PKI: Glue of Middleware Michael R Gettes, Duke University EuroCAMP March, 2005 Michael R Gettes, Duke University EuroCAMP March, 2005.

Slides:



Advertisements
Similar presentations
NIH-EDUCAUSE PKI Interoperability Project Electronic Grant Application With Multiple Digital Signatures Peter Alterman, Ph.D. Director of Operations Office.
Advertisements

PKI Solutions: Buy vs. Build David Wasley, U. California (ret.) Jim Jokl, U. Virginia Nick Davis, U. Wisconsin.
May 06, 2002 Getting Started with Digital Certificates: Is PKI-Lite Real PKI? Internet2 Spring Meeting 2002 Wash, DC.
NSF Middleware Initiative: Managing Identity on Campus Michael R Gettes, Duke University Tom Barton, University of Chicago.
Copyright Judith Spencer This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial,
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
Computer Security: Principles and Practice EECS710: Information Security Professor Hossein Saiedian Fall 2014 Chapter 23: Internet Authentication Applications.
Lecture 23 Internet Authentication Applications
NIH – EDUCAUSE PKI Interoperability Pilot Update Peter Alterman, Ph.D. Director of Operations, Office of Extramural Research, NIH and Senior Advisor to.
Update on federations, PKI, and federated PKI for US feds and higher eds Tom Barton University of Chicago.
PKI in US Higher Education TAGPMA Meeting, March 2006 Rio De Janeiro, Brazil.
Got Directory? January 28, 2004 TIP metadirectory enterprise directory database departmental directories OS directories (MS, Novell,
PKI Activities at Virginia January 2004 CSG Meeting Jim Jokl.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
David L. Wasley Information Resources & Communications Office of the President University of California Directories and PKI Basic Components of Middleware.
Higher Education Bridge Certificate Authority (HEBCA) Project Progress Fed/Ed June 2005.
US Higher Ed PKI Activities Internet2/EDUCAUSE ++ TF-EMC2 November, 2004 Amsterdam Michael R Gettes, Duke University TF-EMC2 November, 2004 Amsterdam Michael.
The 4BF The Four Bridges Forum Higher Education Bridge Certificate Authority.
PKI Update. Topics Background: Why/Why Not, The Four Planes of PKI, Activities in Other Communities Technical activities update S/MIME Pilot prospects.
Higher Education Bridge Certificate Authority (HEBCA) Project Progress Fed/Ed December 2004.
Identity Management and PKI Credentialing at UTHSC-H Bill Weems Academic Technology University of Texas Health Science Center at Houston.
HEBCA – Higher Education Bridge Certification Authority Presented by Scott Rea and Mark Franklin, Fed/Ed Meeting, 12/14/2005.
CAMP - June 4-6, Copyright Statement Copyright Robert J. Brentrup and Mark J. Franklin This work is the intellectual property of the authors.
The E-Authentication Initiative An Overview Peter Alterman, Ph.D. Assistant CIO for e-Authentication, NIH and Chair, Federal PKI Policy Authority The E-Authentication.
1 USHER Update Fed/ED December 2007 Jim Jokl University of Virginia.
9/20/2000www.cren.net1 Root Key Cutting and Ceremony at MIT 11/17/99.
EDUCAUSE PKI Working Group Where Are We and Where are We Going.
PKI: Glue of Middleware Michael R Gettes, Duke University CAMP Enterprise Authentication Michael R Gettes, Duke University CAMP Enterprise Authentication.
F. Guilleux, O. Salaün - CRU Middleware activities in French Higher Education.
Transforming Education Through Information Technologies Common Solutions Group, January, 2002 (Sanibel Island) HEBCA: Higher Education.
David L. Wasley Office of the President University of California Higher Ed PKI Certificate Policy David L. Wasley University of California I2 Middleware.
Bridging Higher Education PKIs PKI Summit, August 2006 Snowmass, Colorado.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
HEBCA Overview Internet2 Meeting, Fall 2002 Michael R Gettes Georgetown University
Lecture 23 Internet Authentication Applications modified from slides of Lawrie Brown.
1 PKI & USHER/HEBCA Fall 2005 Internet2 Member Meeting Jim Jokl September 21, 2005.
X.509/PKI There is progress.... Topics Why PKI? Why not PKI? The Four Stages of X.509/PKI Other sectors Federal Activities - fBCA, NIH Pilot, ACES, other.
Computer Security: Principles and Practice First Edition by William Stallings and Lawrie Brown Lecture slides by Lawrie Brown Chapter 22 – Internet Authentication.
Chapter 23 Internet Authentication Applications Kerberos Overview Initially developed at MIT Software utility available in both the public domain and.
Co Chairs C. W. Goldsmith University of Alabama at Birmingham David L. Wasley University of California Office of the President.
Digital Signatures A Brief Overview by Tim Sigmon April, 2001.
The NIH PKI Pilots Peter Alterman, Ph.D. … again.
HEPKI-PAG Policy Activities Group David L. Wasley University of California.
NSF Middleware Initiative Renee Woodten Frost Assistant Director, Middleware Initiatives Internet2 NSF Middleware Initiative.
Introduction to Public Key Infrastructure January 2004 CSG Meeting Jim Jokl.
Federal and State PKI Bridge Evolution: Cutting Across Stovepipes EDUCAUSE 2000 October 12th, 2000.
PKI and the U.S. Federal E- Authentication Architecture Peter Alterman, Ph.D. Assistant CIO for e-Authentication National Institutes of Health Internet2.
Internet2 Middleware PKI: Oy-vey! Michael R. Gettes Principal Technologist Georgetown University
HEBCA Overview CSG, uWash, 2002 Michael R Gettes Georgetown University
The Federal PKI Or, How to Herd Worms Peter Alterman Senior Advisor, Federal PKI Steering Committee.
Leveraging Campus Authentication for Grid Scalability Jim Jokl Marty Humphrey University of Virginia Internet2 Meeting April 2004.
“Trust me …” Policy and Practices in PKI David L. Wasley Fall 2006 PKI Workshop.
The Feds and Shibboleth Peter Alterman, Ph.D. Asst. CIO, E-Authentication National Institutes of Health.
Identity Federations and the U.S. E-Authentication Architecture Peter Alterman, Ph.D. Assistant CIO, E-Authentication National Institutes of Health.
Higher Ed Bridge CA Extending Trust Across Higher Education - And Beyond David L. Wasley University of California.
HEBCA – The Operating Authority July 2005 Dartmouth PKI Summit.
Day 3 Roadmap and PKI Update. When do we get to go home? Report from the BoFs CAMP assessment, next steps PKI technical update Break Research Issues in.
Electronic Security and PKI Richard Guida Chair, Federal PKI Steering Committee Chief Information Officers Council
Federal PKI Update Peter Alterman, Ph.D. Chair, Federal PKI Policy Authority.
Trusted Electronic Communications for Federal Student Aid Mark Luker Vice President EDUCAUSE Copyright Mark Luker, This work is the intellectual.
Peter Alterman, Ph.D. Chair, Federal PKI Policy Authority Meet FedFed.
Higher Education Bridge Certification Authority Scaleable Linking of PKI trust domains Scaleable Linking of PKI trust domains David L. Wasley Fall 2006.
1 US Higher Education Root CA (USHER) Update Fed/Ed Meeting December 14, 2005 Jim Jokl University of Virginia.
Federal Identity Management Overview and Current Status Dr. Peter Alterman, Chair Federal PKI Policy Authority.
Federal Initiatives in IdM Dr. Peter Alterman Chair, Federal PKI Policy Authority.
U.S. Federal e-Authentication Initiative
USHER U.S. Higher Education Root Certificate Authority
Internet2 Member Meeting
Inter-institutional Trust Fabric Overview and Synergies
Fed/ED December 2007 Jim Jokl University of Virginia
Presentation transcript:

PKI: Glue of Middleware Michael R Gettes, Duke University EuroCAMP March, 2005 Michael R Gettes, Duke University EuroCAMP March, 2005

Landscaping PKI Hierarchies and Bridges National PKI HEBCA, USHER, InCommon Gap Analysis Development and Cost Sharing EDUCAUSE and Internet2 Federation Crosswalk InCommon & US Federal Government eAuth (again!) I-CIDM and JSF PKI Hierarchies and Bridges National PKI HEBCA, USHER, InCommon Gap Analysis Development and Cost Sharing EDUCAUSE and Internet2 Federation Crosswalk InCommon & US Federal Government eAuth (again!) I-CIDM and JSF

Reminder … SSL/TLS SAML Browsers Servers Shibboleth Client PKI issues, CRLs, authentication SSL/TLS SAML Browsers Servers Shibboleth Client PKI issues, CRLs, authentication

Directories are part of the I in PKI Directory Centralized, automated Name Space VERY carefully controlled Users modify very little Priv’d access highly restricted Control considered necessary step for PKI to trust the directory Eventually, client, server and other certs/CRLs will be published in the directory. Directory Centralized, automated Name Space VERY carefully controlled Users modify very little Priv’d access highly restricted Control considered necessary step for PKI to trust the directory Eventually, client, server and other certs/CRLs will be published in the directory.

Are the Directories part of I in PKI? Kx509 (part of NMI distribution) Short-lived Certificates Avoids CRL and Directory Publications MIT 1 year certs, but people can get all they need using Kerberos Authentication But… A namespace infrastructure is still assumed and they all have it. Kx509 (part of NMI distribution) Short-lived Certificates Avoids CRL and Directory Publications MIT 1 year certs, but people can get all they need using Kerberos Authentication But… A namespace infrastructure is still assumed and they all have it.

PKI Basics (Hierarchies) ROOT X Y

PKI Basics (Bridges) ROOT X Y Directories Bridge Membrane

Multiple CAs in FBCA Membrane Survivable PKI Cross Certificates allow for “one/two-way policy” Directories are critical in BCA world. Clients changing Survivable PKI Cross Certificates allow for “one/two-way policy” Directories are critical in BCA world. Clients changing

Technical Policy PKI is 1/3 Technical and 2/3 Policy? Right?

HEPKI Council Jack McCredie, Chair, UC Berkeley Michael Baer, Sr VP ACE Rich Guida, Johnson & Johnson Mark Luker, EDUCAUSE Mark Olson, EVP of NACUBO Dave Smallen, Hamilton College Nancy Tribbensee, ASU Not operational, policy and oversight Will approve the creation of the HEBCA Policy Authority Completed November 15, 2004 Charged with Higher Education direction and strategy for PKI initiatives, not just Bridge Jack McCredie, Chair, UC Berkeley Michael Baer, Sr VP ACE Rich Guida, Johnson & Johnson Mark Luker, EDUCAUSE Mark Olson, EVP of NACUBO Dave Smallen, Hamilton College Nancy Tribbensee, ASU Not operational, policy and oversight Will approve the creation of the HEBCA Policy Authority Completed November 15, 2004 Charged with Higher Education direction and strategy for PKI initiatives, not just Bridge

HEBCA Policy Authority Created January 1, 2005 Larry Levine, Dartmouth College, Chair Nancy Tribbensee (ASU & Counsel) Sheila Sanders (UAB) Mark Luker (EDUCAUSE) David Wasley (UCOP) Barry Ribbeck (Rice) Carrie Regenstein (Wisconsin-Madison & InCommon) Michael Gettes (Duke) Bi-Weekly calls Moving along quickly (a rare occurrence for us!) Created January 1, 2005 Larry Levine, Dartmouth College, Chair Nancy Tribbensee (ASU & Counsel) Sheila Sanders (UAB) Mark Luker (EDUCAUSE) David Wasley (UCOP) Barry Ribbeck (Rice) Carrie Regenstein (Wisconsin-Madison & InCommon) Michael Gettes (Duke) Bi-Weekly calls Moving along quickly (a rare occurrence for us!)

On Campus End Entity: Some schools, MIT, Dartmouth, UTHSC but not wide deployment in US. i2 trials on Doc Sigs Server Side and Infrastructure -- used all over the place but not yet well coordinated Lacking a national infra for Higher Ed HEBCA/USHER/InCommon/SAML PKI is just 18 months away (again!) :-) End Entity: Some schools, MIT, Dartmouth, UTHSC but not wide deployment in US. i2 trials on Doc Sigs Server Side and Infrastructure -- used all over the place but not yet well coordinated Lacking a national infra for Higher Ed HEBCA/USHER/InCommon/SAML PKI is just 18 months away (again!) :-)

PKI in HE – 5 likely “Killer Apps” Signed Stop identity spoofing from weak passwords, etc. Increase use of electronic commerce at campus & Institutional & national levels Windows and Office Applications Interop Shibboleth GRID Computing Enabled for Federations E-grants Faster, secured grant processing Faster (e-)payments More secured communications & fund Xfers Federal focus is on this initiative Signed Stop identity spoofing from weak passwords, etc. Increase use of electronic commerce at campus & Institutional & national levels Windows and Office Applications Interop Shibboleth GRID Computing Enabled for Federations E-grants Faster, secured grant processing Faster (e-)payments More secured communications & fund Xfers Federal focus is on this initiative

US Higher Ed Root:USHER To use ID Proofing policies of CREN augmented for InCommon Low Barrier to entry Coming from Internet2 Should be X-Certified with HEBCA Analog to US Federal Root CA Approval to proceed Feb 27, 2005 To use ID Proofing policies of CREN augmented for InCommon Low Barrier to entry Coming from Internet2 Should be X-Certified with HEBCA Analog to US Federal Root CA Approval to proceed Feb 27, 2005

HEBCA Current Status HEBCA Certificate Policy (brother Wasley) Will develop CPS from this policy (have draft) Dartmouth College Contracted to implement HEBCA in 12/03 EDUCAUSE funded Received AEG from Sun Microsystems ($50K) Equipment ordered and received Signing Hardware -- not yet. Working software agreement with RSA as first CA in bridge Maybe even further deal with Higher Ed for CA services & s/w Informal cross-certification with US Gov completed Will operate at High Level of Assurance HEBCA Certificate Policy (brother Wasley) Will develop CPS from this policy (have draft) Dartmouth College Contracted to implement HEBCA in 12/03 EDUCAUSE funded Received AEG from Sun Microsystems ($50K) Equipment ordered and received Signing Hardware -- not yet. Working software agreement with RSA as first CA in bridge Maybe even further deal with Higher Ed for CA services & s/w Informal cross-certification with US Gov completed Will operate at High Level of Assurance

I-CIDM International Collaboration on Identity Mgmt Joint Strike Fighter Program (big $$$$) Rules of Engagement Citizenship, Legal, Technical, Policy & Process (Criteria & Methods, CP/CPS, Corporate Policy) Principal Parties US Higher Education FBCA Pharmaceutical Industry (SAFE) Commercial Aerospace (JSF, Internationally Driven and Participation International Collaboration on Identity Mgmt Joint Strike Fighter Program (big $$$$) Rules of Engagement Citizenship, Legal, Technical, Policy & Process (Criteria & Methods, CP/CPS, Corporate Policy) Principal Parties US Higher Education FBCA Pharmaceutical Industry (SAFE) Commercial Aerospace (JSF, Internationally Driven and Participation

HEBCA/USHER Synergy Sun Hardware Donation RSA/Keon Software Donation License covers Cert issuance for all PKI ops High Level of Assurance Separation of Duties Admin, Operator, Officer, Auditor Revocation and Citizenship Issues Ops(Dartmouth); RA/Storefront(Internet2) Need to interoperate with US Feds Sun Hardware Donation RSA/Keon Software Donation License covers Cert issuance for all PKI ops High Level of Assurance Separation of Duties Admin, Operator, Officer, Auditor Revocation and Citizenship Issues Ops(Dartmouth); RA/Storefront(Internet2) Need to interoperate with US Feds

InCommon & eAuth Federation interop with Shib (PKI in SAML) To ultimately use Bridge PKI as means of validating and locating members of OTHER federations InCommon CA to X-Certify with HEBCA or be signed by USHER having been X- Certified with HEBCA Shib+Grid to address some Grid issues HEBCA+Grid considered but no work yet See next slide… Federation interop with Shib (PKI in SAML) To ultimately use Bridge PKI as means of validating and locating members of OTHER federations InCommon CA to X-Certify with HEBCA or be signed by USHER having been X- Certified with HEBCA Shib+Grid to address some Grid issues HEBCA+Grid considered but no work yet See next slide…

Federated Digital Signatures Proposed for Phase 5 of PKI Interop Project Use Local PKI for workflow and signatures When document leaves local domain, substitute institutional signature and XML blob describing roles, digital rights & IPR, archival status, etc (IFA) Why do this? Bridges + Inter-Federation Agreements (IFA) can address this -- something else to avoid Bridges. We need to figure out what goes into IFAs to make this useful. Proposed for Phase 5 of PKI Interop Project Use Local PKI for workflow and signatures When document leaves local domain, substitute institutional signature and XML blob describing roles, digital rights & IPR, archival status, etc (IFA) Why do this? Bridges + Inter-Federation Agreements (IFA) can address this -- something else to avoid Bridges. We need to figure out what goes into IFAs to make this useful.

Server Certs for Higher Ed Working with Jan Meijer, Surfnet To obtain server certs (SSL/TLS) for use within Higher Education in USA and Europe. $50K for USA, E50K for EU All connections should be encrypted Search for plain text using IDS on campus Popup Free browser experience Still negotiating … Globalsign & RSA Working with Jan Meijer, Surfnet To obtain server certs (SSL/TLS) for use within Higher Education in USA and Europe. $50K for USA, E50K for EU All connections should be encrypted Search for plain text using IDS on campus Popup Free browser experience Still negotiating … Globalsign & RSA

Global? Trust Diagram (TWD)

PKIs HEBCAFBCA InCommon eAuth/JSF Non-US Gov US-Centric View of PKI World Industry Federations USHER FedRoot Non-US ???