Understand which controls DigiCert enforces
DigiCert® Private CA enforces these controls on FedRAMP compliant deployments.
Control | Secure behavior |
|---|---|
Cryptographic module | In the FedRAMP deployment, Private CA operates with cryptographic enforcement enabled and uses a NIST CMVP validated cryptographic module. You cannot disable this enforcement. |
Cryptographic algorithms | Only FIPS 140-3 approved algorithms, key sizes, and curves are available. An algorithm that is not FIPS 140-3 approved cannot be selected for a CA, profile, or certificate request. The following are available in the FedRAMP deployment: Key algorithms: AES, RSA, ECC/ECDSA RSA key sizes: 2048, 3072, 4096 AES key sizes: 256 ECDSA curves: P-256, P-384, P-521 Signature algorithms: SHA-256, SHA-384, or SHA-512 with ECDSA, RSA, or RSA-PSS |
Key protection | CA private keys are generated and stored in a validated hardware security module. Key export in portable formats is not available in the FedRAMP deployment. |
Cryptographic providers | Only the validated hardware security module path is available. Non-validated providers cannot be configured or used for signing. |
Legacy protocol options | Protocol versions and algorithms that are not Fips-140-3 are unavailable. |
CAs, profiles, and access | Your organization creates and manages CAs, defines certificate profiles, assigns product roles, reviews activity, and revokes certificates and access when no longer required. |