110 likes | 123 Views
Explore technical issues in deploying PKI on campuses, including scope determination, authentication methods, legacy applications, and certificate profiles. Learn about Betrusted's Shared Service Provider for Federal Agencies and its potential Higher Ed Solution. Discover tools, libraries, and validation methods for effective PKI implementation.
E N D
Technical Issues to Deploying PKI on Campuses PKI Summit August 2004
Technical Issues • Determining the scope of the PKI within a Campus and/or Campuses • What is easy to implement and provides a broad acceptance? • Mutual authenticated Web Services
Technical Issues • PKE • Enabling Legacy Applications • Its difficult to do • How do you Authenticate Users to these applications • Proxy Authentication via Web Server then how do you map that to authorizations to these apps. • New Applications and COTs based PKI Libraries • Do they support PKI the way I need it. • Validation through (CRLS, OCSP, SCVP, XKMS, Bridge aware) • CML (Digitalnet), IAIK Java tools, Peter Guttmans PKI, Suns PKI libs
Technical Issues • Consistent Certificate Profiles • Are the certificates being manufactured in a manor that enable Maximum Interoperability? • http://www.cio.gov/ficc/documents/CertCRLprofileForCP.pdf • http://www.cio.gov/ficc/documents/SSPrepositoryRqmts.pdf
Technical Issues • Consistent Processing of Certificates and Extensions • Validation Methods • Discovery of Paths and Validation of Paths • Standards are to flexible there are to many options. • Europeans are doing things differently than the US.
What is it in a nutshell? • A pre-qualified PKI services for Federal Agencies • Issue certificates to Federal Employees and Affiliated personnel • Hierarchical PKI signed by a Federal Root which is cross-certified to the FBCA. • All vendors must comply with the Federal Common Policy
So Betrusted is interested in providing a Higher Ed Solution • I will be looking talk with Edu-Cause about Betrusted providing PKI pricing based on a variant of our SSP.