Skip to main content

Configure certificate profiles with FIPS-approved algorithms

Configuring certificate profiles correctly is the most important customer configuration responsibility in a FedRAMP deployment of DigiCert​​®​​ Trust Lifecycle Manager. Certificate profiles and templates let you choose key algorithms, key sizes, and signature algorithms.

In the FIPS distribution, the product UI restricts the available options to the FIPS-approved subset. For key types, you can select only RSA and ECDSA. EdDSA and post-quantum key types, including MLDSA, SLHDSA, FNDSA, and composite, are not available. For signature algorithms, you can select SHA-256, SHA-384, or SHA-512 with RSA, RSASSA-PSS, or ECDSA. SHA-1-based signature algorithms are not available.

Important

Select FIPS-approved options when creating or editing certificate profiles. If a profile specifies a non-approved algorithm or key size, the approved-only mode rejects the cryptographic operation at runtime. The result is a failed issuance, not a weakened certificate.

Review profiles before relying on them because configuration errors might not surface until the profile is used.

Configuration steps

  1. Review every certificate profile and template in each account and business unit.

  2. Set RSA key sizes to 2048 bits or greater. Do not use 1024, 1536, or other sub-2048 sizes.

  3. Use NIST-approved elliptic curves (P-256, P-384, P-521) for ECDSA profiles.

  4. Set signature algorithms to the SHA-2 family or stronger. Do not use SHA-1-based signature algorithms.

  5. Do not select post-quantum algorithms for production federal workloads until the corresponding module validation is in place.

  6. Re-review profiles after any product upgrade that adds new algorithm options.

  7. Test each profile by issuing a certificate before putting it into production use. This ensures non-approved selections fail during validation rather than an operational need.

Approved algorithm guidance

Operation

Use

Do not use

RSA keys

2048, 3072, 4096 bits

1024, 1536, 2047 bits

Elliptic curve keys

P-256, P-384, P-521

Non-NIST or short curves

Hashing

SHA-256, SHA-384, SHA-512

MD5, SHA-1

Signatures

SHA-256/384/512 with RSA or ECDSA, RSASSA-PSS

SHA-1 with RSA, MD5 with RSA

Symmetric encryption

AES-128, AES-192, AES-256

DES, 3DES, RC4

Post-quantum

Only where a current CMVP validation covers the implementation

Unvalidated PQC for federal production workloads