Skip to main content

Configure keypair profiles and issuance policy

Keypair profiles let administrators pre-configure the algorithm, key size, curve, and category that a keypair is created with. For each profile.

  • Set the algorithm, key size, and curve to the FIPS 140-3 approved options listed above.

  • Set validity periods to the shortest duration that meets the business requirement.

  • Restrict certificate subject and profile fields to the values the use case requires.

  • Review profile changes through your organization's change-management process.

    A keypair profile inherits the FIPS 140-3 approved algorithm and storage options described above — there is no separate configuration step needed to keep a profile FIPS-compliant, but profile changes should still go through change review since they determine what every keypair created from that profile can do.