Configure certificate authorities securely
Before creating or activating a CA:
Confirm the CA hierarchy design is approved by your organization.
Select a FIPS 140-3 approved key algorithm, key size, and signature algorithm from the available options: RSA (2048, 3072, or 4096 bits) or ECDSA (P-256, P-384, or P-521), with SHA-256, SHA-384, or SHA-512 signature algorithms (ECDSA, RSA, or RSA-PSS).
Confirm the CA key will be generated in the FIPS 140-3 validated hardware security module. This is enforced in the FedRAMP deployment.
Define validity periods that meet your agency's policy.
Confirm revocation distribution points are reachable before the CA issues certificates.
Restrict CA creation, activation-status changes, and CA revocation to authorized administrators. Revoking a CA invalidates every certificate it has issued and cannot be undone. Follow your organization's change-approval procedure before making CA status changes in a production environment.