The role of Identity in TLS certificates

Slides:



Advertisements
Similar presentations
AmeriCorps is introducing a new online payment system for the processing of AmeriCorps forms
Advertisements

RTÉ eCommissioning A Guide to the Supplier Registration Process.
ESOS COMPLIANCE PROCESS 26 FEBRUARY REGULATORY APPROACH.
IRTP-C: Handling of Address Changes IRTP-C Implementation Review Team Discussion 8 January 2015.
Craig J. Nichols, Secretary 1. Mainframe and Other Software Florida State Term Contract Mainframe and Other Software July 22,
Modelica Users‘ Group Rules The following slides summarize the decisions of the Modelica Association from the 82nd Modelica Design Meeting in Lund, March.
High-class document management for small and medium businesses. Let effective and easy document handling become reality at your company.
JSPG: User-level Accounting Data Policy David Kelsey, CCLRC/RAL, UK LCG GDB Meeting, Rome, 5 April 2006.
Become an Account Executive Increase Your Income.
Dedicated to preserving the central coordinating functions of the global Internet for the public good. John L. Crain, Chief Technical Officer, ICANN
U.S. General Services Administration Office of Governmentwide Policy GSA EXPO May 4, 2010 Lee Ellis U.S. General Services Administration Office of Governmentwide.
Identity Proofing, Signatures, & Encryption in Direct esMD Author of Record Workgroup John Hall Coordinator, Direct Project June 13, 2012.
Supervision SICOR Securities, Inc.. Why? NASD 3110 requires the firm to “…establish and maintain a system to supervise the activities of each registered.
1 Conveying Water Rights Division of Water Rights By Randy Tarantino Title Program Specialist Telephone: (801) April 2013.
Welcome to EDUC 2110, 2120, & 2130 Field Experience Julie Gray Certification Office University Hall Room 340 Augusta State University.
1 Conveying Water Rights Division of Water Rights By Randy Tarantino Title Program Specialist Telephone: (801) March 2012.
Letter of Authorization and Line of Credit Date: To:Debbie Lemmon Information Technology Management Office Division of the State CIO From:Company Contact.
1 UK Link Security Policy Review January UK Link Security Policy UK Link Security Policy requires review –Administrative changes Amendment of.
Validation Working Group: Proposed Revisions to
Gilda certificates. Certification Authority
Broker Mexico Domiciled: (Property and Household Goods) Submit an Application for New Registration Unified Registration System (URS) URS New Application.
Complete Control Over Every Aspect of Hosting with Dedicated Hosting.
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
Respiratory Therapists List
John Robinson Identity Management: Do You Know Who You Are Doing Business With?
Online Applications. Login / Register If a student has already registered then they may login with their username and password. If not registered they.
LICENSURE PORTABILITY: An Update American Association of State Counseling Boards (AASCB) April 2, Montreal, CA.
Ip addressing: dhcp & dns
The Importance of Whois Accuracy Leslie Nobile
DISADVANTAGED BUSINESS ENTERPRISE program (dbe)
Business Market Administration
Optional Practical Training for F-1 Students
I-9 Instructions and FAQs
How Can NRCS Clients Use the Conservation Client Gateway
When a collector calls:
Everything You need to know
QUESTRA HOLDINGS ACCOUNT REGISTRATION
We understand that thinking about your finances can be daunting
MAIN HISTORY QUESTION HERE NAMEs DATE PERIOD
Module 5: Resolving Host Names by Using Domain Name System (DNS)
ERO Portal Overview & CFR Tool Training
CPS 512 midterm exam #1, 10/5/17 Your name please: NetID:_______ Sign for your honor:____________________________.
Website Design.
/ProStartProgram /ProStartProgram
AFRINIC Services Update
What’s New in Small Business
Proof of performance REQUESTING ACCESS
Draft ETSI TS Annex C Presented by Michał Tabor for PSD2 Workshop
Red Flags Rule An Introduction County College of Morris
[School Name] Presents
Ocean Transportation Intermediary License Renewal System February 2017
Simplifying and Securing Vendor Information
Welcome to the FERPA training for Faculty and Staff.
BCG Account Management
IEEE-SA and GDPR Implementation
Steps to apply for the HP Partner Agreement
Information for panellists
Aftermarket Parts and Services
Deprecation of certificates for internal needs
Challenges to holding closely held business interests in trust
Ip addressing: dhcp & dns
IPNNI SHAKEN Enterprise Models: LEMON TWIST
Title of presentation* + the topic(s) of interest
CFR Enhancement Session
Agenda Brief overview of recent history of validation WG Odds and Ends
Substitute Orientation
Module 2.1 Facilities Management
Client Process Pack.
Distributed Digital Rights Management
Doctors List
Presentation transcript:

The role of Identity in TLS certificates Buypass CA Who should be represented in the “O” field?

Summary from Ryan S – nov 2015 Buypass CA Recognize we don't have consensus yet for what the O field should present as Recognize that the VWG proposals provide many wonderful security benefits that we shouldn't let them get hungup on resolving 1) Take a pass at the BRs, in their entirety, to find places where the language may be inconsistent with respect to the (unresolved) status quo, and update that language to reflect the present reality Longer term, if this is a topic members are passionate about, which I think we have evidence that some CAs are, work to build consensus as to those goals

Who should be represented in the ”O” field? Buypass CA None – ”Identity is not important” A (well) defined set of entities satisfying some requirements All entities that are allowed according to the current BR/EVG Kirk Hall, author of the content and logical operator of the kirk.example.com origin Example.com, provider of hosting services for Kirk Hall CDN Corp, a CDN that provides SSL/TLS front-end services for example.com, which does not offer them directly Marketing Inc, the firm responsible for designing and maintaining the website on behalf of Kirk Hall Payments LLC, the payment processing firm responsible for handling orders and financial details on kirk.example.com DNS Org, the company who operates the DNS services on behalf of Kirk Hall Mail Corp, the organization who handles the MX records that kirk.example.com responds to

Summary from Phenix Ownership Control Authorization Buypass CA Ownership The Applicant is the owner of the Domain, the Domain Registrant Control The Applicant controls the Domain Authorization The Applicant is authorised to use the Domain

Summary from Phenix – and VWG Buypass CA Ownership The Applicant is the owner of the Domain, the Domain Registrant 3.2.2.4.1 Validating the Applicant as Domain Contact 3.2.2.4.2 Email, Fax, SMS, or Postal Mail to Domain Contact 3.2.2.4.3 Phone Contact with Domain Contact Control The Applicant controls the Domain 3.2.2.4.4 Constructed Email to Domain Contact 3.2.2.4.6 Agreed-Upon Change to Website 3.2.2.4.7 DNS Change 3.2.2.4.8 IP Address 3.2.2.4.9 Test certificate 3.2.2.4.10 TLS Using a Random Number Authorization The Applicant is authorised to use the Domain 3.2.2.4.5 Domain Authorization Document

Who should be in the O-field? Buypass CA Kirk Hall, author of the content and logical operator of the kirk.example.com origin Controls the Content of the Domain (Content Owner) - OK Example.com, provider of hosting services for Kirk Hall The Domain Registrant - OK CDN Corp, a CDN that provides SSL/TLS front-end services for example.com, which does not offer them directly Controls what? Why should they be represented in the O-field? Marketing Inc, the firm responsible for designing and maintaining the website on behalf of Kirk Hall Controls the Content on behalf of the Content Owner. Why should they be represented in the O-field? Payments LLC, the payment processing firm responsible for handling orders and financial details on kirk.example.com N/A by current requirements - OK DNS Org, the company who operates the DNS services on behalf of Kirk Hall Controls the DNS – Why should they be in the O-field? Mail Corp, the organization who handles the MX records that kirk.example.com responds to Controls the email service – Why should they be in the O-field? Other Other entities authorized (by Domain Contact) to use the Domain – Examples?

Next steps Decide on who should be in the O-field (and who should not) Buypass CA Decide on who should be in the O-field (and who should not) Define different categories of entities Domain Owner, Content Owner Etc….. Define acceptable methods for verification for each category E.g by ownership, by control using method A, B or C