Configuration checklist
Use this checklist to verify the key DigiCert® Trust Lifecycle Manager configuration requirements for the FedRAMP offering.
The deployment is running the FIPS distribution.
Verified approved-only mode is active via the evidence endpoint.
The reported CMVP certificate and runtime version match the validated version.
Reviewed every certificate profile for FIPS-approved key sizes and signature algorithms.
Set a strong, unique master secret sourced from a secrets manager.
Restricted the
Recoverpermission to the minimum set of named individuals.Restricted the
ProfileandTemplatespermissions to trained personnel.Assigned users to the narrowest business units required.
Disabled unused enrollment protocols.
TLS verification bypass is not enabled.
Audit retention meets authorization requirements.
Forwarded audit records to central log management.
Established a recurring privileged access review covering both Trust Lifecycle Manager and DigiCert® Account Manager.
No operational process depends on a feature disabled in the FIPS distribution.