TigerTrust uses a single CA abstraction: each CA you connect has a type, a config, and a health status. The same Issue button and the same renewal engine can target Let’s Encrypt today and DigiCert tomorrow without changes to your integration.
Certificate Authorities

What it is

CA Management is where you connect external CAs (Let’s Encrypt, DigiCert, AWS Private CA, HashiCorp Vault, and others) and create internal CAs powered by TigerTrust’s built-in PKI. All connected CAs appear in the issuance wizard and are available to the renewal engine.

When to use it

  • Connect Let’s Encrypt to issue and auto-renew public-facing TLS certificates.
  • Add DigiCert or Sectigo for EV or OV certificates that require organization validation.
  • Create an internal CA hierarchy for private PKI — mesh certificates, client auth, code signing.
  • Integrate HashiCorp Vault’s PKI secrets engine for team-managed issuance.

Supported CA types

CategoryTypes
ACMELet’s Encrypt, ZeroSSL, BuyPass, Google Trust Services, any RFC 8555 CA
Public / commercialDigiCert, Sectigo, GlobalSign, GoDaddy, Entrust, and others
CloudAWS Private CA, Azure Key Vault, GCP Certificate Authority Service, Cloudflare
EnterpriseVenafi, HashiCorp Vault, EJBCA, Microsoft ADCS
InternalTigerTrust PKI Core (root and intermediate CAs)

Set it up

1

Add an ACME CA

Click CA Management > Add CA > ACME. Choose Let’s Encrypt production or staging.
2

Enter a contact email

Used for expiry notices from Let’s Encrypt and for ACME account registration.
3

Choose a challenge type

HTTP-01 (via a field agent), DNS-01 (via a DNS provider integration), or TLS-ALPN-01.
4

Save

TigerTrust registers the ACME account and the CA’s health status updates to healthy on first successful directory fetch.

What you’ll see

Connected CAs appear in CA Management with a health indicator (healthy, degraded, unhealthy, unknown) and last-contact timestamp. The Health tab shows per-CA error rates and connectivity probe results. An unhealthy CA generates an alert and is skipped by the renewal engine to avoid stampeding a broken upstream.
A CA marked unhealthy is skipped by the renewal engine. Fix the CA’s credentials or connectivity, then click Test connection to re-validate. Health status updates to healthy on the next successful probe.

PKI Core

Stand up your own internal CA hierarchy.

Certificate issuance

Issue against any connected CA.

Certificate renewal

Every supported renewal method, per CA type.