Skip to main content

Understand which controls DigiCert enforces

The product enforces the following controls in the FIPS distribution. You don’t need to configure them, but you should confirm them during assessment.

Control

How DigiCert enforces it

FIPS validated cryptography

The Bouncy Castle FIPS provider is registered as the highest-priority JCE provider for all cryptographic operations.

Approved-only operation

The provider runs with org.bouncycastle.fips.approved_only=true, set in both the container image and deployment chart. The application sets it defensively at startup and rejects an explicit override to false.

Fail-closed startup

Startup verification aborts the application if the approved-only mode isn’t active, preventing a silent fallback to non-approved cryptography.

FIPS TLS stack

The Bouncy Castle JSSE provider is registered in FIPS mode and installed as the default SSLContext. Key and trust manager factories use PKIX.

Encryption at rest

Sensitive stored data is encrypted with AES-256-GCM using a unique, single-use data key for each encryption operation. A key-encryption key derived from a deployment master secret wraps the data key.

Key derivation

The key-encryption key is derived with PBKDF2 using HMAC-SHA-256 and a SHA-256 derived salt. The deployment master secret must meet a minimum length.

Authenticated API access

Every request carries a signed token issued by Account Manager. Trust Lifecycle Manager validates the signature against Account Manager's published verification key.

Permission enforcement

Named permissions and access scope control privileged operations centrally rather than at each endpoint.

Tamper-evident audit

Audit records are written with accompanying hashes, and an integrity verification operation is exposed for any record.

Reduced feature surface

Features that can’t meet FedRAMP requirements are disabled in the FIPS distribution and can’t be re-enabled by configuration.