Configure certificate profiles with FIPS-approved algorithms
Configuring certificate profiles correctly is the most important customer configuration responsibility in a FedRAMP deployment of DigiCert® Trust Lifecycle Manager. Certificate profiles and templates let you choose key algorithms, key sizes, and signature algorithms.
In the FIPS distribution, the product UI restricts the available options to the FIPS-approved subset. For key types, you can select only RSA and ECDSA. EdDSA and post-quantum key types, including MLDSA, SLHDSA, FNDSA, and composite, are not available. For signature algorithms, you can select SHA-256, SHA-384, or SHA-512 with RSA, RSASSA-PSS, or ECDSA. SHA-1-based signature algorithms are not available.
Important
Select FIPS-approved options when creating or editing certificate profiles. If a profile specifies a non-approved algorithm or key size, the approved-only mode rejects the cryptographic operation at runtime. The result is a failed issuance, not a weakened certificate.
Review profiles before relying on them because configuration errors might not surface until the profile is used.
Configuration steps
Review every certificate profile and template in each account and business unit.
Set RSA key sizes to 2048 bits or greater. Do not use 1024, 1536, or other sub-2048 sizes.
Use NIST-approved elliptic curves (P-256, P-384, P-521) for ECDSA profiles.
Set signature algorithms to the SHA-2 family or stronger. Do not use SHA-1-based signature algorithms.
Do not select post-quantum algorithms for production federal workloads until the corresponding module validation is in place.
Re-review profiles after any product upgrade that adds new algorithm options.
Test each profile by issuing a certificate before putting it into production use. This ensures non-approved selections fail during validation rather than an operational need.
Approved algorithm guidance
Operation | Use | Do not use |
|---|---|---|
RSA keys | 2048, 3072, 4096 bits | 1024, 1536, 2047 bits |
Elliptic curve keys | P-256, P-384, P-521 | Non-NIST or short curves |
Hashing | SHA-256, SHA-384, SHA-512 | MD5, SHA-1 |
Signatures | SHA-256/384/512 with RSA or ECDSA, RSASSA-PSS | SHA-1 with RSA, MD5 with RSA |
Symmetric encryption | AES-128, AES-192, AES-256 | DES, 3DES, RC4 |
Post-quantum | Only where a current CMVP validation covers the implementation | Unvalidated PQC for federal production workloads |