Understand which controls DigiCert enforces
The product enforces the following controls in the FIPS distribution. You don’t need to configure them, but you should confirm them during assessment.
Control | How DigiCert enforces it |
|---|---|
FIPS validated cryptography | The Bouncy Castle FIPS provider is registered as the highest-priority JCE provider for all cryptographic operations. |
Approved-only operation | The provider runs with |
Fail-closed startup | Startup verification aborts the application if the approved-only mode isn’t active, preventing a silent fallback to non-approved cryptography. |
FIPS TLS stack | The Bouncy Castle JSSE provider is registered in FIPS mode and installed as the default |
Encryption at rest | Sensitive stored data is encrypted with AES-256-GCM using a unique, single-use data key for each encryption operation. A key-encryption key derived from a deployment master secret wraps the data key. |
Key derivation | The key-encryption key is derived with PBKDF2 using HMAC-SHA-256 and a SHA-256 derived salt. The deployment master secret must meet a minimum length. |
Authenticated API access | Every request carries a signed token issued by Account Manager. Trust Lifecycle Manager validates the signature against Account Manager's published verification key. |
Permission enforcement | Named permissions and access scope control privileged operations centrally rather than at each endpoint. |
Tamper-evident audit | Audit records are written with accompanying hashes, and an integrity verification operation is exposed for any record. |
Reduced feature surface | Features that can’t meet FedRAMP requirements are disabled in the FIPS distribution and can’t be re-enabled by configuration. |