Skip to main content

Understand supported configurations

DigiCert® Private CA for U.S. government agencies supports the following configurations and operations.

Supported cryptographic modules

Private CA uses NIST 140-3 Cryptographic Module Validation Program (CMVP) validated modules for cryptographic operations that protect U.S. government customer data.

Module

Version

CMVP certificate

Private CA operation

Go Cryptographic Module

(built via GOFIPS140 by Geomys LLC)

v1.0.0

#5247

Certificate link

CA key generation

Certificate signing

CRL and OCSP signing

Key import validation

SCEP enrollment processing

Supported HSMs

Private CA for U.S. government supports the following Hardware Security Module (HSM) configurations.

HSM provider and product

Model or service

FIPS validation

Supported use

AWS CloudHSM

hsm2m.medium

FIPS 140-3 Level 3

Creation of Root/ICA keys

Creation of OCSP Responder Certificate keys

Signing operations for the issuance of certificates

Supported HSM operations:

  • Generate CA keys

    • Creation of root CA, issuing CA (ICA), and OCSP responder signing keys directly within the HSM.

    • In FIPS mode, constrained to RSA 2048/3072/4096 and ECDSA P-256/P-384/P-521; Ed25519 and all PQC algorithms are rejected

  • Import CA keys

    • Import of externally generated key material via PKCS#12 (Import CA), OCSP responder key import, and CSR-based CA creation.

    • In FIPS mode the imported key's algorithm and signature algorithm are validated at import time and rejected if non-approved.

  • Other supported operation

    • Use of HSM-resident private keys for end-entity certificate issuance, CRL signing, and OCSP response signing. These are the highest-volume HSM operations in normal running.

    • In FIPS mode the signature algorithm is validated on each path (SHA-1 and MD5 rejected)

Supported algorithms and key configurations

Private CA for U.S. government supports the following algorithms and key configurations.

Capability

Supported values

CA key algorithms

RSA and ECDSA.

Ed25519 and post-quantum key algorithms are not supported in FIPS mode.

RSA key sizes

2048, 3072, and 4096 bits.

RSA keys smaller than 2048 bits are blocked.

Elliptic curves

NIST P-256, P-384, and P-521.

P-224, Brainpool, secp256k1, and other curves are blocked

Signature algorithms

SHA-256, SHA-384, and SHA-512 with RSA; SHA-256, SHA-384, and SHA-512 with RSA-PSS; and SHA-256, SHA-384, and SHA-512 with ECDSA.

MD5, SHA-1, and SHA-3 signature combinations are blocked.

Hash algorithms

SHA-256, SHA-384, and SHA-512 for supported RSA, RSA-PSS, and ECDSA signatures.

MD5, SHA-1, and SHA-3 are not supported for certificate signing in FIPS mode.

Random-number generation

Uses the NIST CMVP-validated Go Cryptographic Module v1.0.0 through GOFIPS140 for cryptographic operations in FedRAMP FIPS mode.

Post-quantum algorithms

Not supported. ML-DSA, SLH-DSA, and FN-DSA are blocked until a CMVP-validated module that includes them is available.

Certificate key algorithms

RSA and ECDSA public keys are allowed for certificate issuance.

Ed25519 and post-quantum public keys are blocked.

Certificate key sizes

RSA 2048, 3072, and 4096 bits; ECDSA P-256, P-384, and P-521.

TLS versions

Use the TLS versions allowed by the DigiCert ONE for U.S. government platform FIPS configuration.

TLS cipher suites

Use FIPS-approved TLS cipher suites from the maintained DigiCert ONE for U.S. government platform configuration.

DES, 3DES, MD5, SHA-1, and non-FIPS cipher suites are not supported.

The Private CA user interface presents only the cryptographic options supported in the U.S. government environment. The REST APIs validate submitted values against the same supported configuration.

Supported key operations

Private CA for U.S. government supports the following key operations.

Operation

Support

Generate CA keys

Supported using AWS CloudHSM

Import CA keys

Supported using PKCS#12

Export CA keys

Not supported

Generate end entity keys

Supported for both server-side and client-side end entity key generation

Export end entity private keys

Not supported

Submit a subject public key

Supported using PKCS#10 or SCEP

Key backup and recovery

Supported through AWS CloudHSM managed backups

Recover end-entity private keys

Not supported

CA key generation

CA keys are generated and retained in AWS CloudHSM.

Configuration

Supported setting

HSM

AWS CloudHSM hsm2m.medium

Validated cryptographic module

Marvell LS2 HSM Family

CMVP certificate

Certificate #4703

FIPS validation

FIPS 140-3 Overall Level 3

Certificate sunset date

June 5, 2029

Cluster mode

FIPS mode, established when the cluster is created

RSA key sizes

2048, 3072, and 4096 bits

ECDSA curves

P-256 (secp256r1), P-384 (secp384r1), and P-521 (secp521r1)

Signature algorithms

SHA-256, SHA-384, or SHA-512 with RSA PKCS#1 v1.5, RSA-PSS, or ECDSA

CA signing keys are created with the following PKCS#11 attributes:

  • CKA_EXTRACTABLE = CK_FALSE

  • CKA_SENSITIVE = CK_TRUE

  • CKA_NEVER_EXTRACTABLE = CK_TRUE

These attributes prevent CA signing keys from being exported from the HSM and provide evidence that the keys have never been exportable.

Private CA starts only when it is configured with the supported AWS CloudHSM configuration. Only the algorithms and key sizes listed in this section are available for CA key generation and signing.

CA key import

CA private keys can be imported into the Private CA as PKCS#12 containers. The Private CA validates the key and signature algorithms before unwrapping the key material and storing it in AWS CloudHSM through PKCS#11.

AWS CloudHSM supports the following key-wrapping mechanisms:

Mechanism

Standard

CKM_CLOUDHSM_AES_KEY_WRAP_NO_PAD

AES Key Wrap, RFC 3394

CKM_CLOUDHSM_AES_KEY_WRAP_ZERO_PAD

AES Key Wrap with Padding, RFC 5649

CKM_RSA_AES_KEY_WRAP

RSA-AES Key Wrap

CKM_RSA_PKCS_OAEP

RSA OAEP

The AES key-wrapping mechanisms comply with NIST SP 800-38F. RSA key transport uses RSA OAEP or RSA-AES Key Wrap; RSA PKCS#1 v1.5 key transport is not used.

A CA can also be created from a submitted certificate signing request (CSR). With this method, the CA private key is not imported into the Private CA.

End entity key generation

Private CA supports both server-side and client-side end entity key generation.

End entity private keys generated server-side are not escrowed and cannot subsequently be recovered or exported.

Subject public key submission

Private CA accepts subject public keys through the following enrollment methods:

Enrollment method

Support

PKCS#10 CSR

Supported through the REST API

SCEP

Supported using RFC 8894 profiles

Submitted keys and CSRs must use the following cryptographic configurations:

  • RSA with a key size of 2048, 3072, or 4096 bits

  • ECDSA using P-256, P-384, or P-521

  • SHA-256, SHA-384, or SHA-512 with RSA, RSA-PSS, or ECDSA for CSR signatures

SCEP support is limited to RFC 8894 profiles using AES-128-CBC or AES-256-CBC. SCEP Draft 23 profiles are not supported because they require 3DES.

CA key backup and recovery

CA key backup and recovery are provided through the AWS CloudHSM managed backup service. Private CA does not provide a separate application-level key backup, export, or escrow mechanism.

AWS CloudHSM creates an encrypted cluster backup at least once every 24 hours. A backup includes:

  • HSM users

  • Key material

  • Certificates

  • HSM configuration and policies

Backup retention can be configured from 7 through 379 days. The default retention period is 90 days. Customers cannot initiate backups manually.

AWS CloudHSM protects backup key material as follows:

  • Key material does not leave the HSM in plaintext.

  • Backup data is protected using an AES key-wrapping method compliant with NIST SP 800-38F.

  • The ephemeral backup key is wrapped by a persistent backup key derived using a KDF compliant with NIST SP 800-108.

  • Backup data receives an additional encryption layer using AWS KMS before being stored in a service-controlled Amazon S3 bucket.

  • AWS does not possess the manufacturer backup key required to decrypt the HSM backup.

FIPS-mode backups can be restored only to FIPS-mode AWS CloudHSM clusters that use AWS-owned HSMs from the same manufacturer.

Supported enrollment and certificate-status interfaces

Private CA for U.S. government supports the following enrollment and certificate-status interfaces.

Interface

Availability

Supported configuration

REST API

Available

Authentication methods, profiles, key-generation options, and API version

OCSP

Available

Signing configuration, algorithms, and responder URL

CRL

Available

Signing configuration, publication options, and distribution-point URL

Private CA enrollment and certificate-status services use endpoints specific to DigiCert ONE for U.S. government.

Security configuration capabilities

Account settings for Private CA are managed in Account Manager. See Manage your account to learn about the security configuration capabilities available in the U.S. government deployment.

Configuration enforcement

Private CA applies the supported U.S. government configuration consistently across the user interface, APIs, and enrollment services.

  • The user interface displays supported HSMs, algorithms, key sizes, curves, and ciphers.

  • APIs validate requests against the supported configuration.

  • Enrollment requests use supported cryptographic modules and algorithms.

  • Private CA rejects configuration values and operations outside the supported U.S. government configuration.