Private trust stack reference

Look up identifiers, response structures, authentication methods, and endpoints used by the solution.

Use this reference to trace identifiers across DigiCert® Account Manager, DigiCert® Private CA, DigiCert® Device Trust Manager, and DigiCert® Software Trust Manager. You can also look up response structures, authentication methods, and API-specific request formats.

Implementation status and saved values

Record non-secret resource IDs and references to entries in your approved secret manager. Do not record API tokens, passcodes, or private-key values in this status record. Use the linked checkpoint to determine whether each phase is complete.

Environment variables do not survive a new shell. Values to retain lists what to record for the run. Before resuming in a new shell, use Restore the shell environment to re-export the values from the response files in the working directory.

CheckpointWorkstreamCompletion evidenceValues to retainNext step
Establish the account foundationShared foundationService identity with limited roles and matching client certificate verified.account_id, organization_id, service-user and credential IDs, secret-manager references for service_api_token and client.keyPrepare the private trust domain
Prepare the private trust domainShared foundationCA assignments, certificate paths, and approved root fingerprint verified.CA IDs, root-ca.pem, workload issuing-CA certificatesConfigure the device certificate infrastructure and configure and test private code signing in either order or in parallel.
Configure the device certificate infrastructureDevice identityEligible template, division, profile, and policy verified.Template, rendezvous-zone, division, profile, and policy IDsEnroll and verify a device
Enroll and verify a deviceDevice identityPasscode registration, key match, and device certificate path verified.Authentication, passcode, group, device-record, request, and device-certificate IDsConfigure and test private code signing if code signing is incomplete. Otherwise, operate this solution.
Configure and test private code signingCode signingSigning certificate path and returned signature verified.Template, profile, keypair, certificate, and signature IDsConfigure the device certificate infrastructure if device identity is incomplete. Otherwise, operate this solution.

Files each phase writes

Every example uses relative paths, so run all five phases in one working directory. The phase examples create these files:

PhaseFiles writtenHandling
Establish the account foundationaccount-id.txt, organization-id.txt, service-user-response.json, service-user-details.json, service-user-id.txt, api-token-id.txt, service-api-token.txt, role-inventory.json, client.key, client.csr, client.crt, client-auth-ca.pem, client-auth-certificate-id.txt, client-auth-certificate-response.jsonservice-api-token.txt, service-user-response.json, and client.key contain secrets. Move them to your secret manager and remove the local copies when the run ends.
Prepare the private trust domainca-inventory.json, root-ca-id.txt, device-ica-id.txt, signing-ica-id.txt, root-ca.pem, device-issuing-ca.pem, signing-issuing-ca.pem; direct-ID fallback also writes root-ca-record.json, device-ica-record.json, and signing-ica-record.jsonPublic identifiers and certificates. Retain root-ca.pem and its verified fingerprint.
Configure the device certificate infrastructuredevice-template-page.json, device-template-records.json, device-template.json, primary-rendezvous-zone-id.txt, division.json, device-profile-response.json, certificate-policy-response.jsonNon-secret configuration records. Retain them to re-export the identifiers.
Enroll and verify a deviceauthentication-policy-response.json, passcode-response.json, device-group.json, device-name.txt, device-registration-response.json, device-record.json, device-certificate.json, device-id.txt, device.pem, device.keypasscode-response.json, device-registration-response.json, and device.key contain secrets. The server-generated key is demo material; protect it during validation and securely remove it afterward.
Configure and test private code signingsigning-template-page.json, signing-template-items.json, signing-template.json, signing-profile-name.txt, signing-profile-response.json, keypair-alias.txt, keypair-response.json, optional keypair-search.json, signing-certificate-response.json, signing-cert.der, signing-cert.pem, signing-public-key.pem, test-artifact.txt, test-artifact.sha256, signing-response.json, test-artifact.sigThe signing private key never leaves Software Trust Manager. Retain the unique profile name and keypair alias so uncertain create results can be investigated without immediately repeating a POST. The signature artifacts are validation evidence.

Cross-product data flow

DataCreated or selected inUsed inFormat and handling
account_idAccount Manager account listAll setup phasesUUID selected from the account response array.
organization_idAccount Manager organization listSoftware Trust Manager private trust certificate profileUUID for an active organization in account_id.
service_user_idAccount Manager create-user responseCredential administration and auditUUID. It is not an authentication secret.
api_token_idCreate-user response api_token.idCredential removal and auditUUID for the returned-once service API token.
service_api_tokenCreate-user response api_token.tokenSetup calls authenticated with an API token and Software Trust Manager multi-factor authenticationSecret API token that is returned once. Send it in the x-api-key header. It is not an OAuth bearer token.
client_auth_certificate_idAccount Manager create-client-authentication-certificate responseCredential removal and auditUUID for the credential created with the service user identified by service_user_id.
client.crt, client.keyAccount Manager client authentication certificate creationSoftware Trust Manager keypair creation and signingGenerate the private key locally and submit only its certificate signing request (CSR). Protect the PEM private key as a secret.
root_ca_idDigiCert Private CA GET /caCA certificate downloadIdentifier selected from the active root CA record.
root-ca.pemDigiCert Private CA CA-download operationRelying-party trust stores and path validationTrust anchor. Validate the fingerprint before distribution.
device_ica_idActive intermediate from the DigiCert Private CA GET /ca operationDevice Trust Manager certificate policyIdentifier selected from the active device issuing-CA record.
signing_ica_idActive intermediate from the DigiCert Private CA GET /ca operationSoftware Trust Manager private trust certificate profileIdentifier selected from the active signing issuing-CA record. It can equal device_ica_id when your public key infrastructure (PKI) policy permits a shared issuer.
device-issuing-ca.pemDigiCert Private CA CA-download operationDevice certificate-path constructionDevice intermediate certificate. Do not install it as the trust anchor.
signing-issuing-ca.pemDigiCert Private CA CA-download operationSigning certificate-path constructionSigning intermediate certificate. Do not install it as the trust anchor.
device_certificate_template_idDevice Trust Manager certificate-template listDevice certificate profileUUID specific to Device Trust Manager. The template must require the client authentication extended key usage (EKU) and support this request’s key and subject sources.
code_signing_certificate_template_idSoftware Trust Manager certificate-template listPrivate trust certificate profile in the same productUUID specific to Software Trust Manager. The template must be active, custom, available to the account, and require code_signing.
primary_rendezvous_zone_idDevice Trust Manager rendezvous-zone list records[].idDevice Trust Manager division creationUUID for an enabled zone assigned to the account with is_primary_usage: true.
division_idDevice Trust Manager division list records[].idDevice profile, policy, and groupUUID. The create response does not supply this ID directly.
device_certificate_profile_idDevice Trust Manager create-profile responseDevice Trust Manager certificate policyUUID.
certificate_policy_idDevice Trust Manager create-policy responseGroup assignment and enrollmentIOT_<uuid> in the API examples.
authentication_policy_idDevice Trust Manager create-authentication-policy responsePasscode and group policy assignmentUUID.
passcode_idDevice Trust Manager create-passcode responseCredential removalUUID.
enrollment_passcodeClient-supplied create-passcode valueDevice-registration x-passcode headerSecret. The create response might include it, so protect the complete response and continue using the original secret-store value.
device_group_idDevice Trust Manager group list records[].idDevice-registration request and device inventoryUUID required by this solution to apply the group authentication override.
device_idDevice-registration response device_idDevice and certificate inventory verificationUUID for the registered managed device. Require the inventory records to match this value.
certificate_request_idExact registered-certificate inventory recordTroubleshooting and audit correlationIdentifier for the device certificate request.
device_certificate_idExact registered-certificate inventory record idInventory and lifecycle operationsIdentifier for the issued device certificate.
signing_profile_idSoftware Trust Manager create-profile responseSigning-certificate generationUUID.
keypair_aliasLocally generated before the Software Trust Manager create-keypair requestExact lookup, uncertain-result recovery, cleanup, and signing-tool configurationUnique non-secret string retained in keypair-alias.txt. Do not reuse one alias for parallel validation runs.
keypair_idSoftware Trust Manager create-keypair response or exact-alias recovery recordCertificate generation and signing pathsUUID. Keypair creation requires an API token and mutual TLS (mTLS). Resolve an uncertain create result before using this ID.
signing_certificate_idSoftware Trust Manager certificate-generation responseCertificate identification and lifecycle trackingIdentifier for the private code-signing certificate.
signature_idSoftware Trust Manager sign responseRequest identification and retained validation evidenceIdentifier for the returned signature operation.

Response structures

OperationResponse structure
Account Manager list accountsTop-level JSON array.
Account Manager list organizationsTop-level JSON array.
Account Manager list rolesObject keyed by product code, each containing a role array. Role objects carry id, name, display_name, description, type, status, and access_scope. They do not list the permissions the role grants.
Account Manager create user and get user detailsObject containing an applications array. Each entry can report a product’s assigned roles and effective permissions. Keep the two arrays distinct: a role name is not a permission code. Create user can return 200 or 201. Accept a successful 2xx response only when the required response fields and retrieved user record pass validation.
DigiCert Private CA list CAsObject with pagination metadata. CA records are in items, alongside limit, offset, and total. The API reference declares no query parameters for this operation. When total differs from the number of returned items, prefer direct retrieval by approved ID with GET /certificate-authority/api/v1/ca/{id}. Use limit and offset only after confirming that your tenant supports and honors them.
Device Trust Manager list certificate templatesPaginated object. Templates are in records; offset is the index of the first record, and limit accepts up to 1000 with a default of 20.
Software Trust Manager list certificate templatesPaginated object. Templates are in items; offset is the page index.
Device Trust Manager list divisionsPaginated object. Divisions are in records; offset is the index of the first record.
Device Trust Manager list device groupsPaginated object. Groups are in records; offset is the index of the first record.
Device Trust Manager create division or groupResponse with status information but no resource ID. Retrieve the new ID by listing resources and selecting the exact name.
Device Trust Manager create certificate policyObject with the created policy in certificate_policy.
Device Trust Manager register a deviceTop-level object containing device_id, device_name, registration and operational states, and private_keys[]. Each bootstrap result identifies its policy and contains the issued certificate and, for server-side generation, the private key.
Software Trust Manager list keypairsPaginated object with keypairs in items. Use the exact retained alias to resolve an uncertain create result before retrying. A non-2xx create response does not prove the keypair was rolled back.

Authentication matrix

API operationsHostHeadersClient certificate
Account Manager setupTenant hostAPI token in x-api-keyNo
DigiCert Private CA setupTenant hostAPI token in x-api-keyNo
Device Trust Manager administrative setupTenant hostAPI token in x-api-keyNo
Device registration using passcodeTenant hostx-passcode. Omit x-api-key.No
Software Trust Manager profile and certificate setupTenant hostAPI token in x-api-keyNo. The API reference requires multi-factor authentication only on keypair creation and signing.
Software Trust Manager keypair creation and signingclientauth. tenant hostAPI token in x-api-keyYes. The certificate and key must belong to the identity associated with the API token.

Endpoint quick reference

The examples use this host:

https://demo.one.digicert.com
MethodFull pathPhase
GET/account/api/v1/account1
GET/account/api/v1/role1
GET/account/api/v1/organization1
POST/account/api/v1/user1
GET/account/api/v1/user/{service_user_id}1
POST/account/api/v1/client-auth-certificate1
GET/account/api/v1/user/me1
GET/certificate-authority/api/v1/ca2
GET/certificate-authority/api/v1/ca/{ca_id}2
POST/certificate-authority/api/v1/ca/{ica_id}/accounts2
GET/certificate-authority/api/v1/ca/{ca_id}/download?format=pem2
GET/devicetrustmanager/certificate-configuration-service/api/v1/certificate-template3
GET/devicetrustmanager/api/v4/rendezvous-zone3
POST/devicetrustmanager/api/v4/division3
GET/devicetrustmanager/api/v4/division3
POST/devicetrustmanager/certificate-configuration-service/api/v1/certificate-profile3
POST/devicetrustmanager/certificate-configuration-service/api/v2/certificate-policy3
POST/devicetrustmanager/authentication-service/api/v1/authentication-policy4
POST/devicetrustmanager/authentication-service/api/v1/passcode4
POST/devicetrustmanager/api/v4/device-group4
GET/devicetrustmanager/api/v4/device-group4
POST/devicetrustmanager/api/v4/device/registration4
GET/devicetrustmanager/api/v4/device4
GET/devicetrustmanager/certificate-issuance-service/api/v2/certificate4
GET/signingmanager/api/v1/certificate-templates5
POST/signingmanager/api/v1/certificate-profiles5
POST/signingmanager/api/v1/keypairs5
GET/signingmanager/api/v1/keypairs5, uncertain-create recovery
POST/signingmanager/api/v1/keypairs/{keypair_id}/certificates5
POST/signingmanager/api/v1/keypairs/{keypair_id}/sign5

For GET /account/api/v1/user/me and for Software Trust Manager keypair creation and signing, change the host to:

https://clientauth.demo.one.digicert.com

API-specific request formats

Map a product to its role response key and access checks

GET /account/api/v1/role groups roles by product code. The codes are stable and some predate the current product names, so they do not always match the name used elsewhere in the interface or in this manual.

ProductRole response keyAccess check used by this manual
Account Manageraccount_managerThe bootstrap user’s effective permissions include MANAGE_AM_ACCOUNT_USER, VIEW_AM_ACCOUNT, VIEW_AM_ORGANIZATION, and VIEW_AM_ROLE.
DigiCert Private CAca_managerEffective permissions include VIEW_CM_CA and MANAGE_CM_CA_ACCOUNTS.
Device Trust Managerdevice_trust_managerapplications[].roles contains the exact active Solution Administrator role selected from the tenant. Its granular effective permissions appear separately in applications[].permissions.
Software Trust Managersecure_software_managerEffective permissions include MANAGE_SM_CERTIFICATE_PROFILE, VIEW_SM_CERTIFICATE_TEMPLATE, VIEW_SM_KEYPAIR, GENERATE_SM_KEYPAIR, GENERATE_SM_CERTIFICATE, and SIGN_SM_HASH.

The application_code query parameter narrows the role list to one product, but its documented values do not include device_trust_manager. Request the full list instead, and select the keys you need from the response.

The role list does not report permissions. Verify the assigned role names and effective permission codes on the created service user with GET /account/api/v1/user/{user_id}. Its applications entries keep roles and permissions separate.

Select a template from the correct product

Use the template endpoint in the product that creates the profile:

ProductResponse structureRequired checks for this manual
Device Trust ManagerGET /devicetrustmanager/certificate-configuration-service/api/v1/certificate-template → recordsExact name, ACTIVE, custom, X.509 end-entity certificate, target-account access, client_authentication, RSA-2048 through key_types or the key_gen range, user-supplied common name, and required client authentication EKU.
Software Trust ManagerGET /signingmanager/api/v1/certificate-templates → itemsExact name, ACTIVE, CUSTOM, TEST, target-account access, code_signing, and required code-signing EKU.

The DigiCert Private CA GET /template operation returns a third template resource. You cannot use its IDs in Device Trust Manager or Software Trust Manager profile requests.

Device Trust group policy assignment

{
  "policy_id": "IOT_<uuid>",
  "assignment_name": "Private device bootstrap certificate",
  "type": "bootstrapCertificate",
  "auth_policy_id": "<authentication-policy-uuid>",
  "status": "ACTIVE"
}

Device Trust server-side device registration

{
  "name": "device-<unique-run-label>.example.internal",
  "description": "Private trust validation device",
  "account_id": "<account-uuid>",
  "device_group_id": "<device-group-uuid>",
  "certificate_policies": {
    "bootstrap": [
      {
        "server_side_key_gen": true,
        "certificate_policy_id": "IOT_<uuid>",
        "key_type": "RSA_2048",
        "key_format": "PEM",
        "key_syntax": "PKCS8",
        "attributes": [
          {
            "name": "subject.common_name",
            "value": "device-<unique-run-label>.example.internal"
          }
        ]
      }
    ]
  }
}

Software Trust private trust certificate profile

Use this request format:

{
  "profile_type": "CA_PROFILE",
  "ca_certificate_profile_request": {
    "certificate_template_id": "<code-signing-template-uuid>",
    "profile": "TEST",
    "body": [],
    "organization": {
      "id": "<organization-uuid>"
    },
    "ca": {
      "id": "<ica-id>"
    }
  }
}