DigiCert 2FA: How to Set Up an Authenticator App
Your DigiCert CertCentral account is where your organisation manages its certificates. CertCentral requires two-factor authentication (2FA) for all accounts: after your username and password, you confirm with a one-time password (OTP) or a client certificate. With OTP, you connect an app that supports TOTP, such as Authenticator App - Novaz, the first time you sign in.
A DigiCert account is part of your security setup, so it deserves strong 2FA of its own. DigiCert secures sign-ins with an authenticator app — set it up once and you're protected on every login.
2FA methods DigiCert supports
- Authenticator app (TOTP)
Before you start
- Your CertCentral username and password
- A CertCentral administrator must have added you to CertCentral, or reset your OTP method, before you start
- "One-time password (OTP)" set as your second factor by an administrator: the other option, "Client certificate", doesn't use an authenticator app
- Authenticator App - Novaz installed on your iPhone or iPad
- The CertCentral sign-in page open on a computer, so the QR code is on a different screen from your phone
Part 1: Turn on 2FA in DigiCert
- 1
Sign in to CertCentral
On the CertCentral sign-in page, enter your username and password, then select "Sign in". CertCentral redirects you to the "One-time password (OTP) device initialization" page.
- 2
Pick an app from the dropdown
Under "Install an authentication application", select an OTP app from the dropdown. Authenticator App - Novaz isn't on DigiCert's tested list, but CertCentral only needs an app that supports TOTP, so choose a listed option such as Google Authenticator.
- 3
Keep the QR code on screen
Under "Scan QR code or enter setup key", CertCentral shows a QR code and a setup key. Leave the page open.
Part 2: Add DigiCert to Authenticator App - Novaz
- 4
Add CertCentral in Authenticator App - Novaz
Open Authenticator App - Novaz, tap the + button and scan the QR code. If it won't scan, choose to enter a setup key and type the key exactly as shown, using "DigiCert CertCentral" as the account name, then tap "Save".
- 5
Note the one-time passcode
Authenticator App - Novaz now shows a passcode for CertCentral. Each one works only for a limited time and can't be reused, so have the current one ready.
Part 3: Confirm and finish
- 6
Enter the code and select Verify device
Back on CertCentral, enter the passcode under "Enter verification code", then select "Verify device".
- 7
Know when CertCentral will ask for a code
From now on you enter a code from Authenticator App - Novaz each time you sign in. If your administrator has turned on 30-day device verification, you'll see "Remember verification on this computer" when you enter it.
- 8
Save a way to recover your account
If DigiCert offers backup or recovery codes, download them or write them down and store them somewhere safe. They are how you get back into your account if you ever lose your phone. If it doesn't, check how DigiCert recovers accounts before you need it.
If something goes wrong
- You don't see the "One-time password (OTP) device initialization" page: your administrator may not have added you or reset your OTP method yet, or your account uses a client certificate. Ask a CertCentral administrator.
- CertCentral rejects the code: make sure your iPhone sets its date and time automatically (Settings > General > Date & Time), then enter the newest code.
- You're locked out after too many wrong passcodes: only an administrator can reset a locked OTP method.
- You have a new phone: ask an administrator to reset your OTP method, then scan the new QR code with Authenticator App - Novaz at your next sign-in.
Checked against DigiCert's own help pages on September 25, 2026. Menu names can change, so these pages have the current path:
- Configure two-factor authentication – DigiCert product docs ↗
- Set up your OTP app – DigiCert product docs ↗
- Set the default second factor – DigiCert product docs ↗
- Enable 30-day device verification for OTP app authentication – DigiCert product docs ↗
- Reset a user's one-time password method – DigiCert product docs ↗
How to recover your DigiCert account
DigiCert's docs don't describe backup codes for CertCentral: recovery goes through an administrator. If you lose the phone with Authenticator App - Novaz, ask an administrator to go to Settings > Authentication Settings, select the "Two-factor authentication" tab, then "One-time password (OTP) methods", locate you and select "Reset". The reset takes effect immediately, CertCentral emails you instructions, and you set up a new OTP method the next time you sign in. The docs only describe resets by an administrator.
Frequently asked questions
- Can I turn off two-factor authentication in CertCentral?
- No. CertCentral requires it for all accounts. An administrator decides whether your second factor is a one-time password (OTP) or a client certificate.
- Does Authenticator App - Novaz work with CertCentral?
- Yes. CertCentral asks for an app that supports the TOTP protocol. DigiCert lists Google Authenticator, Authy, Authenticator and Duo Mobile as tested, but the codes follow the same standard.
- Will CertCentral ask for a code every time I sign in?
- Yes, unless an administrator enables "Remember verification for 30 days". You can then choose "Remember verification on this computer" and enter a code again after 30 days. This applies to OTP apps, not OTP email verification.
- How does an administrator make OTP the default second factor?
- Go to Settings > Authentication Settings, select the "Default settings" tab, choose "One-time password (OTP)" under "Two-factor authentication settings" and select "Save". User-specific requirements override this default, and users set up the new method at their next sign-in.
Generate your DigiCert codes in Authenticator App - Novaz
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Security guides
Novaz is not affiliated with, endorsed by, or sponsored by DigiCert. DigiCert and its logo are trademarks of their respective owner and are used here for identification only.



