Configure keypairs securely
Before generating a keypair:
Confirm the FIPS 140-3 approved key algorithm, key size, and curve from the available options: RSA (3072-bit or larger), ECDSA (P-256, P-384, or P-521), or EdDSA (Ed25519).
Confirm the keypair will be generated and stored in the validated hardware security module. This is enforced in the FedRAMP deployment.
Assign the keypair only to the teams and users that require it for signing, following least privilege.
Define keypair and certificate validity periods that meet your agency's policy.
Route export and delete requests through your organization's dual-approval process — a user with Manage keypair should not also be the sole approver of their own export/delete requests.
Restrict keypair generation, export approval, and deletion approval to authorized users. Assign these permissions separately from day-to-day signing permissions so that no single role can both request and approve a sensitive keypair action.