Somewhere in your estate right now, a certificate is counting down to its expiry date. Today you probably know which one, because renewals still come around annually and someone owns the calendar. The industry is taking that comfort away: the CA/Browser Forum has voted to cut the maximum TLS certificate lifespan to 47 days by 2029, a decision we looked at in detail in our piece on shortened renewal periods. Renewals that happen once a year will soon happen every few weeks, and every manual touchpoint in that process becomes a potential outage. The math stops working.
The honest complication is that most enterprises do not live in a single-vendor world. You may run your own internal PKI. You may have standardized on a dedicated Certificate Lifecycle Management (CLM) platform. You may answer to compliance mandates that dictate exactly which Certificate Authority issues your certificates, and how. In those environments, visibility and control across every certificate matters as much as automating the renewals themselves. Until now, connecting those established workflows to Imperva meant manual effort, and manual effort is exactly what shrinking lifecycles no longer allow.
Today we are introducing the SSL Integration Center: a new home inside your Imperva cloud account for connecting external certificate workflows to the applications Thales’s Imperva protects. It launches with its first supported integration, the DigiCert Trust Lifecycle Manager (TLM) Agent.
Built as a framework for certificate lifecycle management
The SSL Integration Center is a framework rather than a single connector. It gives your existing certificate processes a native route into Imperva, wherever they live: an enterprise CLM platform, an internal PKI, or several Certificate Authorities at once. Those processes then drive issuance, renewal and deployment automatically. The goal is to meet your certificate workflows where they already live instead of asking you to rebuild them. DigiCert is the first integration we are shipping, and it sets the pattern for the CLM vendors that follow.
Thales-managed or customer-managed: your choice
Many organizations choose Thales-managed certificates because that removes the operational load of provisioning, renewal, monitoring and deployment in one move, and for them nothing changes. Others cannot adopt a fully managed approach: compliance requirements, PKI investments, established CLM platforms and governance policies often require a customer to keep control of their own certificate ecosystem. The Integration Center is built for that second group. You keep your CA, your CLM and your lifecycle processes, and you connect them to Imperva for the automation. Governance stays yours.
Starting with a leader: DigiCert Trust Lifecycle Manager
DigiCert TLM gives enterprises one place to discover, govern, automate and see certificates across cloud, hybrid and on-premises environments. It builds an organization-wide certificate inventory, enforces consistent cryptographic policy, and replaces surprise expirations with automated renewals. A useful way to think about the pairing: TLM is the system of record for your certificates, and the Integration Center is the delivery route into the applications Imperva protects.
With this integration, the DigiCert TLM Agent automates certificate issuance, renewal and deployment straight into Imperva. Under the hood, a post-enrollment script securely uploads the certificate chain and private key to Imperva through the Provisioning API, so a certificate governed in TLM arrives at your protected applications without anyone touching it. It runs on both Linux and Windows.
The value of that automation is documented. In a commissioned Total Economic Impact study, Forrester Consulting found organizations standardizing on DigiCert ONE, the platform behind Trust Lifecycle Manager, achieved 96% fewer outages from expired or misconfigured certificates, and a 312% return on investment over three years.
Source: The Total Economic Impact™ of DigiCert ONE (July 2025), a commissioned study conducted by Forrester Consulting on behalf of DigiCert. Results are based on a composite organization derived from customer interviews. Forrester does not endorse DigiCert or its offerings.
How the DigiCert TLM integration works
- Govern in DigiCert TLM. Your certificate is issued and managed centrally, under the policies your organization already enforces.
- Automate with the TLM Agent. A post-enrollment script runs on issuance or renewal and packages the certificate chain and private key.
- Deploy through the Provisioning API. The script securely uploads the certificate to your Imperva cloud account and puts it to work protecting your applications. No manual upload. No missed renewal window.
What this means for your team
- Continuous, compliant TLS protection. Issuance, renewal and deployment of custom certificates run without manual intervention, so your encryption stays current as lifecycles shrink.
- Full bring-your-own-CA automation. If you use your own Certificate Authority and custom certificates, the entire lifecycle can now run end to end.
- Fewer outages, less toil. Removing the manual steps removes the TLS outages that come from missed renewals, and frees your team from certificate babysitting.
- One view of certificate health. DigiCert’s organization-wide discovery and lifecycle management pairs with Imperva’s application protection insight, so you can see certificate health and protected-application coverage from a central place, across vendors, environments and business units.
A certificate automation ecosystem that grows with you
Shorter certificate lifecycles are the new baseline, and they reward the organizations that automate. The SSL Integration Center makes that automation work on your terms: the CA you trust, the CLM platform you have standardized on, the compliance posture you are held to. It sits alongside Thales’s own SSL management capabilities, including certificate visibility, site coverage monitoring, notifications and real-time SSL health monitoring. DigiCert Trust Lifecycle Manager is the first integration and it will not be the last; each CLM vendor added becomes one more certificate workflow that arrives at your applications without a human in the renewal loop.
That certificate counting down in your estate? Under TLM and the Integration Center, its renewal has already happened by the time you would have thought to check.
Get started with the SSL Integration Center
If you are a Thales Imperva Cloud WAF customer using DigiCert Trust Lifecycle Manager, you can connect the two through the SSL Integration Center today. For step-by-step setup, see the Imperva documentation on integrating custom certificates and the DigiCert + Imperva integration overview.
Try Imperva for Free
Protect your business for 30 days on Imperva.





