Skip to main content

May 26, 2026 Archived

DigiCert ONE Configurations

As an administrator, you can use the Certificate Authorities (CA) settings in Workspace ONE UEM to integrate with your certificate authority. By implementing certificates, your infrastructure is protected against brute force attacks, dictionary attacks, and human error. Use this information to configure DigiCert ONE for integration with Worspace ONE UEM.

Configuring DigiCert ONE Certificate Authority

Integrating with DigiCert ONE (a trusted certificate authority) helps ensure a secure, seamless connection with Workspace ONE UEM while enhancing stability, security, and authentication. Once integrated with Workspace ONE UEM, the DigiCert CA capabilities enable efficient management of certificate delivery, lifecycle, and observability. These features support the use of certificates across various domains, including Public Key Infrastructure (PKI) and S/MIME, ensuring seamless and secure operations across your device fleets.

Procedure

  1. Create a Service User in DigiCert ONE.

    • Ensure permissions are assigned by following the DigiCert user creation recommendations. For the DigiCert supporting information, see Create service users.
  2. Create a Client Authentication certificate. For the DigiCert supporting information, see Create a client authentication certificate.

  3. In the Workspace ONE UEM console main menu, navigate to Devices > Certificates > Certificate Authorities.

  4. Click Add.

  5. Configure the following options on the Certificate Authority page.

    Note: Make sure that DigiCert is selected as the Authority Type before you configure this page.

Option Description
Name Enter a name for the new Certificate Authority.
Description Enter a description for the new Certificate Authority.
Authority Type Select DigiCert.
Server URL Enter the URL of the server. Enter the host name as the following: https://clientauth.one.digicert.com.

Note: If the connection fails when you test the URL, remove any trailing address additions and test the connection again.

Certificate Upload the certificate generated in Step 2.
  1. Click Test Connection to confirm a successful bind.
  2. Click Save.
  3. Next, configure a DigiCert ONE Template.
  4. Optional: If you are using AirWatch Cloud Connector and the DigiCert One appliance is not public-facing, then you need to ensure the AirWatch Cloud Connector configuration trusts the appliance.
    1. Obtain the same certificate and passcode provided during the CA configuration. If this is not possible, generate another client credential. 2. Open MMC by searching for it using Windows search and launching the mmc.exe file. 3. Navigate to File > Add/Remove Snap-in. The Add or Remove Snap-ins screen displays.
    2. In the left pane, select the Certificates snap-in. Select Add.
    3. Select Computer account as Snap-in source. Select Next.
    4. Select Local computer and then select Finish.
    5. Select OK.
    6. Expand the newly added Certificates tree.
    7. Expand the Trusted Root Certification Authorities folder.
    8. Right-click the Certificates folder here. Select All Tasks > Import.
    9. Proceed through the Certificate Import Wizard. You will be prompted to Browse. 12. Select the file of the root certificate used to generate the certificate. Select Next.
    10. Select Place all certs in the following store and then select Next.
    11. Click Finish.
    12. Select all other intermediate and child certificates to add them to their associated stores within the Certificates tree.

Configuring DigiCert ONE Template

After configuring the DigiCert ONE certificate authority, you'll sync to an existing Certificate Template.

Prerequisites

  • Configure the DigiCert ONE Certificate Authority in Workspace ONE UEM.

  • A valid template created in the DigiCert ONE Lifecycle Manager.

  • Ensure the certificate templates are set up with an Enrollment Method and compatible Authentication Method.

    Workspace ONE UEM only supports the following Enrollment and Authentication Methods:

    Enrollment MethodAuthentication Method
    Rest API
    • Third-Party App
    DigiCert Trust Assistant
    • DigiCert ONE Login
    • SAML IDP

Procedure

  1. In the Workspace ONE UEM console, navigate to System > Enterprise Integration > Certificate Authorities.

  2. On the Request Template tab, click Add.

  3. Select the DigiCert CA.

    • After selecting the DigiCert ONE CA, select a pre-loaded, configured certificate template from the drop-down in the DigiCert ONE Lifecycle Manager.
  4. Optional: After selecting the certificate template, configure the revocation and automatic renewal configurations.

    • The escrow status is configured in the template. It is displayed but is not interactable.
  5. In the Segment section, configure mandatory template attributes.

    • Use the + to add dynamic values.

Shows the Segment Attribute and Occurence configureation section of the screen.

  1. In the Workspace ONE UEM console, use your new certificate configuration to deploy certificates to end user devices.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…