Fujitsu has partnered with DigiCert to bring together the DigiCert ONE platform with Fujitsu's consulting, integration, and managed services expertise, providing customers with an automated approach to certificate lifecycle management.
Through this partnership, Fujitsu will deliver implementation, integration and managed services for the company’s DigiCert ONE platform, a platform that touts the ability to bring PKI and DNS together across machines, software, and devices under one trust model; automate PKI workflows and reduce DNS misconfigurations; and centralise visibility and governance.
The partnership is a direct response to security challenges such as the CA/Browser Forum, an industry body of browser and security certificate providers that sets web security policy, reducing public Transport Layer Security (TLS) certificate lifetimes from what was 398 days less than six months ago to just 47 days by 2029.
TLS certificates - most commonly known as SSL, or digital certificates - secure internet connections by encrypting data sent between a browser, the website being visited, and the website server, ensuring that data is transmitted privately and without modifications, loss or theft.
In addition, the Australian Signals Directorate has recommended that by the end of this year, organisations should have a plan for their transition to post-quantum cryptography (PQC); by the end of 2028, organisations should have commenced their transition to PQC, starting with their critical systems and data; and by the end of 2030, organisations should have completed their PQC transition.
As such, the joint offering between Fujitsu and DigiCert aims to enable organisations to gain complete visibility of their digital certificates, before replacing the manual renewal process with a fully automated system that intends to prevent problems before they happen.
James Richmond, head of Fujitsu Cyber Security Services, said that the partnership gives Fujitsu the opportunity to sit over and above what the DigiCert platform does, as well as allowing the company to layer in key aspects of its capability set.
“Natural to Fujitsu is developing relationships with customers around governance, integration, managed services, but the extra piece that the cyber team and I bring to the equation is this cyber resilience expertise set that's been years in the making for us,” he said.
“Formalising this partnership in the way that we have is our way of drawing more attention to the burning need for the DigiCert platform in automating lifecycle management.
“Fujitsu is a DigiCert customer in its own right [too], so having that extra hands-on experience in evaluating the solution, deploying it in a reasonably complex environment and then understanding in detail what the customer - us in this instance - has gotten out of it is a fantastic and powerful story to be able to take to the customer.”
Daniel Sutherland, VP of Digicert in ANZ, said that the partnership between his company – which counts a customer base of around 6,000 across Australia and New Zealand - and Fujitsu comes at a time when the way of managing digital trust across an organisation is shifting simultaneously alongside the nature of infrastructure.
“You have a lot more complexity, you have a greater number of use cases where organisations are distributing certificates across their environments, and that's just increased the complexity which is being managed by organisations,” he told techpartner.news.
“Digital certificates touch every aspect of an enterprise - cyber, infrastructure, cloud, operations teams. When you're looking for a partnership and an outcome for an organisation, working with a partner that can cover those different business units within an organisation made Fujitsu a really exciting proposition for DigiCert as a partnership.”
Sutherland said that a “fundamental shift” that DigiCert has heard from customers over the last two to three years is organisations wanting more support, knowledge and understanding of how to roll out that automation of certificate lifecycle management.
“[They’re asking] can we get support with implementation? Can we take it a step further and get that managed services support for our organisation?" he explained.
"They want to manage the outcome; they want to be putting their investment into what's going to be a faster time to value for them as a business; they want to make sure that this PKI and digital trust is maintained with a strong resiliency layer.
“It moves from less of an expiry and ad hoc management process into more of a certificate lifecycle management operational model.”
That move into a formal operational model is needed, according to Sutherland, due to the number of machine identities that now exists in the wider market.
Sutherland stated that number now stands at around 100 machine identities for every one human identity – a number increased over two times from a few years ago when that figure was sitting at around only 40 machine identities.
“You've got this perfect storm of the number of machine identities increasing, and then the turnovers that we have to manage also increasing by a factor of eight, and that's before we get into how we validate domains and all the other complexities that come with it,” he said.
“It’s a huge risk for organisations in terms of how do you govern this space, but it's also a risk operationally because as the operational turnover increases, the propensity for mistakes or gaps or mis-renewals to happen also increases, and that fundamentally leads to outages or brand damage for organisations when services go down.
“That is the real key factor that's creating a little bit of urgency in the market - how do we shift from what we've done as a traditional model, which is a heavily manual process, to building more operational resiliency.”
Sutherland said that problems currently affecting the industry – such as a lack of visibility or missing expiries - are all symptoms of the same underlying issue: the fact that there's too much of that aforementioned manual process involved in the way the certificate lifecycle management space is currently managed.
“A lot of organisations that DigiCert speaks to are managing this space in the same way they've been doing it for 15 years, and that creates a real challenge as we move into ‘what does certificate lifecycle management look like when we're provisioning certificates to AI agents in our organisation, and the number of digital certificates actually increases because we want to secure those agents?’” he told techpartner.news.
“What does it look like when we transition to post-quantum cryptography? How do we manage that change in process? These are all future state requirements that [don’t even touch on] the underlying day-to-day operations that we need to manage today.”
Richmond agreed, saying that as it relates to that readiness conversation, you can't control what you can't see.
“Knowing where your cryptography exists is a very important part of the thought process,” he said.
“Putting in place an automated solution that provides the governance layer, the visibility layer, the observability layer and then the automation that goes with it, is only going to put you in a far better position to be ready.”




