Skip to main content

Understand which controls DigiCert enforces

DigiCert® Private CA enforces these controls on FedRAMP compliant deployments.

Control

Secure behavior

Cryptographic module

In the FedRAMP deployment, Private CA operates with cryptographic enforcement enabled and uses a NIST CMVP validated cryptographic module. You cannot disable this enforcement.

Cryptographic algorithms

Only FIPS 140-3 approved algorithms, key sizes, and curves are available. An algorithm that is not FIPS 140-3 approved cannot be selected for a CA, profile, or certificate request. The following are available in the FedRAMP deployment:

Key algorithms: AES, RSA, ECC/ECDSA

RSA key sizes: 2048, 3072, 4096

AES key sizes: 256

ECDSA curves: P-256, P-384, P-521

Signature algorithms: SHA-256, SHA-384, or SHA-512 with ECDSA, RSA, or RSA-PSS

Key protection

CA private keys are generated and stored in a validated hardware security module. Key export in portable formats is not available in the FedRAMP deployment.

Cryptographic providers

Only the validated hardware security module path is available. Non-validated providers cannot be configured or used for signing.

Legacy protocol options

Protocol versions and algorithms that are not Fips-140-3 are unavailable.

CAs, profiles, and access

Your organization creates and manages CAs, defines certificate profiles, assigns product roles, reviews activity, and revokes certificates and access when no longer required.