollment and a read-only Status panel for the issued certificate.
Configure the account settings
| Parameter | Required | Accepted value | Description |
|---|---|---|---|
| Account | Yes | 1 to 120 characters | The account identifier from the DigiCert ONE tenant. |
| Enrollment profile | Yes | 1 to 120 characters | The DigiCert ONE IoT Trust enrollment profile used to issue the device certificate. |
| Device name | Yes | 1 to 120 characters | The device name submitted during enrollment. It can contain letters, numbers, spaces, dots, hyphens, and underscores. |
| Authentication | Yes | Passcode, API Key, or Certification | The authentication method configured for the enrollment profile. |
| Renewal window (days) | Yes | A whole number from 1 to 365
|
The number of days before certificate expiry when SIA Connect should request renewal. |
Choose an authentication method
Select the method used by the DigiCert ONE enrollment profile.
Passcode
Select Passcode when the enrollment profile authenticates the device with a passcode.
- The passcode must contain at least 6 characters.
- The passcode can contain no more than 64 characters.
API Key
Select API Key and enter the API key associated with the enrollment profile. The field cannot be empty.
Certification
Select Certification when the enrollment profile authenticates the request with an existing certificate and key.
| Credential | Required | Accepted file extensions |
|---|---|---|
| Authentication certificate | Yes |
.crt, .pem, .cer, or .der
|
| Authentication key | Yes |
.key, .pem, .der, or .pub
|
- Select Upload authentication certificate.
- Choose the certificate file.
- Select Upload authentication key.
- Choose the matching key file.
- Confirm that both selected filenames are displayed.
Save the configuration and enroll
- Review the account, enrollment profile, and device name.
- Confirm that the selected authentication method matches the enrollment profile.
- Enter a renewal window from
1to365days. - Select Save and Enroll.
- Wait for the enrollment request to complete and the page to refresh.
A successful request displays a message similar to Saved enrollment settings for "device name".
If the certificate has not been issued, the page displays Not enrolled yet. Complete the account settings and select Save and Enroll to request a certificate.
Review the certificate status
After successful enrollment, the read-only Status panel is populated.
| Status field | Meaning |
|---|---|
| Start date | The date and time from which the issued certificate is valid. |
| Expiry date | The date and time when the issued certificate expires. |
| Certificate | The certificate file associated with the enrollment. |
| Key | The key file associated with the issued certificate and generated request. |
| Certificate ID | The identifier assigned to the certificate by DigiCert ONE IoT Trust. |
A populated Certificate ID indicates that the device has received an issued certificate. The certificate and key can then be referenced by SIA Connect features that support certificate selection.
Change the enrollment configuration
- Open Tools > DigiCert ONE IoT Trust.
- Change the required account setting, authentication method, credential, device name, or renewal window.
- Select Save and Enroll.
- Review the updated status and any message returned by the enrollment service.
When certificate authentication is already configured, the existing authentication certificate and key are shown in the form. Upload replacement files only when the credentials need to be changed.
Understand certificate renewal
The Renewal window (days) determines how many days before the current certificate expires SIA Connect should request a renewal. Select a value from 1 to 365 that matches the organization's certificate policy.
Use the Expiry date in the Status panel to confirm the current certificate lifetime. After a renewed certificate is issued, review the displayed certificate, key, Certificate ID, and validity dates.
Protect enrollment credentials
Passcodes, API keys, authentication keys, and private keys are sensitive. Store them securely and replace them in DigiCert ONE and SIA Connect if they are exposed.
- Treat passcodes, API keys, authentication keys, and issued private keys as sensitive.
- Use credentials created for the intended enrollment profile and device.
- Do not share private-key files or store them in an unsecured location.
- Replace credentials in DigiCert ONE and SIA Connect if they are exposed.
- Confirm that the device name and enrollment profile are correct before requesting a certificate.
Troubleshoot validation errors
| Message | What to do |
|---|---|
| Account is required. or Account must be 120 characters or less. | Enter the DigiCert ONE account identifier and keep it within the allowed length. |
| Enrollment profile is required. or Enrollment profile must be 120 characters or less. | Enter a valid enrollment profile ID from DigiCert ONE IoT Trust Manager. |
| Device name is required. | Enter the device name that should be used for enrollment. |
| Device name can include letters, numbers, spaces, dots, hyphens, and underscores. | Remove unsupported characters from the device name. |
| Passcode must be at least 6 characters. or Passcode must be 64 characters or less. | Enter a passcode within the permitted length. |
| API key is required. | Enter the API key configured for the selected enrollment profile. |
| Authentication certificate is required. or Authentication key is required. | Upload both credentials when using Certification. |
| Certificate file must be .crt, .pem, .cer, or .der. | Select a supported authentication-certificate file. |
| Key file must be .key, .pem, .der, or .pub. | Select a supported authentication-key file. |
| Renewal window must be a whole number. | Enter a whole number of days. |
| Renewal window must be at least 1 day. or Renewal window cannot exceed 365 days. | Enter a value from 1 to 365. |
Troubleshoot enrollment failures
If the configuration contains invalid fields, the portal displays Please fix the highlighted fields before continuing. Correct each highlighted value and select Save and Enroll again.
If the enrollment request fails, the portal displays Failed to save DigiCert settings. Check the following:
- The gateway has working internet and DNS access.
- The account identifier and enrollment profile ID are correct.
- The selected authentication method matches the enrollment profile.
- The passcode, API key, or authentication certificate and key are valid.
- The device name complies with the enrollment profile requirements.
DigiCert ONE can return an additional status message. The Edge Portal displays that message above the form with the instruction to review the configuration and try enrolling again. Use the returned message as the first troubleshooting step.