Skip to main content

Secure configuration guide for Trust Lifecycle Manager

Use this guide to securely configure DigiCert​​®​​ Trust Lifecycle Manager for your organization's security and compliance requirements. Understand the security controls that DigiCert​​®​​ enforces and the controls remain your responsibility.

The guide also provides configuration guidance for cryptography, certificate profiles, enrollment, and access control. It also covers business units, agents and sensors, secrets, and audit activity.

This guide supports your organization's FedRAMP authorization and ongoing compliance activities. Your organization is responsible for determining and applying the configuration, approval, and monitoring requirements for its environment.

Important

FedRAMP certification status

DigiCert for Government is pursuing FedRAMP certification. Publishing this documentation doesn't indicate certification or agency authorization. For the current status, refer to the DigiCert for Government listing in FedRAMP Marketplace.

In this guide

The following sections explain how to securely configure and operate Trust Lifecycle Manager for the FedRAMP offering.

Section

What it covers

Understand the FIPS distribution

How the FIPS distribution operates, including approved-only cryptography, startup verification, and features that cannot meet FedRAMP requirements.

Understand what Trust Lifecycle Manager controls

The certificate lifecycle, trust infrastructure, enrollment, discovery, automation, integrations, and audit capabilities managed through Trust Lifecycle Manager.

Understand which controls DigiCert enforces

Security controls enforced by DigiCert, including FIPS-validated cryptography, encryption at rest, authenticated API access, permission enforcement, and audit integrity.

Understand the Bouncy Castle FIPS cryptographic provider

The Bouncy Castle FIPS cryptographic provider and companion libraries used by DigiCert​​®​​ Trust Lifecycle Manager, including how the provider is enforced.

Configure certificate profiles with FIPS-approved algorithms

FIPS-approved key types, key sizes, signature algorithms, and configuration requirements for certificate profiles and templates.

Features disabled in the FIPS distribution

Trust Lifecycle Manager capabilities that are unavailable in the FIPS distribution and why they are disabled.

Understand account management responsibilities

How responsibilities are divided between Trust Lifecycle Manager and DigiCert® Account Manager for identity, authentication, roles, licensing, and certificate management.

Understand critical roles and permissions

Access scopes, account roles, and privileged permissions that require additional access controls and review.

Configure business units and tenant scoping

How to use business units and access scopes to limit user access and certificate operations.

Configure certificate enrollment securely

Security guidance and configuration requirements for certificate enrollment methods.

Secure agents, sensors, and service users

Security guidance for managing agents, sensors, and their associated identities and automation.

Protect keys and secrets

Encryption-at-rest protections and customer responsibilities for private key access, credentials, and enrollment secrets.

Review product activity and access

Audit logging, retention, integrity verification, privileged activity reviews, and continuous compliance evidence.

Remove administrative and privileged access

Steps for removing roles and business unit assignments, reassigning certificate ownership, disabling machine identities, and reviewing privileged access.

Configuration checklist

Key Trust Lifecycle Manager configuration requirements to verify for the FedRAMP offering.

Secure configuration history

Updates to the secure configuration guidance for Trust Lifecycle Manager in the FedRAMP offering.