Skip to main content

Configure keypairs securely

Before generating a keypair:

  • Confirm the FIPS 140-3 approved key algorithm, key size, and curve from the available options: RSA (3072-bit or larger), ECDSA (P-256, P-384, or P-521), or EdDSA (Ed25519).

  • Confirm the keypair will be generated and stored in the validated hardware security module. This is enforced in the FedRAMP deployment.

  • Assign the keypair only to the teams and users that require it for signing, following least privilege.

  • Define keypair and certificate validity periods that meet your agency's policy.

  • Route export and delete requests through your organization's dual-approval process — a user with Manage keypair should not also be the sole approver of their own export/delete requests.

    Restrict keypair generation, export approval, and deletion approval to authorized users. Assign these permissions separately from day-to-day signing permissions so that no single role can both request and approve a sensitive keypair action.