Cyber News / Article / Bring Your Own CA: Introducing the Thales Imperva SSL Integration Center, Featuring DigiCert Trust Lifecycle Manager

Bring Your Own CA: Introducing the Thales Imperva SSL Integration Center, Featuring DigiCert Trust Lifecycle Manager
Home>Blog>Bring Your Own CA: Introducing the Thales Imperva SSL Integration Center, Featuring DigiCert Trust Lifecycle Manager
MichaelWright
,ZivRika
Aug 24, 20264 min read
Somewhere in your estate right now, a certificate is counting down to its expiry date. Today you probably know which one, because renewals still come around annually and someone owns the calendar. The industry is taking that comfort away: the CA/Browser Forum has voted to cut the maximum TLS certificate lifespan to 47 days by 2029, a decision we looked at in detail inour piece on shortened renewal periods. Renewals that happen once a year will soon happen every few weeks, and every manual touchpoint in that process becomes a potential outage. The math stops working.
The honest complication is that most enterprises do not live in a single-vendor world. You may run your own internal PKI. You may have standardized on a dedicated Certificate Lifecycle Management (CLM) platform. You may answer to compliance mandates that dictate exactly which Certificate Authority issues your certificates, and how. In those environments, visibility and control across every certificate matters as much as automating the renewals themselves. Until now, connecting those established workflows to Imperva meant manual effort, and manual effort is exactly what shrinking lifecycles no longer allow.
Today we are introducing theSSL Integration Center: an integration framework connecting Imperva Cloud WAF with leading Certificate Lifecycle Management platforms. It launches with its first supported integration, theDigiCert Trust Lifecycle Manager (TLM)Agent.
The SSL Integration Center is not a new product or another console to learn. It is an integration framework, and the experience runs from the side you already live in: you configure the integration from within your CLM platform, and your CLM remains the place where certificates are managed. Once connected, two things happen from there. You can see all of your Imperva-managed domains and the SSL coverage status of each one, directly in your certificate workflow. And the complete certificate lifecycle cadence, issuance, renewal and deployment to Imperva, runs automatically under the policies your CLM already enforces. Imperva’s role is to integrate smoothly into the workflow you have, supplying application and SSL-coverage visibility and taking automated deployment off your hands. DigiCert is the first integration, and it sets the pattern for the CLM vendors that follow.
Many organizations choose Thales-managed certificates because that removes the operational load of provisioning, renewal, monitoring and deployment in one move, and for them nothing changes. Others cannot adopt a fully managed approach: compliance requirements, PKI investments, established CLM platforms and governance policies often require a customer to keep control of their own certificate ecosystem. The Integration Center is built for that second group. You keep your CA, your CLM and your lifecycle processes, exactly where they run today, and Imperva plugs into them. Governance stays yours, and so does the console.
DigiCert TLM gives enterprises one place to discover, govern, automate and see certificates across cloud, hybrid and on-premises environments. It builds an organization-wide certificate inventory, enforces consistent cryptographic policy, and replaces surprise expirations with automated renewals. A useful way to think about the pairing: TLM is the system of record for your certificates, and the Integration Center is the delivery route into the applications Imperva protects.
With this integration, the DigiCert TLM Agent automates certificate issuance, renewal and deployment straight into Imperva. Under the hood, apost-enrollment scriptsecurely uploads the certificate chain and private key to Imperva through the Provisioning API, so a certificate governed in TLM arrives at your protected applications without anyone touching it. It runs on both Linux and Windows.
The value of that automation is documented. In a commissioned Total Economic Impact study, Forrester Consulting found organizations standardizing on DigiCert ONE, the platform behind Trust Lifecycle Manager, achieved96% fewer outagesfrom expired or misconfigured certificates, and a312% return on investmentover three years.
Source:The Total Economic Impact™ of DigiCert ONE (July 2025), a commissioned study conducted by Forrester Consulting on behalf of DigiCert. Results are based on a composite organization derived from customer interviews. Forrester does not endorse DigiCert or its offerings.
Shorter certificate lifecycles are the new baseline, and they reward the organizations that automate. The SSL Integration Center makes that automation work on your terms: the CA you trust, the CLM platform you have standardized on, the compliance posture you are held to. It sits alongside Thales’s own SSL management capabilities, including certificate visibility, site coverage monitoring, notifications and real-time SSL health monitoring. DigiCert Trust Lifecycle Manager is the first integration and it will not be the last; each CLM vendor added becomes one more certificate workflow that arrives at your applications without a human in the renewal loop.
That certificate counting down in your estate? Under TLM and the Integration Center, its renewal has already happened by the time you would have thought to check.
It is also one thread in a wider fabric. Imperva integrates across the tools enterprises already run, from SIEM and ITSM platforms to API gateways, scanners and cloud providers, through the Imperva Technology Alliance Program. If your certificate stack is the workflow we meet today, the rest of your stack has a meeting point there too.
If you are a Thales Imperva Cloud WAF customer using DigiCert Trust Lifecycle Manager, you can configure the integration from your TLM console today. For step-by-step setup, see theImperva documentation on integrating custom certificatesand theDigiCert + Imperva integration overview.
Protect your business for 30 days on Imperva.
Protect your business for 30 days on Imperva.
RohitKumar
,AmritTalapatra
Aug 13, 20261 min read
LynelDsouza
Jul 30, 20266 min read
ZivRika
,GrainneMcKeever
Jun 30, 20268 min read
AmritTalapatra
Jun 25, 20263 min read
VivekPurkayastha
Jun 22, 20268 min read
EricGuillotin
,BrianSchwarz
Jun 15, 202625 min read
Cookie PreferencesTrust CenterModern Slavery StatementPrivacyLegal
Cookie PreferencesTrust CenterModern Slavery StatementPrivacyLegal
Copyright © 2026 Imperva. All rights reserved
Related articles
Your Cloud Security Checklist Doesn't Work the Way You Think It Does
4 days ago
ChatGPT can now connect to your personal apps to mimic writing style
4 days ago
Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your Perimeter
16 days ago

