PKI Forum Application Cert Interop Project David Crowe

Slides:



Advertisements
Similar presentations
Public Key Infrastructure and Applications
Advertisements

NIH-EDUCAUSE PKI Interoperability Project Electronic Grant Application With Multiple Digital Signatures Peter Alterman, Ph.D. Director of Operations Office.
EDUCAUSE 2001, Indianapolis IN Securing e-Government: Implementing the Federal PKI David Temoshok Federal PKI Policy Manager GSA Office of Governmentwide.
SSL Implementation Guide Onno W. Purbo
Grid Computing, B. Wilkinson, 20045a.1 Security Continued.
1st Expert Group Meeting (EGM) on Electronic Trade-ECO Cooperation on Trade Facilitation May 2012, Kish Island, I.R.IRAN.
CREN-Mellon conference, December 1, 2001 University of Texas PKI Status.
WISeWorld2000 WISeKey By Malcolm Hutchinson CEO & Cofounder WISekey.
Financial Systems Needs Assessment Project Update Monthly Research Administrators Meeting March 11, 2010.
Uncle Sam, Meet The PKI! Richard Guida Chair, Federal PKI Steering Committee Michèle Rubenstein Department of the Treasury,
Sentry: A Scalable Solution Margie Cashwell Senior Sales Engineer Sept 2000 Margie Cashwell Senior Sales Engineer
The PKI Lab at Dartmouth. Dartmouth PKI Lab R&D to make PKI a practical component of a campus network Multi-campus collaboration sponsored by the Mellon.
Introduction to PKI Seminar What is PKI? Robert Brentrup July 13, 2004.
Introduction to PKI Mark Franklin September 10, 2003 Dartmouth College PKI Lab.
CERTIFICATES “a document containing a certified statement, especially as to the truth of something ”
CS470, A.SelcukPKI1 Public Key Infrastructures CS 470 Introduction to Applied Cryptography Instructor: Ali Aydin Selcuk.
CAMP - June 4-6, Copyright Statement Copyright Robert J. Brentrup and Mark J. Franklin This work is the intellectual property of the authors.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Online AAI José A. Montenegro GISUM Group Security Information Section University of Malaga Malaga (Spain) Web:
VDA Security Services Freeware Libraries Update IETF S/MIME WG 29 March 2000 John Pawling J.G. Van Dyke & Associates (VDA), Inc;
Wolfgang Schneider NSI: A Client-Server-Model for PKI Services.
Security Directions - Release 6 and beyond SearchDomino.com Webcast Patricia Booth Security and Directory Product Management 9/25/02.
Securing Data at the Application Layer Planning Authenticity and Integrity of Transmitted Data Planning Encryption of Transmitted Data.
SNIA/SSIF KMIP Interoperability Proposal. What is the proposal? Host a KMIP interoperability program which includes: – Publishing a set of interoperability.
PKI interoperability and policy in the wireless world.
S/MIME Freeware Library IETF S/MIME WG 13 December 2000 Getronics Government Solutions.
Technical Working Group June 2001 Andrew Nash Steve Lloyd.
TNC2004 Rhodes 1 Authentication and access control in Sympa mailing list manager Serge Aumont & Olivier Salaün May 2004.
02/22/2005 Joint Seminer Satoshi Koga Information Technology & Security Lab. Kyushu Univ. A Distributed Online Certificate Status Protocol with Low Communication.
Chapter 9: Using and Managing Keys Security+ Guide to Network Security Fundamentals Second Edition.
Introduction to Secure Sockets Layer (SSL) Protocol Based on:
Unit 1: Protection and Security for Grid Computing Part 2
Chapter 23 Internet Authentication Applications Kerberos Overview Initially developed at MIT Software utility available in both the public domain and.
Co Chairs C. W. Goldsmith University of Alabama at Birmingham David L. Wasley University of California Office of the President.
Certificate-Based Operations. Module Objectives By the end of this module participants will be able to: Define how cryptography is used to secure information.
06 APPLYING CRYPTOGRAPHY
Technical Working Group December 2000 Mark Davis Andrew Nash.
Digital Signatures A Brief Overview by Tim Sigmon April, 2001.
CERTIFICATES. What is a Digital Certificate? Electronic counterpart to a drive licenses or a passport. Enable individuals and organizations to secure.
Module 9: Fundamentals of Securing Network Communication.
Secure Messaging Workshop The Open Group Messaging Forum February 6, 2003.
Dartmouth PKI Update Robert Brentrup Internet2 Member Meeting April 21, 2004.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
1. 2 Overview In Exchange security is managed by assigning permissions in Active Directory Exchange objects are secured with DACL and ACEs Permissions.
Security in ebXML Messaging CPP/CPA Elements. Elements of Security P rivacy –Protect against information being disclosed or revealed to any entity not.
© 2003 The MITRE Corporation. All rights reserved For Internal MITRE Use Addressing ISO-RTO e-MARC Concerns: Clarifications and Ramifications Response.
Who’s watching your network The Certificate Authority In a Public Key Infrastructure, the CA component is responsible for issuing certificates. A certificate.
1 A Division of TruSecure Corporation CMP Interop Project December 6, 2000 Robert Moskowitz
Security fundamentals Topic 5 Using a Public Key Infrastructure.
Computer and Network Security - Message Digests, Kerberos, PKI –
Bridge Certification Architecture A Brief Overview by Tim Sigmon May, 2000.
Some Technical Issues in PKI Deployment David Chadwick
Digital Signatures and Digital Certificates Monil Adhikari.
Libpkix & CertPath: Bringing High Quality Certificate Handling to the Masses PKI Higher Education Summit July 14, 2004 Steve Hanna, Sun Microsystems, Inc.
Copyright Statement Copyright Robert J. Brentrup This work is the intellectual property of the author. Permission is granted for this material to.
1 Certification Issue : how do we confidently know the public key of a given user? Authentication : a process for confirming or refuting a claim of identity.
1 Public Key Infrastructure Rocky K. C. Chang 6 March 2007.
Application Cert Interop Project David Crowe PKI Forum, Jun 2001, Munich, Germany.
This courseware is copyrighted © 2016 gtslearning. No part of this courseware or any training material supplied by gtslearning International Limited to.
Interoperability and the Evolving Federal PKI Richard Guida, P.E. Member, Government Information Technology Services Board Chair, Federal PKI Steering.
GRID-FR French CA Alice de Bignicourt.
Prof. Reuven Aviv, Nov 2013 Public Key Infrastructure1 Prof. Reuven Aviv Tel Hai Academic College Department of Computer Science Public Key Infrastructure.
December 13, 2000 Robert Moskowitz
کاربرد گواهی الکترونیکی در سیستمهای کاربردی (امضای دیجیتال)
June 28, 2000 Robert Moskowitz CMP Interop Project June 28, 2000 Robert Moskowitz
刘振 上海交通大学 计算机科学与工程系 电信群楼3-509
September 2002 CSG Meeting Jim Jokl
Electronic Payment Security Technologies
刘振 上海交通大学 计算机科学与工程系 电信群楼3-509
National Trust Platform
Presentation transcript:

PKI Forum Application Cert Interop Project David Crowe

Project Purpose To establish interoperability of application certs Pertains both to certs themselves, issued by different vendors’ CAs, and to the certs’ usage by applications Focus is on finding successful interoperations rather than on seeking “complete” interoperability between products

Project Deliverables Public demonstration –to cover a chosen subset of our successful tests –to be scheduled by Sep 2000 Results Matrices –A matrix for each script listing successfully tested variants

Matrix for SSL Script

Matrix for S/MIME Script

Project Plan (so far) Solicit participation (14 Apr 2000) Agree on project plan, scenarios, applications, & algorithms (Apr-May 2000) Flesh out the scenarios (May 2000) Perform tests through bilateral electronic communication (May-Jun 2000) Have 1st communal "bake-off" (26 Jun 2000 in Dublin)

Project Plan (from now on) Provide TWG with status update, solicit feedback (28-29 Jun 2000 in Dublin) Fix problems encountered (Jul-Aug 2000) Plan public demo (Jul 2000) Have 2nd communal "bake-off" to verify success (12 Sep 2000 in Montreal)

Achievements to Date Participants lined up (more are welcome) Test scripts prepared (more are welcome) –Inter-PKI application cert usage (SSL) –S/MIME Remote testing underway Initial bake-off held

Test Scripts Have different variants Participants (& pairs of participants) will test only variants of interest to them Each successful test of a variant is shown as a row in the results matrix Internal test results are private to the participants involved (but results matrices are published)

SSL Script Tests one PKI vendor's web server's ability to authenticate user presenting another PKI vendor's cert Variants: –status checking: CRLs (v1 & v2) & OCSP (with CA signer, designated signer, & out-of- band-agreed signer) –algorithms: RSA & DSA

S/MIME Script Tests S/MIME transfer between two users possessing certs from different PKI vendors Focuses on cert interoperability Separate scripts might be desired for testing client interoperability

S/MIME Script (2) Variants: –status checking: CRLs (v1 & v2) & OCSP (with CA signer, designated signer, & out-of- band-agreed signer) –single & dual certs – client –S/MIME v2 & v3

Early Test Findings Early tests relate to cert path construction & validation—for which script is not written yet Tests indicate need for configuration notes in addition to results matrix rows Test results are preliminary, with tests needing to be rerun using full written script

Cert Path Construction & Validation Results Vendor for CACA SoftwareVendor for Application Application Software How Constructed Status Checking Algorithm for CAs Algorithm for End-Entity Certs XcertSentry CAEntegrityPKI BenchManuallyCRLRSA XcertSentry CAEntegrityPKI BenchManuallynoneRSA KeonEntegrityPKI BenchManuallyCRLRSA KeonEntegrityPKI BenchManuallynoneRSA XcertSentry CACeloCelocom MailManuallyCRLRSA XcertSentry CACeloCelocom MailManuallynoneRSA XcertSentry CACeloCelocom MailManuallyCRLmixed RSA & DSA RSA XcertSentry CACeloCelocom MailManuallynonemixed RSA & DSA RSA XcertSentry CACeloSignature Plugin ManuallyCRLRSA XcertSentry CACeloSignature Plugin ManuallynoneRSA XcertSentry CACeloSignature Plugin ManuallyCRLmixed RSA & DSA RSA XcertSentry CACeloSignature Plugin Manuallynonemixed RSA & DSA RSA XcertSentry CACeloSSL-GatewayManuallyCRLRSA XcertSentry CACeloSSL-GatewayManuallynoneRSA XcertSentry CACeloSSL-GatewayManuallyCRLmixed RSA & DSA RSA XcertSentry CACeloSSL-GatewayManuallynonemixed RSA & DSA RSA XcertSentry CAEntegrityPKI BenchPKCS#7 built by Celo Signature Plugin CRLRSA

Project Participants Baltimore Technologies Celo Communications Entegrity Solutions Entrust JAWS Technologies Netlexis Rainbow Technologies RSA Security Tivoli (IBM) Xcert

Discussion Tomorrow Suggestions for improvements to project plan