90 likes | 98 Views
Federal Identity Management Overview and Current Status. Dr. Peter Alterman, Chair Federal PKI Policy Authority. EAF Graphically. EAF Executive. LOA 3,4. LOA 1,2. Business & Legal Rules ,. FPKI Cert Policies. Policy. FPKIPA. Interop Lab SAML Spec. Fed PKI OA. Operations. CAF.
E N D
Federal Identity Management Overview and Current Status Dr. Peter Alterman, Chair Federal PKI Policy Authority
EAF Graphically EAF Executive LOA 3,4 LOA 1,2 Business & Legal Rules, FPKI Cert Policies Policy FPKIPA Interop Lab SAML Spec. Fed PKI OA Operations CAF XCert and MOA Providers
Components of EAF • Organized around Assurance Levels • 1, 2 for assertion-based credentials • SAML • Emphasis on SAML interoperability tools on the operational level • Business and Legal rules imposed on Apps and credential providers alike • 3, 4 for crypto-based • PKI predominates • Serviced by Federal PKI Policy Authority and Federal PKI Operational Authority • Major growth area for Federal Apps in first round
Simplified Diagram of Federal PKI Federal Bridge CA Cross- Certified gov PKIs Common Policy CA Shared Service Provider PKIs (Common Policy OID And root Cert) C4 CA E-Gov CAs (3) Cross- Certified External PKIs eAuth CSPs
FPKI Policy Authority Org. Chart Federal CIO Council E-Auth PMO Policy Authority www.cio.gov/fpkipa FICC FBCA Op Auth Tech WG PD-Val WG SSP WG Cert Policy WG • Charter • Bylaws • Criteria & Methodology Document • Policies
EAF Interoperability Status • Interfederation Interoperability Work Group completed policy work • Technical Interoperability with Shibboleth suite completed • InCommon interfederation proposal delivered to EAF • Initial Meeting late March • Second Meeting today (4/25)
Requirements for Interfed Interop Evolving • Technical interop solved, future going forward hand-in-hand • Policy interop under discussion, Will require evolved IdM from university inCommon + members
Related Work • Built 1.0 usPerson profile, ongoing work • Building SAML 2.0 spec and implementation plan
Resources • www.cio.gov/fpkipa • www.cio.gov/fbca • www.cio.gov/ficc • www.cio.gov/eauthentication