Secure configuration guide for DigiCert Private CA
Use this guide to configure DigiCert® Private CA in alignment with your organization's approved security, key-management, and change-management procedures. It explains the available certificate-authority controls, recommended configuration approaches, and security considerations for cryptographic enforcement, CA key protection, certificate profiles, revocation services, product access, and audit activity.
This guide supports your organization's FedRAMP authorization and ongoing compliance activities. Your organization is responsible for determining and applying the configuration, approval, and monitoring requirements that apply to its environment.
For step-by-step instructions about setting up and using the Private CA, see Get started with DigiCert Private CA.
Important
FedRAMP certification status
DigiCert for Government is pursuing FedRAMP certification. Publishing this documentation doesn't indicate certification or agency authorization. For the current status, refer to the DigiCert for Government listing in FedRAMP Marketplace.
In this guide
The following sections explain how to securely configure and operate DigiCert Private CA in compliance with FedRAMP requirements.
Section | What it covers |
|---|---|
Supported cryptographic module, HSM, algorithms, key sizes, elliptic curves, signature algorithms, key operations, enrollment methods, and CA key backup and recovery. | |
Private CA responsibilities, including CA lifecycle management, certificate profiles, certificate issuance and revocation, revocation services, and product audit logging. | |
Security controls enforced by Private CA, including cryptographic enforcement, use of the supported HSM, prevention of unsupported cryptographic selections, key-protection requirements, and protocol restrictions. | |
Responsibilities divided between Account Manager and Private CA, including authentication, user management, API credentials, Private CA authorization, and service users. | |
Account and system roles, critical permissions, custom roles, combined permissions, separation of duties, and roles available for Private CA in customer-hosted DigiCert ONE. | |
CA hierarchy, CA key and signature configuration, validity periods, revocation distribution points, and controls for creating, activating, and revoking CAs. | |
Certificate algorithms, key requirements, validity periods, subject and SAN restrictions, enrollment methods, and profile change control. | |
OCSP and CRL configuration, distribution-point availability, CRL-generation intervals, and revocation propagation. | |
Storage and rotation of integration credentials, protection of secrets, and access to key escrow and recovery operations. | |
Private CA audit logs, user and service-user access reviews, combined-role permissions, separation of duties, and integration-credential reviews. | |
Transfer of responsibilities, credential revocation, role removal, account deactivation, audit-log review, and preservation of required administrative access. | |
Changes to secure configuration recommendations and enforced Private CA behavior. | |
Account Manager security guidance, Private CA roles and permissions, product administration instructions, and release notes. |