110 likes | 232 Views
Technical Issues to Deploying PKI on Campuses. PKI Summit August 2004. Technical Issues. Determining the scope of the PKI within a Campus and/or Campuses What is easy to implement and provides a broad acceptance? Mutual authenticated Web Services. Technical Issues. PKE
E N D
Technical Issues to Deploying PKI on Campuses PKI Summit August 2004
Technical Issues • Determining the scope of the PKI within a Campus and/or Campuses • What is easy to implement and provides a broad acceptance? • Mutual authenticated Web Services
Technical Issues • PKE • Enabling Legacy Applications • Its difficult to do • How do you Authenticate Users to these applications • Proxy Authentication via Web Server then how do you map that to authorizations to these apps. • New Applications and COTs based PKI Libraries • Do they support PKI the way I need it. • Validation through (CRLS, OCSP, SCVP, XKMS, Bridge aware) • CML (Digitalnet), IAIK Java tools, Peter Guttmans PKI, Suns PKI libs
Technical Issues • Consistent Certificate Profiles • Are the certificates being manufactured in a manor that enable Maximum Interoperability? • http://www.cio.gov/ficc/documents/CertCRLprofileForCP.pdf • http://www.cio.gov/ficc/documents/SSPrepositoryRqmts.pdf
Technical Issues • Consistent Processing of Certificates and Extensions • Validation Methods • Discovery of Paths and Validation of Paths • Standards are to flexible there are to many options. • Europeans are doing things differently than the US.
What is it in a nutshell? • A pre-qualified PKI services for Federal Agencies • Issue certificates to Federal Employees and Affiliated personnel • Hierarchical PKI signed by a Federal Root which is cross-certified to the FBCA. • All vendors must comply with the Federal Common Policy
So Betrusted is interested in providing a Higher Ed Solution • I will be looking talk with Edu-Cause about Betrusted providing PKI pricing based on a variant of our SSP.