InCommon Certificate Service REN-ISAC Meeting/Educause Security Professionals 2011 Wednesday, April 6 th, 2011, San Antonio TX Joe St Sauver, Ph.D. Internet2.

Slides:



Advertisements
Similar presentations
Sponsored by the National Science Foundation GENI-Enabling Universities GENI Engineering Conference July 10, 2012 Larry Landweber GENI Project Office.
Advertisements

National Institutes of Health U.S. Department of Health and Human Services The PEPH Resource Center: A New, More Convenient Login.
 A new type of associate degree, different from the AA and AS  An option that allows students to complete an Associate degree while also completing CSU.
California “a-g” requirements  Who uses them?  What are they used for?  What are they, and how will I meet them?  Does JFK offer everything I will.
HATHITRUST A Shared Digital Repository We’re Preserving the Past, What About the Present? NISO Webinar: Ensuring the Preservation of E-Books May 23, 2012.
HATHITRUST A Shared Digital Repository HathiTrust current work, challenges, and opportunities for public libraries Creating a Blueprint for a National.
HATHITRUST A Shared Digital Repository HathiTrust as a Model for Preservation and Access Jeremy York Media Preservation Conference April 17, 2013.
HATHITRUST A Shared Digital Repository Bibliographic Metadata and HathiTrust ALCTS CaMMS Catalog Management Interest Group Meeting American Library Association.
The West` Washington Idaho 1 Montana Oregon California 3 4 Nevada Utah
HATHITRUST A Shared Digital Repository HathiTrust: A Second Life for Library Collections Jeremy York Exploring Humanities Cyberinfrastructure April 30,
Welcome Hinsdale Central Class of University of Illinois Urbana.
The California State University (CSU) GAAP Reporting Manual ORA 1 © 2008 KPMG LLP, the U.S. member firm of KPMG International, a Swiss cooperative.
© 2010 KPMG LLP, a Delaware limited liability partnership and the U.S. member firm of the KPMG network of independent member firms affiliated with KPMG.
The California State University (CSU) GAAP Reporting Manual © 2009 KPMG LLP, the U.S. member firm of KPMG International, a Swiss cooperative. All.
11920 ORA The California State University (CSU) GAAP Reporting Manual 2007 Engagement Team Phone List 3.
A/B/C Campus Scope Presented by: Kathy Lai, KPMG LLP AUDIT.
Year Round Operations Current Status FOA Conference April 10, 2001.
Physical Therapy Schools (in Texas) Property of the Texas A&M Physical Therapy Society *Seeking Accreditation.
Guaranteed admission to top 4% of class Admits the top 8% of California Seniors Requires ACT with the Writing or the SAT Reasoning test Requires two SAT.
1 How to Get to College Cristina Parodi Araya Parent/Family Liaison San Diego County Office of Education (858)
BINARY CODING. Alabama Arizona California Connecticut Florida Hawaii Illinois Iowa Kentucky Maine Massachusetts Minnesota Missouri 0 Nebraska New Hampshire.
Average Increase in Direct Compensation by Employee Group (Includes Extension, excludes Hospital) PercentPercent.
Farming and Populism in the West Chapter 18, Section 3 8 th Grade Social Studies.
California’s Engineering Transfer Universities Three Main Types of Universities: 1.University of California System (UC) 2.California State University System.
COLLEGE ENTRANCE DATA EL Dorado High School Class of 2015.
CILogon and InCommon: Technical Update Jim Basney This material is based upon work supported by the National Science Foundation under grant numbers
HATHITRUST A Shared Digital Repository HathiTrust: Putting Research in Context HTRC UnCamp September 10, 2012 John Wilkin, Executive Director, HathiTrust.
1 The Partnership Challenge Higher education’s missions are realized in increasingly global, collaborative, online relationships –Higher educations’ digital.
Student Success Fee for Cal Poly Pomona September 26, 2012 Academic Senate.
LEGEND Public Health Schools Law Schools Medical & Other Schools Public Health Schools Teaching Public Health Law As of July 1, 2012.
Map Review. California Kentucky Alabama.
Judicial Circuits. If You Live In This State This Is Your Judicial Circuit Alabama11th Circuit Alaska 9th Circuit Arkansas 8th Circuit Arizona 9th Circuit.
WACAC Share, Learn, Connect Conference Update on the California State University March 12, 2014 Ilana Israel Samuels Associate Director of Recruitment.
1. AFL-CIO What percentage of the funds received by Alabama K-12 public schools in school year was provided by the state of Alabama? a)44% b)53%
June, 2012 Art Mandel.  Multiple acceptances to Ivy League Schools  Multiple acceptances to the “Most Competitive” colleges and universities  State.
Navigating the College Course September 21, 2015.
HATHITRUST A Shared Digital Repository HathiTrust and TRAC DigitalPreservation 2012 July 25, 2012 Jeremy York, Project Librarian, HathiTrust.
College Questions. What does it mean to study abroad?
10 th Grade Guidance Lesson. Agenda  Transcript and Graduation Status Review  College Options  Testing for Colleges  How to Get Help.
Harrison’s Top 25 1.Florida State 2.Alabama 3.Oregon 4.Oklahoma 5.South Carolina 6.Michigan State 7.Ohio State 8.Auburn 9.Baylor 10.Georgia 11.UCLA 12.LSU.
1 Fall 2004 Freshman Profile September 9, Total Number of Applications = (+13%)
AVID’s mission is to close the achievement gap by preparing all students for college readiness and success in a global society. A-G Requirements.
HATHITRUST A Shared Digital Repository HathiTrust and the Future of Research Libraries American Antiquarian Society March 31, 2012 Jeremy York, Project.
Unlimited SSL and personal certificates at one annual fixed fee.
HATHITRUST A Shared Digital Repository Institution Uses of HathiTrust Jeremy York University of Maine May 24, 2013.
Study Cards The East (12) Study Cards The East (12) New Hampshire New York Massachusetts Delaware Connecticut New Jersey Rhode Island Rhode Island Maryland.
Staffed Location Future Satellite Location Satellite Location.
US MAP TEST Practice
UPDATED KUALI STATISTICS. KUALI FOUNDATION MEMBERS – INSTITUTIONAL (60) Australian National University Boston College Boston University Brock University.
HATHITRUST A Shared Digital Repository HathiTrust Large Digital Libraries: Beyond Google Books Modern Language Association January 5, 2012 Jeremy York,
Peace Corps University Partnerships Life is calling. How far will you go? Peace Corps.
HathiTrust: A valuable and visionary Partnership.
CSU Libraries’ Use of Social Networking Platforms Cynthia McCarthy MLIS, December 2010 Administration Office Volunteer 2011 May 10, 2011.
Review of Compliance with the NCAA Financial Data Reporting Requirements Sedong John, SFSR Chancellor’s Office Year-End GAAP Training April 18, 2014.
1st Hour2nd Hour3rd Hour Day #1 Day #2 Day #3 Day #4 Day #5 Day #2 Day #3 Day #4 Day #5.
Introducing Students to the Locker
University Budget and Marginal Cost Components
SCATTERGRAMS COLLEGE ENTRANCE DATA
Equipment Maintenance Direct $pend Opportunity
2c: States grouped by region
Expanded State Agency Use of NMLS
Physicians per 1,000 Persons
Name the State Flags Your group are to identify which state the flag belongs to and sign correctly to earn a point.
GLD Org Chart February 2008.
The States How many states are in the United States?
University Budget and Marginal Cost Components
Supplementary Data Tables, Utilization and Volume
WASHINGTON MAINE MONTANA VERMONT NORTH DAKOTA MINNESOTA MICHIGAN
Expanded State Agency Use of NMLS
From Innovation to Commercialization Access to Data
Presentation transcript:

InCommon Certificate Service REN-ISAC Meeting/Educause Security Professionals 2011 Wednesday, April 6 th, 2011, San Antonio TX Joe St Sauver, Ph.D. Internet2 Nationwide Security Programs Manager or

What Is The InCommon Certificate Service? The InCommon Certificate Service offers unlimited SSL certificates for one fixed fee for all campus servers and domains, including all domains owned by the school (such as professional organizations or athletic sites, including any.org,.com,.net or other domains). This includes unlimited Domain Validation SSL certs and Extended Validation (green bar) certs, and personal certs for signing and encryption (code-signing certs are coming) Trust anchors are in all major browsers and other clients Campus staff create and control certificates through the a GUI Certificate Manager interface or via an API For more info, see (that site has a very helpful FAQ, and also has information about how to subscribe, participation costs, etc.)

Whos Currently Participating? 102 Sites… Arizona State University California Institute of Technology; California Maritime Academy; California Polytechnic State University-San Luis Obispo; California State Polytechnic University, Pomona; California State University, Bakersfield; California State University, Channel Islands; California State University, Chico; California State University, Dominguez Hills; California State University, East Bay; California State University, Fresno; California State University, Fullerton; California State University, Long Beach California State University, Los Angeles; California State University, Monterey Bay; California State University, Northridge; California State University, Office of the Chancellor; California State University, Sacramento; California State University, San Marcos; California State University, Stanislaus; California State University San Bernardino; Carleton College; Clemson University; Columbia University; Drexel University; Duke University; Emory University; Fort Lewis College; George Mason University; Georgetown University; Humboldt State University; Indiana Institute of Technology; Indiana University at Bloomington; Internet2; Iowa State University; James Madison University; Lafayette College; Loyola University Maryland; Medical University of South Carolina; Miami University; Michigan Technological University; Northwestern University; Ohio Northern University; Ohio University Main Campus; Penn State (The Pennsylvania State University); Princeton University; Purdue University Main Campus; Regis University; Rice University; San Diego State University; San Francisco State University; San Jose State University; Skidmore College; Sonoma State University; Southern Methodist University; Texas Tech University; The Moody Bible Institute of Chicago; The Ohio State University; The University of Montana; University of Alaska Statewide System; University of California, Office of the President; University of California-Berkeley; University of California-Davis; University of California-Los Angeles; University of California-San Diego; University of California-San Francisco; University of Central Florida; University of Chicago; University of Cincinnati Main Campus; University of Florida; University of Illinois at Urbana-Champaign; University of Iowa; University of Maryland Baltimore County; University of Massachusetts; University of Minnesota-Twin Cities; University of Missouri System; University of Nebraska – Lincoln; University of North Carolina At Greensboro; University of Richmond; University of South Florida; University of Texas at Arlington; University of Texas at Austin; University of Texas At Brownsville; University of Texas at Dallas; University of Texas at El Paso; University of Texas at San Antonio; University of Texas At Tyler; University of Texas Health Science Center At Houston; University of Texas Health Science Center At San Antonio; University of Texas M. D. Anderson Cancer Center; University of Texas Medical Branch At Galveston; University of Texas of the Permian Basin; University of Texas Southwestern Medical Center at Dallas; University of Texas System; University of Texas-Pan American; University of Vermont; University of Virginia; University of Wisconsin Madison; University of Wisconsin-Whitewater; Villanova University; Virginia Commonwealth University; and Whitman College. [Source: ]

What About The Comodo Incident? InCommons Certificate Service partner, Comodo, had a recent incident (mid-March 2011) that attracted media attention. With the partnership between InCommon & Comodo, questions have arisen. Key Point: This incident does NOT impact the InCommon Certificate Services. A short summary of this incident: -- A Comodo reseller account was compromised; certs were issued that could be used to spoof certain high-value websites. -- Comodo revoked the certificates and communicated details of the incident in a blog post (see data-security/the-recent-ra-compromise/ ) -- This in no way affects the InCommon Certificate Service, the InCommon physical Certificate Authority (CA) systems, or for that matter any Comodo CA. The incident involved an account username/password issue. The security of all the Comodo CAs and their private keys are intact. [ ]

CRLs and OCSP The Comodo incident did highlight one issue you may want to think about, and thats how systems handle revoked certificates. Note: This is not an issue thats specific to the InCommon Certificate Service, this is a broad/general cert-related issue. Certificate Revocation Lists (RFC5280) and the Online Certificate Status Protocol (RFC2560) are supposed to be the basis for signaling the revocation status of certs. Unfortunately, some browsers (such as Safari) do not do CRL and OCSP checking by default. If revocation checking isnt done, users risk trusting a revoked certificate, which is generally a pretty bad idea. You may want to encourage your users to consider using browsers that do support OCSP and CRLs by default (such as current versions of Firefox).