Certificate lifecycle automation — DigiCert Trust Lifecycle Manager
Apache, nginx and Tomcat all run on this single machine on different ports. Each terminates TLS with its own certificate, and a single agent discovers and renews all three independently.
When a renewal is triggered in Trust Lifecycle Manager, the agent installs the new certificate and reloads the service. The serial number above changes — with no downtime and no administrator touching the server.
TLS is passed through unterminated by the gateway, so your browser negotiates directly with nginx 1.24 on this host. The certificate shown above is read from the live connection, not from a file.
Served by nginx 1.24 on port 9443 · details refresh automatically every 30 seconds