PKI in Virginia September 2000
Commonwealth Bridge Project Time Line of Activity l COVITS Meeting - September 1999 »Commonwealth of Virginia Information Technology Symposium »Established by Secretary of Technology »Richard Guida - Federal bridge talk l PSA working group of COTS »PSA Privacy, Security, and Access »COTS Council on Technology Services
Commonwealth Bridge Project Time Line of Activity cont. l PSA Presentation at UVa - Oct 1999 »Richard Guida on Federal bridge project »Eye opener for the PSA group l November 1999 PSA Report »Recommended the state establish DSI –Digital Signatures Initiative working group »Requested UVa explore adapting the federal bridge model for use in the commonwealth
Bridge Project Goals l Demonstrate adaptability of Federal approach to the Commonwealth l Simplify Virginia PKI Environment »Interoperability via a bridge »Agencies free to use best solution for their individual environments l Officially a DSI Pilot Project l Demonstrate a working bridge
Goals and Results l Planned demonstration »DIT - VeriSign »VIPNET - Entrust »DGIF - VIPNET - Entrust l Instead used UVa signed Web-form demo application
Technical l Pilot BCA based on »OpenSSL and OpenCA »Linux »Normally left turned off l Certificate profile based on Federal bridge project profile
Virginia On-Line Transaction (VOLT) Certificates l Key DSI workgroup recommendation »Reduce complexity to ensure success l VOLT certificate idea »A set of open vendor neutral PKI standards »A VOLT bridge l VOLT should be default - not mandatory l An agency to issue VOLTs for smaller agencies?
VOLT Certificate Policy and Practices Statements l COTS report – end of September l Expect a follow-on group charged to: »Develop the VOLT idea –Management structure –Draft/default Certification Policy Statement –Draft/default Certification Practices statement –Draft/default Subscriber Agreement »Anticipate starting with a relatively high assurance process l Many state agencies may choose to issue VOLT certificates
A Potential Virginia Organizational Structure Secretary of Technology VOLT Standards Committee VOLT Central Services Subcommittee VOLT Bridge Subcommittee AuditAudit Audit – CPSAudit – Bridge MOA Vendor BCA Operations From 7/30/00 Discussion Draft Paper
Future and what have we learned? l Defer policy early on – focus on vision l Our Audit department’s involvement is critical l Timing is right e-government is popular l Its ok to get involved at state level - help educate