Skip to main content

Sectigo Certificate Manager

Sectigo Certificate Manager (SCM) can act as the issuing certificate authority for your workspace. Unlike the other integrations, SCM runs in the cloud: there is nothing to install or configure on a Mesh Node, and no node is assigned. When a certificate is issued through an SCM connector, Sectigo Edge sends SCM the CSR together with the immutable authorization evidence from the approval quorum; every certificate is requested under the SCM organization and certificate type you configure.

Setting it up has two parts:

  1. a CA connector in ConsoleCAs & signing that holds your SCM organization ID and certificate type ID; and
  2. the Sectigo SCM integration in ConsoleIntegrations that points at that connector and a certificate profile.

Requirements​

  • An SCM account with an organization and an SSL certificate type (profile) for the certificates Sectigo Edge will request.
  • The numeric organization ID (shown for your organization under Organizations in SCM) and the numeric certificate type ID (from your SCM certificate settings).
  • The can_manage_ca permission and a fresh MFA session in Sectigo Edge.

You never enter SCM passwords or API secrets in the console, and CA private keys are never stored in the Sectigo Edge application plane.

1. Create the SCM CA connector​

  1. Open ConsoleCAs & signing and select Connect a signing authority.
  2. Enter a descriptive Connector name (at least 3 characters), for example Production SCM.
  3. Under Sectigo SCM enrollment IDs, enter the SCM organization ID (for example 12345) and the SCM certificate type ID (for example 678). Both must be positive whole numbers of up to 10 digits.
  4. Select Sectigo SCM.
Connect a signing authority dialog with connector name, SCM organization ID and certificate type ID fields, and Sectigo SCM and Bring your own CA options
The SCM connector stores only the connector name and the two numeric SCM IDs.

The connector card then shows Org 12345 · Cert type 678. If an ID is missing it shows Missing organization ID, Missing certificate type ID or Missing organization and certificate type IDs — complete them before relying on the connector.

Change the IDs later​

Open the connector from ConsoleCAs & signing, edit the SCM enrollment IDs and save. The console confirms: SCM enrollment IDs saved. The signer picks them up at the next registry publication. — new values apply from that publication onward, not instantly. See CAs and signing.

2. Enable the Sectigo SCM integration​

  1. Open ConsoleIntegrations and select Configure on the Sectigo SCM card.
  2. Select Enable this integration. There is no node selection — SCM runs in the cloud.
  3. Enter the Certificate / identity profile that should issue through SCM.
  4. Under Active SCM connector, select the connector you created. Only active SCM connectors are listed.
  5. Select Save desired state.

The card's target shows Cloud once enabled.

Status and "connectivity not verified"​

Sectigo Edge does not currently perform a live connectivity check against SCM from the console. To avoid implying a check that did not happen, the integration is never shown as Healthy just because you saved or tested it:

ActionCard statusError shown on the card
Saved with Enable this integration offDisabled—
Saved enabledDegradedscm connectivity not verified (scm_connectivity_not_verified)
Test selectedDegradedscm connectivity not verified

After a test the console reports: Test recorded, but connectivity was not verified (scm connectivity not verified). The test is still written to the audit log.

What this means for you: a Degraded status with scm_connectivity_not_verified is the expected state for a correctly configured SCM integration. It is a statement that nothing was verified, not a reported failure. Confirm that the setup works end to end by issuing a test certificate (below).

Policy and rotation​

SCM is only the issuer. The approval quorum, your signed policy (profiles, SPIFFE prefixes, DNS suffixes, algorithms, lifetimes) and the protected-signer checks apply exactly as for any other CA. Delivery and rotation are handled by the node-side integrations — ACME, NGINX, Apache, Java PKCS#12, HashiCorp Vault and others — with the same dual-slot staging, health checks and rollback. Revocation, CRL and OCSP for SCM-issued certificates are handled through the protected signer; see Revocation, CRL and OCSP.

Verify​

  1. Request a certificate for a profile bound to the SCM integration, for example through ACME or Request certificate in ConsoleCertificates.
  2. Confirm it appears under ConsoleCertificates with the expected issuer.
  3. Confirm the matching order appears in SCM under your organization and certificate type.

Troubleshooting​

SymptomCauseFix
Enter the SCM organization and certificate type IDs before connecting Sectigo SCM.One or both IDs empty or not numericEnter positive whole numbers
Enter a descriptive connector name.Name shorter than 3 charactersUse a longer name
No connector in Active SCM connectorThe connector is not active or not an SCM connectorCheck it in ConsoleCAs & signing
Save desired state is disabledIntegration enabled without a connector, or the profile is shorter than 2 charactersSelect a connector and enter a profile
Card Degraded with scm connectivity not verifiedExpected — no live check existsVerify by issuing a test certificate
Issuance through SCM failsWrong organization or certificate type ID, or the IDs were changed and the registry has not been republished yetCorrect the IDs; allow for the next registry publication
Permission or re-authentication error on saveMissing can_manage_ca or stale MFAAsk an administrator for the permission; re-authenticate