
What it is
CA Management is where you connect external CAs (Let’s Encrypt, DigiCert, AWS Private CA, HashiCorp Vault, and others) and create internal CAs powered by TigerTrust’s built-in PKI. All connected CAs appear in the issuance wizard and are available to the renewal engine.When to use it
- Connect Let’s Encrypt to issue and auto-renew public-facing TLS certificates.
- Add DigiCert or Sectigo for EV or OV certificates that require organization validation.
- Create an internal CA hierarchy for private PKI — mesh certificates, client auth, code signing.
- Integrate HashiCorp Vault’s PKI secrets engine for team-managed issuance.
Supported CA types
| Category | Types |
|---|---|
| ACME | Let’s Encrypt, ZeroSSL, BuyPass, Google Trust Services, any RFC 8555 CA |
| Public / commercial | DigiCert, Sectigo, GlobalSign, GoDaddy, Entrust, and others |
| Cloud | AWS Private CA, Azure Key Vault, GCP Certificate Authority Service, Cloudflare |
| Enterprise | Venafi, HashiCorp Vault, EJBCA, Microsoft ADCS |
| Internal | TigerTrust PKI Core (root and intermediate CAs) |
Set it up
- Let's Encrypt
- DigiCert
- Microsoft ADCS
- Internal CA
Choose a challenge type
HTTP-01 (via a field agent), DNS-01 (via a DNS provider integration), or TLS-ALPN-01.
What you’ll see
Connected CAs appear in CA Management with a health indicator (healthy, degraded, unhealthy, unknown) and last-contact timestamp. The Health tab shows per-CA error rates and connectivity probe results. An unhealthy CA generates an alert and is skipped by the renewal engine to avoid stampeding a broken upstream.
Related
PKI Core
Stand up your own internal CA hierarchy.
Certificate issuance
Issue against any connected CA.
Certificate renewal
Every supported renewal method, per CA type.