Understand supported configurations
DigiCert® Private CA for U.S. government agencies supports the following configurations and operations.
Supported cryptographic modules
Private CA uses NIST 140-3 Cryptographic Module Validation Program (CMVP) validated modules for cryptographic operations that protect U.S. government customer data.
Module | Version | CMVP certificate | Private CA operation |
|---|---|---|---|
Go Cryptographic Module (built via GOFIPS140 by Geomys LLC) | v1.0.0 | #5247 | CA key generation Certificate signing CRL and OCSP signing Key import validation SCEP enrollment processing |
Supported HSMs
Private CA for U.S. government supports the following Hardware Security Module (HSM) configurations.
HSM provider and product | Model or service | FIPS validation | Supported use |
|---|---|---|---|
AWS CloudHSM | hsm2m.medium | FIPS 140-3 Level 3 | Creation of Root/ICA keys Creation of OCSP Responder Certificate keys Signing operations for the issuance of certificates |
Supported HSM operations:
Generate CA keys
Creation of root CA, issuing CA (ICA), and OCSP responder signing keys directly within the HSM.
In FIPS mode, constrained to RSA 2048/3072/4096 and ECDSA P-256/P-384/P-521; Ed25519 and all PQC algorithms are rejected
Import CA keys
Import of externally generated key material via PKCS#12 (Import CA), OCSP responder key import, and CSR-based CA creation.
In FIPS mode the imported key's algorithm and signature algorithm are validated at import time and rejected if non-approved.
Other supported operation
Use of HSM-resident private keys for end-entity certificate issuance, CRL signing, and OCSP response signing. These are the highest-volume HSM operations in normal running.
In FIPS mode the signature algorithm is validated on each path (SHA-1 and MD5 rejected)
Supported algorithms and key configurations
Private CA for U.S. government supports the following algorithms and key configurations.
Capability | Supported values |
|---|---|
CA key algorithms | RSA and ECDSA. Ed25519 and post-quantum key algorithms are not supported in FIPS mode. |
RSA key sizes | 2048, 3072, and 4096 bits. RSA keys smaller than 2048 bits are blocked. |
Elliptic curves | NIST P-256, P-384, and P-521. P-224, Brainpool, secp256k1, and other curves are blocked |
Signature algorithms | SHA-256, SHA-384, and SHA-512 with RSA; SHA-256, SHA-384, and SHA-512 with RSA-PSS; and SHA-256, SHA-384, and SHA-512 with ECDSA. MD5, SHA-1, and SHA-3 signature combinations are blocked. |
Hash algorithms | SHA-256, SHA-384, and SHA-512 for supported RSA, RSA-PSS, and ECDSA signatures. MD5, SHA-1, and SHA-3 are not supported for certificate signing in FIPS mode. |
Random-number generation | Uses the NIST CMVP-validated Go Cryptographic Module v1.0.0 through GOFIPS140 for cryptographic operations in FedRAMP FIPS mode. |
Post-quantum algorithms | Not supported. ML-DSA, SLH-DSA, and FN-DSA are blocked until a CMVP-validated module that includes them is available. |
Certificate key algorithms | RSA and ECDSA public keys are allowed for certificate issuance. Ed25519 and post-quantum public keys are blocked. |
Certificate key sizes | RSA 2048, 3072, and 4096 bits; ECDSA P-256, P-384, and P-521. |
TLS versions | Use the TLS versions allowed by the DigiCert ONE for U.S. government platform FIPS configuration. |
TLS cipher suites | Use FIPS-approved TLS cipher suites from the maintained DigiCert ONE for U.S. government platform configuration. DES, 3DES, MD5, SHA-1, and non-FIPS cipher suites are not supported. |
The Private CA user interface presents only the cryptographic options supported in the U.S. government environment. The REST APIs validate submitted values against the same supported configuration.
Supported key operations
Private CA for U.S. government supports the following key operations.
Operation | Support |
|---|---|
Generate CA keys | Supported using AWS CloudHSM |
Import CA keys | Supported using PKCS#12 |
Export CA keys | Not supported |
Generate end entity keys | Supported for both server-side and client-side end entity key generation |
Export end entity private keys | Not supported |
Submit a subject public key | Supported using PKCS#10 or SCEP |
Key backup and recovery | Supported through AWS CloudHSM managed backups |
Recover end-entity private keys | Not supported |
CA key generation
CA keys are generated and retained in AWS CloudHSM.
Configuration | Supported setting |
|---|---|
HSM | AWS CloudHSM hsm2m.medium |
Validated cryptographic module | Marvell LS2 HSM Family |
CMVP certificate | Certificate #4703 |
FIPS validation | FIPS 140-3 Overall Level 3 |
Certificate sunset date | June 5, 2029 |
Cluster mode | FIPS mode, established when the cluster is created |
RSA key sizes | 2048, 3072, and 4096 bits |
ECDSA curves | P-256 (secp256r1), P-384 (secp384r1), and P-521 (secp521r1) |
Signature algorithms | SHA-256, SHA-384, or SHA-512 with RSA PKCS#1 v1.5, RSA-PSS, or ECDSA |
CA signing keys are created with the following PKCS#11 attributes:
CKA_EXTRACTABLE = CK_FALSE
CKA_SENSITIVE = CK_TRUE
CKA_NEVER_EXTRACTABLE = CK_TRUE
These attributes prevent CA signing keys from being exported from the HSM and provide evidence that the keys have never been exportable.
Private CA starts only when it is configured with the supported AWS CloudHSM configuration. Only the algorithms and key sizes listed in this section are available for CA key generation and signing.
CA key import
CA private keys can be imported into the Private CA as PKCS#12 containers. The Private CA validates the key and signature algorithms before unwrapping the key material and storing it in AWS CloudHSM through PKCS#11.
AWS CloudHSM supports the following key-wrapping mechanisms:
Mechanism | Standard |
|---|---|
CKM_CLOUDHSM_AES_KEY_WRAP_NO_PAD | AES Key Wrap, RFC 3394 |
CKM_CLOUDHSM_AES_KEY_WRAP_ZERO_PAD | AES Key Wrap with Padding, RFC 5649 |
CKM_RSA_AES_KEY_WRAP | RSA-AES Key Wrap |
CKM_RSA_PKCS_OAEP | RSA OAEP |
The AES key-wrapping mechanisms comply with NIST SP 800-38F. RSA key transport uses RSA OAEP or RSA-AES Key Wrap; RSA PKCS#1 v1.5 key transport is not used.
A CA can also be created from a submitted certificate signing request (CSR). With this method, the CA private key is not imported into the Private CA.
End entity key generation
Private CA supports both server-side and client-side end entity key generation.
End entity private keys generated server-side are not escrowed and cannot subsequently be recovered or exported.
Subject public key submission
Private CA accepts subject public keys through the following enrollment methods:
Enrollment method | Support |
|---|---|
PKCS#10 CSR | Supported through the REST API |
SCEP | Supported using RFC 8894 profiles |
Submitted keys and CSRs must use the following cryptographic configurations:
RSA with a key size of 2048, 3072, or 4096 bits
ECDSA using P-256, P-384, or P-521
SHA-256, SHA-384, or SHA-512 with RSA, RSA-PSS, or ECDSA for CSR signatures
SCEP support is limited to RFC 8894 profiles using AES-128-CBC or AES-256-CBC. SCEP Draft 23 profiles are not supported because they require 3DES.
CA key backup and recovery
CA key backup and recovery are provided through the AWS CloudHSM managed backup service. Private CA does not provide a separate application-level key backup, export, or escrow mechanism.
AWS CloudHSM creates an encrypted cluster backup at least once every 24 hours. A backup includes:
HSM users
Key material
Certificates
HSM configuration and policies
Backup retention can be configured from 7 through 379 days. The default retention period is 90 days. Customers cannot initiate backups manually.
AWS CloudHSM protects backup key material as follows:
Key material does not leave the HSM in plaintext.
Backup data is protected using an AES key-wrapping method compliant with NIST SP 800-38F.
The ephemeral backup key is wrapped by a persistent backup key derived using a KDF compliant with NIST SP 800-108.
Backup data receives an additional encryption layer using AWS KMS before being stored in a service-controlled Amazon S3 bucket.
AWS does not possess the manufacturer backup key required to decrypt the HSM backup.
FIPS-mode backups can be restored only to FIPS-mode AWS CloudHSM clusters that use AWS-owned HSMs from the same manufacturer.
Supported enrollment and certificate-status interfaces
Private CA for U.S. government supports the following enrollment and certificate-status interfaces.
Interface | Availability | Supported configuration |
|---|---|---|
REST API | Available | Authentication methods, profiles, key-generation options, and API version |
OCSP | Available | Signing configuration, algorithms, and responder URL |
CRL | Available | Signing configuration, publication options, and distribution-point URL |
Private CA enrollment and certificate-status services use endpoints specific to DigiCert ONE for U.S. government.
Security configuration capabilities
Account settings for Private CA are managed in Account Manager. See Manage your account to learn about the security configuration capabilities available in the U.S. government deployment.
Configuration enforcement
Private CA applies the supported U.S. government configuration consistently across the user interface, APIs, and enrollment services.
The user interface displays supported HSMs, algorithms, key sizes, curves, and ciphers.
APIs validate requests against the supported configuration.
Enrollment requests use supported cryptographic modules and algorithms.
Private CA rejects configuration values and operations outside the supported U.S. government configuration.