Skip to main content

Secure configuration guide for Software Trust Manager

This chapter provides guidance for securely configuring DigiCert​​®​​ Software Trust Manager in a FedRAMP environment.

Important

FedRAMP certification status

DigiCert for Government is pursuing FedRAMP certification. Publishing this documentation doesn't indicate certification or agency authorization. For the current status, refer to the DigiCert for Government listing in FedRAMP Marketplace.

In this guide

The following section explains the security controls, cryptographic requirements, roles and permissions, and configuration practices for securely managing Software Trust Manager.

Feature

Description

Software Trust Manager controls

Understand the keypair, certificate, signing, release, and audit activities controlled by Software Trust Manager

DigiCert-enforced controls

Review the cryptographic, key protection, transport security, and other controls enforced in the FedRAMP deployment.

BC-FIPS provider

Understand how the BC-FIPS provider supports validated cryptographic operations in the FedRAMP deployment

Cryptographic modules

Review the validated cryptographic modules used for key generation, certificate operations, signing, and TLS connections.

NIST-approved algorithms

Review the NIST-approved algorithms, key sizes, curves, and cryptographic standards supported in the FedRAMP deployment.

Account management

Understand responsibilities for authentication, users, credentials, roles, and product access.

Roles and permissions

Review critical roles and permissions to apply appropriate access and least-privilege controls.

Secure keypairs

Configure keypairs using approved cryptographic settings, protected storage, and appropriate access controls.

Keypair profiles

Configure keypair profiles with approved cryptographic settings, validity periods, and issuance restrictions.

Signing and releases

Secure signing and release workflows using approved algorithms, separation of duties, and appropriate roles.

Keys and secrets

Protect secrets and credentials through secure storage, rotation, restricted access, and dedicated integration credentials.

Activity and access

Review audit activity, role assignments, credentials, and user access to identify unnecessary or unexpected activity.

Privileged access

Review and remove administrative or privileged access when it is no longer required.

Secure configuration history

Review changes to secure configuration recommendations and FedRAMP-enforced behavior.