Download presentation
Presentation is loading. Please wait.
Published byWarren Barber Modified over 8 years ago
1
On live video supported F2F May 9-11, 2016 Abingdon, Oxfordshire, UK
2
37 th EUGridPMA Abingdon – May 2016 2 David Groep – davidg@eugridpma.org For the BIRCH and CEDAR Assurance [Vetting] should be based on a face-to-face meeting and should be confirmed via photo-identification and/or similar valid official documents. Identity vetting and validation should be based on an in-person appearance before a trusted agent of the authority with presentation of a reliable photo-ID and/or valid official documents; or be validated using notary-public attestations and/or official government data sources and supported by remote live video conversation; or be performed according to Kantara LoA 2 or better.
3
37 th EUGridPMA Abingdon – May 2016 3 David Groep – davidg@eugridpma.org Some current methods Most CAs support explicit F2F only But may be designating RAs in many different ways Video-supported Notary-public via postal mail + video: BR, TR Government records: some TCS subscribers (universities with access to these databases) Kantara LoA 2 Some TCS countries (SE) for some of their applicants
4
37 th EUGridPMA Abingdon – May 2016 4 David Groep – davidg@eugridpma.org On the notary public & govt. databases In many countries, notaries are rather exclusive, and rather expensive to attest to documents (think ~€25 + half a day & travel for the appointment) Access to databases to rather complex for most orgs So e.g. HPCI and others are looking for alternatives By ‘chance’, I was exposed to another, quite interesting and rigorous process – which was easier – if you’re allowed to keep photographs … … and which some CAs (specifically HPCI, but I expect many others) would seriously want to consider!
5
37 th EUGridPMA Abingdon – May 2016 5 David Groep – davidg@eugridpma.org Challenge-response live video 1.Send a registration form that can mostly be filled beforehand to the email address of record 2.Start a video-conf (even just HD skype), and have the applicant write down some unique information on the form and sign it visibly during the chat. 3.Ask applicant to scan this form, and mail it to the RA 4.Have the applicant hold up the same form, a govt photoID, next to the face, and (I assume) have the RA take a screenshot for record 5.The RA can check if the form is correct, and – with the nonce – if it’s the same person (the video is ongoing) 6.The RA has validated the data, photoID, and a ‘video nonce’, and has the screenshot as proof
6
37 th EUGridPMA Abingdon – May 2016 6 David Groep – davidg@eugridpma.org Open questions The applicant needs a scanner & printer nearby – does that help for most applicants? Is this an alternative acceptable process? Is keeping the photograph a critical element? If so: how can we document it in a way that is verifiable?
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.