Protect keys and secrets
Sensitive values stored by DigiCert® Trust Lifecycle Manager are encrypted at rest using an envelope scheme.
Element | Implementation |
|---|---|
Data encryption | AES-256-GCM with a 128-bit authentication tag. |
Data key | A fresh 256-bit AES key is generated for every encryption operation, so no key is ever reused. |
Key wrapping | The single-use data key is wrapped with a key-encryption key derived from the deployment master secret. |
Key derivation | PBKDF2 with HMAC-SHA-256, using a SHA-256-derived salt in the FIPS distribution. |
Master secret | Supplied through the |
Note
Deployment, including setting the master secret, is DigiCert's responsibility. A DigiCert employee generates and sets the master secret as part of the deployment process. Customers do not configure this value.
Your responsibilities
Store the master secret in your secret management system and inject it at runtime. Never commit it to source control, container images, or Helm values checked into a repository.
Restrict the
Recoverpermission, which is the only path to escrowed private key material.Rotate connector credentials, API credentials, SCEP challenge passwords, and ACME credentials on a defined schedule.
Ensure database and backup storage are encrypted and access-controlled, since the encrypted values live there.