Skip to main content

Understand which controls DigiCert enforces

Control

Secure behavior

Cryptographic module

In the FedRAMP deployment, Software Trust Manager operates with cryptographic enforcement enabled and uses a NIST CMVP validated cryptographic module (BC-FIPS). You cannot disable this enforcement.

Cryptographic algorithms

Only FIPS 140-3 approved algorithms, key sizes, and curves are available. An algorithm that is not FIPS 140-3 approved cannot be selected for a keypair, certificate, or signing request. The following are available in the FedRAMP deployment: Key algorithms: RSA, ECDSA, EdDSA RSA key size: 3072-bit and above ECDSA curves: P-256, P-384, P-521 EdDSA: Ed25519 Message digest / hashing: SHA-256, SHA-384, SHA-512, SHA3-256, SHA3-384, SHA3-512 Symmetric encryption: AES Certificate and data-signing algorithms: SHA-256, SHA-384, or SHA-512 with RSA, ECDSA, or RSA-PSS; EdDSA (Ed25519).

Key protection

Keypairs are generated and stored in a validated Level-3 hardware security module (HSM) on Private CA.(Software Trust does not store the keypairs and the task is delegated to Private CA). Software Trust requests them to create and then sends Hash to get the hash signed using the private key saved on Level-3 HSMs.

Keypair category

Keypairs are created in the production category, so that every signing operation uses a keypair generated and protected the same way.

Cryptographic providers

Only the validated FIPS cryptographic provider is registered for key generation, certificate issuance, and signing (BC-FIPS). Non-validated providers cannot be configured or used.

Transport security

Inbound and outbound connections use TLS 1.2 or TLS 1.3 with FIPS-approved AES-GCM cipher suites only.

Data at rest

Stored key material and sensitive configuration data are protected using an organization-supplied master encryption secret, a random initialization vector per encryption operation, and key wrapping.

Keypair, certificate, and account roles

Your organization creates and manages keypairs, certificate hierarchies and profiles, assigns product roles, reviews activity, and removes access and keypairs when no longer required.

Signing using keypairs

Users use FIPS approved Client tools (smctl, smksp, smpkcs11) to request signing of there artifacts. These artifacts are hashed at client and sent over internet (over secured TLS protocol) and Software Trust forwards it to Private CA to sign the hash and then the returned singed hash are returned to clients. Each Signing Activity is logged and save on encrypted database.