Download presentation
Presentation is loading. Please wait.
Published byCuthbert Quentin Green Modified over 9 years ago
1
Inside the PKI Framework: * Activating the Puzzle Pieces PKI Summit Snowmass August 10 2001
2
8/10/01www.cren.net2 Themes —(1)Parallelism and (2) Build on What We Have… 1. Technical developments (TAG) 2. Policy Developments (PAG) 3. Web Lite & Ultra-Lite PKI Services
3
PKI is a complex set of technologies — Thus lots of pieces... Theme #3: Time to Get Started...
4
8/10/01www.cren.net4 Sample Uses of Digital Certificates with Web Applications from Campuses Inter-library Loan Requests Student Registration Transcripts Faculty to see grade reports, etc Students to see their grade reports Housing Lottery HR Self Service E-commerce Access to Class or Departmental Materials Access to journals from non-campus machines Portal Authentication Network Requests From HEPKI-TAG /J. Jokl Chart
5
8/10/01www.cren.net5 What Can CREN Bring to this Space? Educational Services CA Higher education services, tailored to and responsive to higher education
6
8/10/01www.cren.net6 Adding Value with CREN CA Services Intra-campus Services - Web Server Certificates l Support secure web server applications and services Solves need for secure authorization for campus services Inter-Institutional Services - Institutional Certs l Support secure and convenient access to learning and research materials anywhere and anytime Solves messy problems associated with proxy servers Certifies Campus Certificates for many purposes Both Campus and Inter-Institutional Services - Institutional Certs l Support secure and signed email Solves problems of sending documents and communications securely and with integrity
7
8/10/01www.cren.net7 Web Server Certs Service Web Server Certs Service Campus Services - Authorization - Signed, Secure Email Campus Services - Authorization - Signed, Secure Email PKI Landscape…The Campus Infrastructure for Digital Certs Campus Infrastructure - Know Your People - Issue Digital Certificates - Setup Secure Servers Campus Infrastructure - Know Your People - Issue Digital Certificates - Setup Secure Servers CREN CA Institutional Certificate Service
8
8/10/01www.cren.net8 Core PKI Pieces - Campus Packaging
9
8/10/01www.cren.net9 Supporting CA Services Overview Policy work l Supporting the HE_CP Work l Update CREN CPS (January 27, 2000) Educational Services - Seminars, etc Getting Started Projects Certificate Repository
10
8/10/01www.cren.net10 CA Educational Services - 2001 Seminars l Directories and Certificate Authority Services January and June 2001 Supported by NSF Almost 100 institutions represented... Survey on state of implementation at campuses... Frequently Asked Questions (FAQ) Series PKI Infrastructure (1999) Institutional Directories (April, 2000)
11
8/10/01www.cren.net11 CA Educational Services - What’s Next? Seminars l Directories and Certificate Authority Services More being planned… Clear requests/feedback on what to do next... Web site updating CA Bulletins - Examples l Loading Root Certificates l Accessing JSTOR with Digital Certificates TechTalks...
12
8/10/01www.cren.net12 CREN CA Web Server Certificates Available now Self-signed root issued on July 12, 2001, valid until July 10, 2009 Issued to institutions via existing institutional technical contacts l One contact/conduit per institution l Quick turnaround after CSR is received Users will load CREN root into browser - See “Root Bulletin” and web site
13
8/10/01www.cren.net13 Getting Started with Dig Certs - The JSTOR Project Goal: l Use digital certificates to access JSTOR l Draft Bulletin… Project supported by Mellon A PKI-Lite Project using rudimentary level of assurance (LOA) Project just redesigned over last two weeks Org Committee recommended to focus on librarians and 2-3 content providers
14
8/10/01www.cren.net14 Getting Started with Dig Certs - The JSTOR Project Meeting at Internet2/Austin Institutions with IT people and librarians who work well together Invite 14-15 institutions Proposed scope of project... l Issue 50 -250 certificates to needy faculty, students l Develop materials to enthuse and disseminate information and opportunity l Report on projects at Spring CNI
15
8/10/01www.cren.net15 Getting Started with Dig Certs - The JSTOR Project JSTOR is ready — is digital certificate- enabled with a log-in url ready Applies three tests to certificates l Is the issuer of certificate, such as U of Minn in their current licensee database? l Is the certificate a valid certificate, in that it has not expired? l Is the certificate a valid certificate — does it contain a valid chain to a recognized root, i.e. CREN?
16
8/10/01www.cren.net16 Web Server Certs Service Web Server Certs Service Campus Uses - Authorization - Signed, Secure Email Campus Uses - Authorization - Signed, Secure Email The Campus Infrastructure and Link to Content Providers Campus Infrastructure - Know Your People - Issue Digital Certificates - Setup Secure Servers Campus Infrastructure - Know Your People - Issue Digital Certificates - Setup Secure Servers Content Providers - Non-Profit - For-Profit - University Databases CREN CA Institutional Certificate Service
17
8/10/01www.cren.net17 Making progress… “Because it is Time”
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.