QuoVadis Group Roman Brunner, Group CEO Update for EUGridPMA – May 12, 2009.

Slides:



Advertisements
Similar presentations
Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
Advertisements

© Southampton City Council Sean Dawtry – Southampton City Council The Southampton Pathfinder for Smart Cards in public services.
1 WebTrust for Certification Authorities (CAs) Overview October 2011 WebTrust for Certification Authorities (CAs) Overview October 2011 Presentation based.
1st Expert Group Meeting (EGM) on Electronic Trade-ECO Cooperation on Trade Facilitation May 2012, Kish Island, I.R.IRAN.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
Public Key Infrastructure (PKI) Providing secure communications and authentication over an open network.
PKI in US Higher Education TAGPMA Meeting, March 2006 Rio De Janeiro, Brazil.
PKI Activities at Virginia January 2004 CSG Meeting Jim Jokl.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
National Institute of Advanced Industrial Science and Technology Auditing, auditing template and experiences on being audited Yoshio Tanaka
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 9: Planning and Managing Certificate Services.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Identity Management and PKI Credentialing at UTHSC-H Bill Weems Academic Technology University of Texas Health Science Center at Houston.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
1 USHER Update Fed/ED December 2007 Jim Jokl University of Virginia.
Configuring Active Directory Certificate Services Lesson 13.
Public Key Infrastructure from the Most Trusted Name in e-Security.
Public Key Infrastructure Ammar Hasayen ….
1 Digital Credential for Higher Education John Gardiner August 11, 2004.
IDA Security Experts Workshop Olivier LIBON Vice President – GlobalSign November 2000.
Wolfgang Schneider NSI: A Client-Server-Model for PKI Services.
May 30 th – 31 st, 2006 Sheraton Ottawa. Microsoft Certificate Lifecycle Manager Saleem Kanji Technology Solutions Professional - Windows Server Microsoft.
Deploying a Certification Authority for Networks Security Prof. Dr. VICTOR-VALERIU PATRICIU Cdor.Prof. Dr. AUREL SERB Computer Engineering Department Military.
Best Practices in Deploying a PKI Solution BIEN Nguyen Thanh Product Consultant – M.Tech Vietnam
Deploying PKI Inside Microsoft The experience of Microsoft in deploying its own corporate PKI Published: December 2003.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
© GlobalSign. A GMO Internet Inc group company. Authentication. Security. Trust. Code Signing Distributing trustworthy software over the Internet.
WebTrust SM/TM Principles and Criteria for Certification Authorities CA Trust Jeff
Best of Both Worlds: Information Management Solutions SmartCore Management Dashboards.
HEPKI-TAG UPDATE Jim Jokl University of Virginia
+1 (801) Standards for Registration Practices Statements IGTF Considerations.
Chapter 9: Using and Managing Keys Security+ Guide to Network Security Fundamentals Second Edition.
Configuring Directory Certificate Services Lesson 13.
1 June Richard Guida Stephanie Evans Johnson & Johnson Director, WWIS WWIS SAFE Infrastructure Overview.
HEPKI-PAG Policy Activities Group David L. Wasley University of California.
Module 9: Fundamentals of Securing Network Communication.
Secure Messaging Workshop The Open Group Messaging Forum February 6, 2003.
PKI Forum Business Panel March 6, 2000 Dr. Ray Wagner Sr. Director, Technology Research.
Security Overview  System protection requirements areas  Types of information protection  Information Architecture dimensions  Public Key Infrastructure.
Maintaining Network Health. Active Directory Certificate Services Public Key Infrastructure (PKI) Provides assurance that you are communicating with the.
Module 9: Designing Public Key Infrastructure in Windows Server 2008.
IHEP Grid CA Status Report Wei F2F Meeting 8 Mar Computing Centre, IHEP,CAS,China.
Customer Interface for wuw.com 1.Context. Customer Interface for wuw.com 2. Content Our web-site can be classified as an service-dominant website. 3.
Public Key Infrastructure (X509 PKI) Presented by : Ali Fanian
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Profile for Portal-based Credential Services (POCS) Yoshio Tanaka International Grid Trust Federation APGrid PMA AIST.
© 2003 The MITRE Corporation. All rights reserved For Internal MITRE Use Addressing ISO-RTO e-MARC Concerns: Clarifications and Ramifications Response.
ESnet RAF and eduroam ™ Tony J. Genovese ATF Team ESnet/Lawrence Berkeley National Laboratory.
“Trust me …” Policy and Practices in PKI David L. Wasley Fall 2006 PKI Workshop.
Security fundamentals Topic 5 Using a Public Key Infrastructure.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Creating and Managing Digital Certificates Chapter Eleven.
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
The NGS Support Centre Katie Weeks. NGS Support Centre SLD Many areas to NGS Support Centre –SLD defines supported areas including: Certification Authority.
8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK
TACAR Updates version David Groep, NIKHEF. 9 th EUGridPMA ‘RAL’ meeting – Jan David Groep – TACAR Aims  Trusted and.
Egypt Certification Authority Dr. Ayman Bahaa-Eldin EUN Director 8 May th EuGridPMA meeting, Germany.
QuoVadis Group Overview for EUGridPMA. Snapshot Trust/Link certificate services for the global enterprise –Digital certificates including End User, Qualified,
QuoVadis Group EUGridPMA Update September Overview ► Founded in 1999 in Bermuda, with particular focus providing PKI managed services to multinational.
QuoVadis accreditation with EuGridPMA Alessandro Usai
18 th EUGridPMA, Dublin / SRCE CA Self Audit SRCE CA Self Audit Emir Imamagić SRCE Croatia.
29 th EUGridPMA meeting, September 2013, Bucharest AEGIS Certification Authority Dušan Radovanović University of Belgrade Computer Centre.
AEGIS Certification Authority
Public Key Infrastructure (PKI)
کاربرد گواهی الکترونیکی در سیستمهای کاربردی (امضای دیجیتال)
CERN Certificates platform Emmanuel Ormancey / Anatoly Gladkov
جايگاه گواهی ديجيتالی در ايران
Public Key Infrastructure from the Most Trusted Name in e-Security
September 2002 CSG Meeting Jim Jokl
RSA Digital Certificate Solutions RSA Solutions for PKI David Mateju RSA Sales Consultant
Presentation transcript:

QuoVadis Group Roman Brunner, Group CEO Update for EUGridPMA – May 12, 2009

QuoVadis Snapshot Founded 1999 as Commercial Certification Authority Offices in Switzerland, UK, Holland, Bermuda Organisations want to “use digital certificates” more than “run their own PKI” –Complexity of PKI policy and technology can distract from the actual business QuoVadis provides turnkey solutions surrounding digital certificates and digital signatures –Allow the customer to focus on their users and core systems/processes Critical mass to provide: –Specialised registration systems to improve user experience, compliance –Secure hosting and operations of the PKI –Support for arcane PKI issues –Audits and accreditations –Wide distribution of roots in OS and Browsers

Do It Yourself ? OIDs Operational policy and procedures Archiving Policy Approval Authority Implementation plan Operational CAs Root CA Directory structure Token management Smart card issuing Validation process Naming convention Regulatory compliance Renewal process OCSP Revocation process Registration process Legal liability CP & CPS Backup systems Firewalls Business continuity plan Security Policy and Procedures Support organisation Trust Model End-to-end test Operations test System test Training Support Training end-users Training Operations Audit Key Management Hardware management Concept of Operations

Service Overview Digital Certificates End User certificates, including Qualified and Advanced certificates, for various uses. Functional certificates, including ElDI-V/GeBüV, code signing, gateway, etc. SSL including the new Extended Validation SSL. Managed PKI Outsourced certification authorities (CA) that can be tailored to the particular needs of a client or community. Rapid-deployment Trust/Link registration authority (RA) web portals for easy issuance for both End User and SSL certificates. Signing Services Trusted time-stamping to reinforce data integrity and non-repudiation in the submission, storage/archive, or tracking of electronic records. Digital signing tools (both client and server side). Root Services Root CA hosting for organisations wishing to set up their own trust anchors. Root CA signing enhances the trust and recognition of customers’ in-house CAs. PKI policy, technologies, and integration into customer environments.

Root Distribution Browsers Microsoft Internet Explorer 5.0+ (including Maxthon and others) Mozilla Firefox (including Camino, Fennec, and Sea Monkey) Opera (including Opera Mini) Safari 1.0+ (including mobile Safari) Google Chrome Konqueror and K-Meleon Operating Systems Microsoft Windows XP+ Apple OS/X+ RIM Blackberry 4+ KDE Java (in progress) Clients Apple Mail.app Eudora Microsoft Entourage Microsoft Outlook Microsoft Outlook Express Mozilla Thunderbird Mozilla Sea Monkey RIM Blackberry Mail (part of Core Applications) Other Microsoft Office Open Office Wide array of OSS applications that use the Mozilla NSS libraries 3.9+ Adobe Acrobat (in progress)

Audits and Accreditations QuoVadis seeks accreditations in support of our client needs: –WebTrust for Certification Authorities –WebTrust for Extended Validation –Swiss Qualified Certification Services Provider –Netherlands Qualified Certification Services Provider –Bermuda Authorised Certification Services Provider –Currently obtaining PKI Overheid Accreditation in the Netherlands

QuoVadis Grid CA Custom GridCA built for SWITCH in compliance with EUGridPMA standards –Updates made to QuoVadis CP/CPS Evolved from QuoVadis relationship providing SSL to SWITCH institutions using Trust/Link SSL Available for other EUGrid members’ use: –Reduce PKI management burden –Simple interface for users –Chained to QuoVadis root for wider “trust” in end user software

EUGridPMA Accreditation EUGridPMA team has performed a detailed review and approval of: –The QuoVadis CP/CPS –The QuoVadis Grid Issuing CA, End User, Server and CRL certificate profiles The repository on the QuoVadis website ( contains the QuoVadis Grid Issuing CA certificate, the Grid CRL, and the QuoVadis Root Certificateshttp:// Update to CP/CPS will be posted when CA goes into production QuoVadis are currently in progress with the TACAR application A big thanks to all the EUGridPMA reviewers for all their hard work, time, and input!

Certificate Types Grid End User certificates for authentication and secure Grid Server certificates for authentication and secure communication with Grid resources Grid members who wish to use the Grid CA would sign up as Participating Institutions/Registration Authorities –QuoVadis is working with SWITCH to document procedures for RAs Certificates will be issued and managed using our Trust/Link web applications: –Trust/Link For End Users –Trust/Link For SSL

Example: Trust/Link SSL Pre-vetted details allows immediate issuance of SSL –Templates for consistency Separation of institution “accounts” Delegated administration, ability to accommodate different approval regimes Single login for Subscribers to manage all their SSL Custom s for lifecycle events Flexibility for certificate types, use of SANs, etc. QuoVadis can provide demonstrations for interested groups

Roman Brunner