Private trust stack reference
Look up identifiers, response structures, authentication methods, and endpoints used by the solution.
Use this reference to trace identifiers across DigiCert® Account Manager, DigiCert® Private CA, DigiCert® Device Trust Manager, and DigiCert® Software Trust Manager. You can also look up response structures, authentication methods, and API-specific request formats.
Implementation status and saved values
Record non-secret resource IDs and references to entries in your approved secret manager. Do not record API tokens, passcodes, or private-key values in this status record. Use the linked checkpoint to determine whether each phase is complete.
Environment variables do not survive a new shell. Values to retain lists what to record for the run. Before resuming in a new shell, use Restore the shell environment to re-export the values from the response files in the working directory.
| Checkpoint | Workstream | Completion evidence | Values to retain | Next step |
|---|---|---|---|---|
| Establish the account foundation | Shared foundation | Service identity with limited roles and matching client certificate verified. | account_id, organization_id, service-user and credential IDs, secret-manager references for service_api_token and client.key | Prepare the private trust domain |
| Prepare the private trust domain | Shared foundation | CA assignments, certificate paths, and approved root fingerprint verified. | CA IDs, root-ca.pem, workload issuing-CA certificates | Configure the device certificate infrastructure and configure and test private code signing in either order or in parallel. |
| Configure the device certificate infrastructure | Device identity | Eligible template, division, profile, and policy verified. | Template, rendezvous-zone, division, profile, and policy IDs | Enroll and verify a device |
| Enroll and verify a device | Device identity | Passcode registration, key match, and device certificate path verified. | Authentication, passcode, group, device-record, request, and device-certificate IDs | Configure and test private code signing if code signing is incomplete. Otherwise, operate this solution. |
| Configure and test private code signing | Code signing | Signing certificate path and returned signature verified. | Template, profile, keypair, certificate, and signature IDs | Configure the device certificate infrastructure if device identity is incomplete. Otherwise, operate this solution. |
Files each phase writes
Every example uses relative paths, so run all five phases in one working directory. The phase examples create these files:
| Phase | Files written | Handling |
|---|---|---|
| Establish the account foundation | account-id.txt, organization-id.txt, service-user-response.json, service-user-details.json, service-user-id.txt, api-token-id.txt, service-api-token.txt, role-inventory.json, client.key, client.csr, client.crt, client-auth-ca.pem, client-auth-certificate-id.txt, client-auth-certificate-response.json | service-api-token.txt, service-user-response.json, and client.key contain secrets. Move them to your secret manager and remove the local copies when the run ends. |
| Prepare the private trust domain | ca-inventory.json, root-ca-id.txt, device-ica-id.txt, signing-ica-id.txt, root-ca.pem, device-issuing-ca.pem, signing-issuing-ca.pem; direct-ID fallback also writes root-ca-record.json, device-ica-record.json, and signing-ica-record.json | Public identifiers and certificates. Retain root-ca.pem and its verified fingerprint. |
| Configure the device certificate infrastructure | device-template-page.json, device-template-records.json, device-template.json, primary-rendezvous-zone-id.txt, division.json, device-profile-response.json, certificate-policy-response.json | Non-secret configuration records. Retain them to re-export the identifiers. |
| Enroll and verify a device | authentication-policy-response.json, passcode-response.json, device-group.json, device-name.txt, device-registration-response.json, device-record.json, device-certificate.json, device-id.txt, device.pem, device.key | passcode-response.json, device-registration-response.json, and device.key contain secrets. The server-generated key is demo material; protect it during validation and securely remove it afterward. |
| Configure and test private code signing | signing-template-page.json, signing-template-items.json, signing-template.json, signing-profile-name.txt, signing-profile-response.json, keypair-alias.txt, keypair-response.json, optional keypair-search.json, signing-certificate-response.json, signing-cert.der, signing-cert.pem, signing-public-key.pem, test-artifact.txt, test-artifact.sha256, signing-response.json, test-artifact.sig | The signing private key never leaves Software Trust Manager. Retain the unique profile name and keypair alias so uncertain create results can be investigated without immediately repeating a POST. The signature artifacts are validation evidence. |
Cross-product data flow
| Data | Created or selected in | Used in | Format and handling |
|---|---|---|---|
account_id | Account Manager account list | All setup phases | UUID selected from the account response array. |
organization_id | Account Manager organization list | Software Trust Manager private trust certificate profile | UUID for an active organization in account_id. |
service_user_id | Account Manager create-user response | Credential administration and audit | UUID. It is not an authentication secret. |
api_token_id | Create-user response api_token.id | Credential removal and audit | UUID for the returned-once service API token. |
service_api_token | Create-user response api_token.token | Setup calls authenticated with an API token and Software Trust Manager multi-factor authentication | Secret API token that is returned once. Send it in the x-api-key header. It is not an OAuth bearer token. |
client_auth_certificate_id | Account Manager create-client-authentication-certificate response | Credential removal and audit | UUID for the credential created with the service user identified by service_user_id. |
client.crt, client.key | Account Manager client authentication certificate creation | Software Trust Manager keypair creation and signing | Generate the private key locally and submit only its certificate signing request (CSR). Protect the PEM private key as a secret. |
root_ca_id | DigiCert Private CA GET /ca | CA certificate download | Identifier selected from the active root CA record. |
root-ca.pem | DigiCert Private CA CA-download operation | Relying-party trust stores and path validation | Trust anchor. Validate the fingerprint before distribution. |
device_ica_id | Active intermediate from the DigiCert Private CA GET /ca operation | Device Trust Manager certificate policy | Identifier selected from the active device issuing-CA record. |
signing_ica_id | Active intermediate from the DigiCert Private CA GET /ca operation | Software Trust Manager private trust certificate profile | Identifier selected from the active signing issuing-CA record. It can equal device_ica_id when your public key infrastructure (PKI) policy permits a shared issuer. |
device-issuing-ca.pem | DigiCert Private CA CA-download operation | Device certificate-path construction | Device intermediate certificate. Do not install it as the trust anchor. |
signing-issuing-ca.pem | DigiCert Private CA CA-download operation | Signing certificate-path construction | Signing intermediate certificate. Do not install it as the trust anchor. |
device_certificate_template_id | Device Trust Manager certificate-template list | Device certificate profile | UUID specific to Device Trust Manager. The template must require the client authentication extended key usage (EKU) and support this request’s key and subject sources. |
code_signing_certificate_template_id | Software Trust Manager certificate-template list | Private trust certificate profile in the same product | UUID specific to Software Trust Manager. The template must be active, custom, available to the account, and require code_signing. |
primary_rendezvous_zone_id | Device Trust Manager rendezvous-zone list records[].id | Device Trust Manager division creation | UUID for an enabled zone assigned to the account with is_primary_usage: true. |
division_id | Device Trust Manager division list records[].id | Device profile, policy, and group | UUID. The create response does not supply this ID directly. |
device_certificate_profile_id | Device Trust Manager create-profile response | Device Trust Manager certificate policy | UUID. |
certificate_policy_id | Device Trust Manager create-policy response | Group assignment and enrollment | IOT_<uuid> in the API examples. |
authentication_policy_id | Device Trust Manager create-authentication-policy response | Passcode and group policy assignment | UUID. |
passcode_id | Device Trust Manager create-passcode response | Credential removal | UUID. |
enrollment_passcode | Client-supplied create-passcode value | Device-registration x-passcode header | Secret. The create response might include it, so protect the complete response and continue using the original secret-store value. |
device_group_id | Device Trust Manager group list records[].id | Device-registration request and device inventory | UUID required by this solution to apply the group authentication override. |
device_id | Device-registration response device_id | Device and certificate inventory verification | UUID for the registered managed device. Require the inventory records to match this value. |
certificate_request_id | Exact registered-certificate inventory record | Troubleshooting and audit correlation | Identifier for the device certificate request. |
device_certificate_id | Exact registered-certificate inventory record id | Inventory and lifecycle operations | Identifier for the issued device certificate. |
signing_profile_id | Software Trust Manager create-profile response | Signing-certificate generation | UUID. |
keypair_alias | Locally generated before the Software Trust Manager create-keypair request | Exact lookup, uncertain-result recovery, cleanup, and signing-tool configuration | Unique non-secret string retained in keypair-alias.txt. Do not reuse one alias for parallel validation runs. |
keypair_id | Software Trust Manager create-keypair response or exact-alias recovery record | Certificate generation and signing paths | UUID. Keypair creation requires an API token and mutual TLS (mTLS). Resolve an uncertain create result before using this ID. |
signing_certificate_id | Software Trust Manager certificate-generation response | Certificate identification and lifecycle tracking | Identifier for the private code-signing certificate. |
signature_id | Software Trust Manager sign response | Request identification and retained validation evidence | Identifier for the returned signature operation. |
Response structures
| Operation | Response structure |
|---|---|
| Account Manager list accounts | Top-level JSON array. |
| Account Manager list organizations | Top-level JSON array. |
| Account Manager list roles | Object keyed by product code, each containing a role array. Role objects carry id, name, display_name, description, type, status, and access_scope. They do not list the permissions the role grants. |
| Account Manager create user and get user details | Object containing an applications array. Each entry can report a product’s assigned roles and effective permissions. Keep the two arrays distinct: a role name is not a permission code. Create user can return 200 or 201. Accept a successful 2xx response only when the required response fields and retrieved user record pass validation. |
| DigiCert Private CA list CAs | Object with pagination metadata. CA records are in items, alongside limit, offset, and total. The API reference declares no query parameters for this operation. When total differs from the number of returned items, prefer direct retrieval by approved ID with GET /certificate-authority/api/v1/ca/{id}. Use limit and offset only after confirming that your tenant supports and honors them. |
| Device Trust Manager list certificate templates | Paginated object. Templates are in records; offset is the index of the first record, and limit accepts up to 1000 with a default of 20. |
| Software Trust Manager list certificate templates | Paginated object. Templates are in items; offset is the page index. |
| Device Trust Manager list divisions | Paginated object. Divisions are in records; offset is the index of the first record. |
| Device Trust Manager list device groups | Paginated object. Groups are in records; offset is the index of the first record. |
| Device Trust Manager create division or group | Response with status information but no resource ID. Retrieve the new ID by listing resources and selecting the exact name. |
| Device Trust Manager create certificate policy | Object with the created policy in certificate_policy. |
| Device Trust Manager register a device | Top-level object containing device_id, device_name, registration and operational states, and private_keys[]. Each bootstrap result identifies its policy and contains the issued certificate and, for server-side generation, the private key. |
| Software Trust Manager list keypairs | Paginated object with keypairs in items. Use the exact retained alias to resolve an uncertain create result before retrying. A non-2xx create response does not prove the keypair was rolled back. |
Authentication matrix
| API operations | Host | Headers | Client certificate |
|---|---|---|---|
| Account Manager setup | Tenant host | API token in x-api-key | No |
| DigiCert Private CA setup | Tenant host | API token in x-api-key | No |
| Device Trust Manager administrative setup | Tenant host | API token in x-api-key | No |
| Device registration using passcode | Tenant host | x-passcode. Omit x-api-key. | No |
| Software Trust Manager profile and certificate setup | Tenant host | API token in x-api-key | No. The API reference requires multi-factor authentication only on keypair creation and signing. |
| Software Trust Manager keypair creation and signing | clientauth. tenant host | API token in x-api-key | Yes. The certificate and key must belong to the identity associated with the API token. |
Endpoint quick reference
The examples use this host:
https://demo.one.digicert.com
| Method | Full path | Phase |
|---|---|---|
| GET | /account/api/v1/account | 1 |
| GET | /account/api/v1/role | 1 |
| GET | /account/api/v1/organization | 1 |
| POST | /account/api/v1/user | 1 |
| GET | /account/api/v1/user/{service_user_id} | 1 |
| POST | /account/api/v1/client-auth-certificate | 1 |
| GET | /account/api/v1/user/me | 1 |
| GET | /certificate-authority/api/v1/ca | 2 |
| GET | /certificate-authority/api/v1/ca/{ca_id} | 2 |
| POST | /certificate-authority/api/v1/ca/{ica_id}/accounts | 2 |
| GET | /certificate-authority/api/v1/ca/{ca_id}/download?format=pem | 2 |
| GET | /devicetrustmanager/certificate-configuration-service/api/v1/certificate-template | 3 |
| GET | /devicetrustmanager/api/v4/rendezvous-zone | 3 |
| POST | /devicetrustmanager/api/v4/division | 3 |
| GET | /devicetrustmanager/api/v4/division | 3 |
| POST | /devicetrustmanager/certificate-configuration-service/api/v1/certificate-profile | 3 |
| POST | /devicetrustmanager/certificate-configuration-service/api/v2/certificate-policy | 3 |
| POST | /devicetrustmanager/authentication-service/api/v1/authentication-policy | 4 |
| POST | /devicetrustmanager/authentication-service/api/v1/passcode | 4 |
| POST | /devicetrustmanager/api/v4/device-group | 4 |
| GET | /devicetrustmanager/api/v4/device-group | 4 |
| POST | /devicetrustmanager/api/v4/device/registration | 4 |
| GET | /devicetrustmanager/api/v4/device | 4 |
| GET | /devicetrustmanager/certificate-issuance-service/api/v2/certificate | 4 |
| GET | /signingmanager/api/v1/certificate-templates | 5 |
| POST | /signingmanager/api/v1/certificate-profiles | 5 |
| POST | /signingmanager/api/v1/keypairs | 5 |
| GET | /signingmanager/api/v1/keypairs | 5, uncertain-create recovery |
| POST | /signingmanager/api/v1/keypairs/{keypair_id}/certificates | 5 |
| POST | /signingmanager/api/v1/keypairs/{keypair_id}/sign | 5 |
For GET /account/api/v1/user/me and for Software Trust Manager keypair creation and signing, change the host to:
https://clientauth.demo.one.digicert.com
API-specific request formats
Map a product to its role response key and access checks
GET /account/api/v1/role groups roles by product code. The codes are stable and some predate the current product names, so they do not always match the name used elsewhere in the interface or in this manual.
| Product | Role response key | Access check used by this manual |
|---|---|---|
| Account Manager | account_manager | The bootstrap user’s effective permissions include MANAGE_AM_ACCOUNT_USER, VIEW_AM_ACCOUNT, VIEW_AM_ORGANIZATION, and VIEW_AM_ROLE. |
| DigiCert Private CA | ca_manager | Effective permissions include VIEW_CM_CA and MANAGE_CM_CA_ACCOUNTS. |
| Device Trust Manager | device_trust_manager | applications[].roles contains the exact active Solution Administrator role selected from the tenant. Its granular effective permissions appear separately in applications[].permissions. |
| Software Trust Manager | secure_software_manager | Effective permissions include MANAGE_SM_CERTIFICATE_PROFILE, VIEW_SM_CERTIFICATE_TEMPLATE, VIEW_SM_KEYPAIR, GENERATE_SM_KEYPAIR, GENERATE_SM_CERTIFICATE, and SIGN_SM_HASH. |
The application_code query parameter narrows the role list to one product, but its documented values do not include device_trust_manager. Request the full list instead, and select the keys you need from the response.
The role list does not report permissions. Verify the assigned role names and effective permission codes on the created service user with GET /account/api/v1/user/{user_id}. Its applications entries keep roles and permissions separate.
Select a template from the correct product
Use the template endpoint in the product that creates the profile:
| Product | Response structure | Required checks for this manual |
|---|---|---|
| Device Trust Manager | GET /devicetrustmanager/certificate-configuration-service/api/v1/certificate-template → records | Exact name, ACTIVE, custom, X.509 end-entity certificate, target-account access, client_authentication, RSA-2048 through key_types or the key_gen range, user-supplied common name, and required client authentication EKU. |
| Software Trust Manager | GET /signingmanager/api/v1/certificate-templates → items | Exact name, ACTIVE, CUSTOM, TEST, target-account access, code_signing, and required code-signing EKU. |
The DigiCert Private CA GET /template operation returns a third template resource. You cannot use its IDs in Device Trust Manager or Software Trust Manager profile requests.
Device Trust group policy assignment
{
"policy_id": "IOT_<uuid>",
"assignment_name": "Private device bootstrap certificate",
"type": "bootstrapCertificate",
"auth_policy_id": "<authentication-policy-uuid>",
"status": "ACTIVE"
}
Device Trust server-side device registration
{
"name": "device-<unique-run-label>.example.internal",
"description": "Private trust validation device",
"account_id": "<account-uuid>",
"device_group_id": "<device-group-uuid>",
"certificate_policies": {
"bootstrap": [
{
"server_side_key_gen": true,
"certificate_policy_id": "IOT_<uuid>",
"key_type": "RSA_2048",
"key_format": "PEM",
"key_syntax": "PKCS8",
"attributes": [
{
"name": "subject.common_name",
"value": "device-<unique-run-label>.example.internal"
}
]
}
]
}
}
Software Trust private trust certificate profile
Use this request format:
{
"profile_type": "CA_PROFILE",
"ca_certificate_profile_request": {
"certificate_template_id": "<code-signing-template-uuid>",
"profile": "TEST",
"body": [],
"organization": {
"id": "<organization-uuid>"
},
"ca": {
"id": "<ica-id>"
}
}
}