Understand the FIPS distribution
DigiCert® Trust Lifecycle Manager is delivered for FedRAMP deployments as a dedicated Federal Information Processing Standards (FIPS) distribution. This is a separate build of the product, not a runtime setting.
The FIPS distribution:
Runs all cryptographic operations through a FIPS 140-3 validated cryptographic module.
Operates that module in approved-only mode, so non-approved cryptographic operations fail rather than silently downgrade.
Refuses to start if approved-only mode isn’t active, so a misconfigured deployment can’t run in a weakened state.
Disables product features that can’t meet FedRAMP requirements. See Feature support for more information.
Important
Because FIPS mode is selected at build time, you can’t enable or disable it from the product UI or configuration. Verify you’re running the FIPS distribution before treating a deployment as in scope. The live evidence API reports the running mode.