Secure configuration guide for Trust Lifecycle Manager
Use this guide to securely configure DigiCert® Trust Lifecycle Manager for your organization's security and compliance requirements. Understand the security controls that DigiCert® enforces and the controls remain your responsibility.
The guide also provides configuration guidance for cryptography, certificate profiles, enrollment, and access control. It also covers business units, agents and sensors, secrets, and audit activity.
This guide supports your organization's FedRAMP authorization and ongoing compliance activities. Your organization is responsible for determining and applying the configuration, approval, and monitoring requirements for its environment.
Important
FedRAMP certification status
DigiCert for Government is pursuing FedRAMP certification. Publishing this documentation doesn't indicate certification or agency authorization. For the current status, refer to the DigiCert for Government listing in FedRAMP Marketplace.
In this guide
The following sections explain how to securely configure and operate Trust Lifecycle Manager for the FedRAMP offering.
Section | What it covers |
|---|---|
How the FIPS distribution operates, including approved-only cryptography, startup verification, and features that cannot meet FedRAMP requirements. | |
The certificate lifecycle, trust infrastructure, enrollment, discovery, automation, integrations, and audit capabilities managed through Trust Lifecycle Manager. | |
Security controls enforced by DigiCert, including FIPS-validated cryptography, encryption at rest, authenticated API access, permission enforcement, and audit integrity. | |
The Bouncy Castle FIPS cryptographic provider and companion libraries used by DigiCert® Trust Lifecycle Manager, including how the provider is enforced. | |
Configure certificate profiles with FIPS-approved algorithms | FIPS-approved key types, key sizes, signature algorithms, and configuration requirements for certificate profiles and templates. |
Trust Lifecycle Manager capabilities that are unavailable in the FIPS distribution and why they are disabled. | |
How responsibilities are divided between Trust Lifecycle Manager and DigiCert® Account Manager for identity, authentication, roles, licensing, and certificate management. | |
Access scopes, account roles, and privileged permissions that require additional access controls and review. | |
How to use business units and access scopes to limit user access and certificate operations. | |
Security guidance and configuration requirements for certificate enrollment methods. | |
Security guidance for managing agents, sensors, and their associated identities and automation. | |
Encryption-at-rest protections and customer responsibilities for private key access, credentials, and enrollment secrets. | |
Audit logging, retention, integrity verification, privileged activity reviews, and continuous compliance evidence. | |
Steps for removing roles and business unit assignments, reassigning certificate ownership, disabling machine identities, and reviewing privileged access. | |
Key Trust Lifecycle Manager configuration requirements to verify for the FedRAMP offering. | |
Updates to the secure configuration guidance for Trust Lifecycle Manager in the FedRAMP offering. |