Configure keypair profiles and issuance policy
Keypair profiles let administrators pre-configure the algorithm, key size, curve, and category that a keypair is created with. For each profile.
Set the algorithm, key size, and curve to the FIPS 140-3 approved options listed above.
Set validity periods to the shortest duration that meets the business requirement.
Restrict certificate subject and profile fields to the values the use case requires.
Review profile changes through your organization's change-management process.
A keypair profile inherits the FIPS 140-3 approved algorithm and storage options described above — there is no separate configuration step needed to keep a profile FIPS-compliant, but profile changes should still go through change review since they determine what every keypair created from that profile can do.