DigiCert KnowledgeBase - Technical Support-hero

Knowledge Base

How to Migrate Certificate Profiles to Use New CA | PKI Platform

Solution ID : TL060619224107
Last Modified : 06/13/2024



This article describes the actors, pre-requisites and the 2 main options available to account Administrators to ‘migrate’ from an existing certificate profile configured against a Symantec Public CA hierarchy, to a certificate profile configured against a DigiCert Public Issuing CA hierarchy (whether a Shared Public CA or a Co-branded Public CA):

  • Using the “Profile migrate” functionality
  • Creating a New certificate profile and replicating the configuration settings

Process steps for both options, as well as a more complex configuration use-case are outlined in detail in the following article: PKI Client Autoenrollment



  • [SE] DigiCert Systems Engineers & Consultants
  • [PKI Ops] DigiCert PKI Operations – DigiCert team responsible for CA Key Ceremonies
  • [PKI Admin] Customer PKI Admin – Customer PKI Administrator with certificate to access the PKI Manager portal
  • [AD Admin] Customer AD Administrator – Customer Active Directory (AD) Administrator



  • Account is Active
  • For Customers with their own Public Co-branded CA (chaining up to a Symantec Root CA):
    • A new CA Naming document needs to be completed and signed (using the new “DigiCert Assured ID Root G2” CA as the issuer).
      Liaise with your DigiCert customer representative or Systems Engineer/Consultant for support.
    • The new Public Co-branded CA needs to be created by the DigiCert PKI Operations team.
    • The new Public Co-branded CA must have been loaded onto the Customer’s account.
  • For Customers using certificate profiles (e.g. Secure Email) bound to a Symantec Shared CA, wait for the new DigiCert Shared CA to be loaded against all accounts.

New DigiCert PKI Platform Class 2 and Class 3 Shared Public CAs

The following table shows the new DigiCert Class 2 and Class 3 Shared Public CAs available to customers from the 29th of May 2019, the Base Certificate Templates (BCTs) they will be bound to, the account type they will be available on, as well as how they will be made available (on-demand vs automatically):

Shared CA
Common Name
Automatically loaded vs
Account Type BCTs to be bound
DigiCert PKI Platform Class C2 Shared SMIME Individual Subscriber CA Automatic Standard Full

Secure Email

SMIME (Signing Only)

S/MIME (Encryption Only)

DigiCert PKI Platform Class C2 Shared SMIME Individual Subscriber TEST CA On-demand

Standard Full

Private Verified

Private Unverified

Secure Email

SMIME (Signing Only)

S/MIME (Encryption Only)

DigiCert PKI Platform Class C2 Shared Individual Subscriber CA On-demand Standard Full Client Authentication
DigiCert PKI Platform Class C2 Shared Individual Subscriber TEST CA On-demand

Standard Full

Private Verified

Private Unverified

Client Authentication
DigiCert PKI Platform Class C3 Shared SMIME Organization CA Automatic Standard Full Secure Email Gateway BCT
DigiCert PKI Platform Class C3 Shared SMIME Organization TEST CA On-demand

Standard Full

Private Verified

Private Unverified

Secure Email Gateway BCT

All new Shared CAs will chain up to the “DigiCert Assured ID Root G2” CA:























What process should I follow?

There are 3 main process flows you can follow in order to start making use of the new DigiCert Public CA hierarchy (whether Public Shared CAs or Public Co-Branded):

1) Use the “Migrate profile” functionality

Pros: Quick process.
Recommended for customers with lots of certificate profile needing to be migrated onto a DigiCert Public CA hierarchy.
Less prone to error.
Cons: The old and new profiles become locked – no further changes can be made to neither certificate profiles.


2) Create a New Certificate Profile for non-PKI Client Autoenrollment use-case

Pros: The newly created certificate profile is editable in the same way as the older one.
Cons: The process to create the new certificate profiles is longer than when using the “Migrate profile” process.
More prone to error.


3) Create a New Certificate Profile for PKI Client Autoenrollment use-case

Pros: The newly created certificate profile is editable in the same way as the older one.
Cons: The process to create the new certificate profiles is a lot longer than when using the “Migrate profile” process.
More prone to error.
More exhaustive testing required before decommissioning the older certificate profile.

Please follow the below KB articles for "Migrate profile” and “PKI Client Autoenrollment” process flows:

For Migrate Certificate profile use the following KB


For PKI Client Autoenrollment use the following KB


For Non-PKI Client Autoenrollment use the following KB



If you have issues performing these steps, please contact PKI Support.