Download presentation
Presentation is loading. Please wait.
Published byArron Burke Modified over 8 years ago
1
Real Life Enterprise PKI MMS Minnesota 2014 Hasain Alshakarti – TrueSec Enterprise Security MVP @Alshakarti #MMSMinnesota #MMSConfigMgr #MMSLove
2
Level of protection required? Polices & Compliance Tiers & Hierarchies Key length, Lifetime & Integrity Algorithms Availability & Recovery Revocation Information Administration & Roles Audit & Monitoring
3
Key Integrity? Offline Hardware Security Module (HSM) Least Access & Least Privilege Hardened System
4
Algorithms Signing (RSA/DSA/ECC) Hashing (SHA1/SHA256)
5
Tiers & Hierarchies Whitepapers & Books Requirements Policy & Compliance Functional Organizational
6
Availability & Recovery Functional Availability Issuing Revocation Information Backup
7
Revocation Information PKI Client centric Base, delta and overlapping CRL OCSP Caching Validation behavior & usage Application oriented
8
Enterprise vs Standalone CA? Trust: Issuer of Authentication Tokens “Golden Ticket” Ent CA = DC Ent CA Admin = Ent Admin Enrollment Certificate Templates (AD Objects) Auto Enrollment (AD ACE & Templates)
9
CA Compromise? Relying Parties (RP)
10
Real Life Enterprise PKI Evaluations Please provide session feedback by clicking the Eval button in the scheduler app. One lucky winner will get a free ticket to the next MMS! Visit all of our sponsors in the expo area and online! Platinum Sponsors: Gold Sponsors : MMS Minnesota 2014 Hasain Alshakarti – TrueSec
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.