Skip to main content

Secure configuration guide for DigiCert Private CA

Use this guide to configure DigiCert® Private CA in alignment with your organization's approved security, key-management, and change-management procedures. It explains the available certificate-authority controls, recommended configuration approaches, and security considerations for cryptographic enforcement, CA key protection, certificate profiles, revocation services, product access, and audit activity.

This guide supports your organization's FedRAMP authorization and ongoing compliance activities. Your organization is responsible for determining and applying the configuration, approval, and monitoring requirements that apply to its environment.

For step-by-step instructions about setting up and using the Private CA, see Get started with DigiCert Private CA.

Important

FedRAMP certification status

DigiCert for Government is pursuing FedRAMP certification. Publishing this documentation doesn't indicate certification or agency authorization. For the current status, refer to the DigiCert for Government listing in FedRAMP Marketplace.

In this guide

The following sections explain how to securely configure and operate DigiCert Private CA in compliance with FedRAMP requirements.

Section

What it covers

Understand supported configurations

Supported cryptographic module, HSM, algorithms, key sizes, elliptic curves, signature algorithms, key operations, enrollment methods, and CA key backup and recovery.

Understand what Private CA controls

Private CA responsibilities, including CA lifecycle management, certificate profiles, certificate issuance and revocation, revocation services, and product audit logging.

Understand which controls DigiCert enforces

Security controls enforced by Private CA, including cryptographic enforcement, use of the supported HSM, prevention of unsupported cryptographic selections, key-protection requirements, and protocol restrictions.

Understand account management responsibilities

Responsibilities divided between Account Manager and Private CA, including authentication, user management, API credentials, Private CA authorization, and service users.

Critical Private CA roles and permissions

Account and system roles, critical permissions, custom roles, combined permissions, separation of duties, and roles available for Private CA in customer-hosted DigiCert ONE.

Configure certificate authorities securely

CA hierarchy, CA key and signature configuration, validity periods, revocation distribution points, and controls for creating, activating, and revoking CAs.

Configure certificate profiles and issuance policy

Certificate algorithms, key requirements, validity periods, subject and SAN restrictions, enrollment methods, and profile change control.

Manage revocation services

OCSP and CRL configuration, distribution-point availability, CRL-generation intervals, and revocation propagation.

Protect keys and secrets

Storage and rotation of integration credentials, protection of secrets, and access to key escrow and recovery operations.

Review product activity and access

Private CA audit logs, user and service-user access reviews, combined-role permissions, separation of duties, and integration-credential reviews.

Remove administrative and privileged access

Transfer of responsibilities, credential revocation, role removal, account deactivation, audit-log review, and preservation of required administrative access.

Secure configuration history

Changes to secure configuration recommendations and enforced Private CA behavior.

Quick links

Account Manager security guidance, Private CA roles and permissions, product administration instructions, and release notes.