Skip to main content

Configure certificate authorities securely

Before creating or activating a CA:

  • Confirm the CA hierarchy design is approved by your organization.

  • Select a FIPS 140-3 approved key algorithm, key size, and signature algorithm from the available options: RSA (2048, 3072, or 4096 bits) or ECDSA (P-256, P-384, or P-521), with SHA-256, SHA-384, or SHA-512 signature algorithms (ECDSA, RSA, or RSA-PSS).

  • Confirm the CA key will be generated in the FIPS 140-3 validated hardware security module. This is enforced in the FedRAMP deployment.

  • Define validity periods that meet your agency's policy.

  • Confirm revocation distribution points are reachable before the CA issues certificates.

Restrict CA creation, activation-status changes, and CA revocation to authorized administrators. Revoking a CA invalidates every certificate it has issued and cannot be undone. Follow your organization's change-approval procedure before making CA status changes in a production environment.