Skip to main content

Configuration checklist

Use this checklist to verify the key DigiCert​​®​​ Trust Lifecycle Manager configuration requirements for the FedRAMP offering.

  • The deployment is running the FIPS distribution.

  • Verified approved-only mode is active via the evidence endpoint.

  • The reported CMVP certificate and runtime version match the validated version.

  • Reviewed every certificate profile for FIPS-approved key sizes and signature algorithms.

  • Set a strong, unique master secret sourced from a secrets manager.

  • Restricted the Recover permission to the minimum set of named individuals.

  • Restricted the Profile and Templates permissions to trained personnel.

  • Assigned users to the narrowest business units required.

  • Disabled unused enrollment protocols.

  • TLS verification bypass is not enabled.

  • Audit retention meets authorization requirements.

  • Forwarded audit records to central log management.

  • Established a recurring privileged access review covering both Trust Lifecycle Manager and DigiCert® Account Manager.

  • No operational process depends on a feature disabled in the FIPS distribution.