Skip to main content

Protect keys and secrets

Sensitive values stored by DigiCert​​®​​ Trust Lifecycle Manager are encrypted at rest using an envelope scheme.

Element

Implementation

Data encryption

AES-256-GCM with a 128-bit authentication tag.

Data key

A fresh 256-bit AES key is generated for every encryption operation, so no key is ever reused.

Key wrapping

The single-use data key is wrapped with a key-encryption key derived from the deployment master secret.

Key derivation

PBKDF2 with HMAC-SHA-256, using a SHA-256-derived salt in the FIPS distribution.

Master secret

Supplied through the MASTER_CRYPT_SECRET environment variable, sourced from a Kubernetes secret. Subject to a minimum length requirement in the FIPS distribution.

Note

Deployment, including setting the master secret, is DigiCert's responsibility. A DigiCert employee generates and sets the master secret as part of the deployment process. Customers do not configure this value.

Your responsibilities

  1. Store the master secret in your secret management system and inject it at runtime. Never commit it to source control, container images, or Helm values checked into a repository.

  2. Restrict the Recover permission, which is the only path to escrowed private key material.

  3. Rotate connector credentials, API credentials, SCEP challenge passwords, and ACME credentials on a defined schedule.

  4. Ensure database and backup storage are encrypted and access-controlled, since the encrypted values live there.