Presented at PKI Meetings

PKI-Enabled Applications That Work

Added by the EDUCAUSE Librarian
Title:PKI-Enabled Applications That Work (ID: PKI08008)
Author(s):James A. Jokl (University of Virginia), Mark B. Jones (The University of Texas Health Science Center at Houston), and Linda Pruss (University of Wisconsin-Madison)
Origin:Presented at PKI Meetings (04/16/2008)
Type:Presentations/Speeches
Abstract:

Having PKI-authenticated applications is not enough. In this session, we will discuss how applications have been PKI enabled and how they have been accepted and used. You will hear from institutions that have implemented and maintain multiple applications that are PKI authenticated and are well accepted by their user community.

View this resource:

How to Deploy and Get the Most Out of Tokens

Added by the EDUCAUSE Librarian
Title:How to Deploy and Get the Most Out of Tokens (ID: PKI08007)
Author(s):Scott A. Rea (Dartmouth College) and Paul Caskey (University of Texas System)
Origin:Presented at PKI Meetings (04/16/2008)
Type:Presentations/Speeches
Abstract:

Password-based security is no longer enough for many kinds of sensitive data, with dual-factor authentication now a requirement under some legislation. In this session, you will find what some schools have been doing to address higher levels of authentication with multifactor devices that use PKI. The Aladdin eToken will be featured, demonstrating flexible deployment configurations (smartcard and USB form factors) on multiple operating systems, including the three most important to higher education: Linux (or some variant), Apple Mac (OS X and PowerPC chip sets), and Windows. We are specifically seeking schools to participate in a new user group to be formed around support of these eToken devices.

View this resource:

PKI and LOA: It's Probably Not What You Think

Added by the EDUCAUSE Librarian
Title:PKI and LOA: It's Probably Not What You Think (ID: PKI08006)
Author(s):Stefan Wahe (University of Wisconsin-Madison) and David L. Wasley (University of California Office of the President)
Origin:Presented at PKI Meetings (04/16/2008)
Type:Presentations/Speeches
Abstract:

A level of assurance (LoA) refers to the degree of certainty that (1) a resource owner can assume a specific known physical person is associated with credentials issued by a registration authority, and (2) that physical person presented credentials before attempting to access the resource. The requirements for the level of certainty at both ends of that set of transactions should be driven by a risk assessment based on the value of the resources being protected. This session will describe the concept of LoA, outline its general components, and discuss how PKI can fit into a successful implementation of LoA.

View this resource:

Audit: Not Just for the Finance Guys Anymore

Added by the EDUCAUSE Librarian
Title:Audit: Not Just for the Finance Guys Anymore (ID: PKI08002)
Author(s):Nathan Faut (KPMG) and William A. Weems (The University of Texas Health Science Center at Houston)
Origin:Presented at PKI Meetings (04/16/2008)
Type:Presentations/Speeches
Abstract:

Auditing is an important and necessary step for establishing trust among relying parities when running a CA, PKI, and IdM system. This session will discuss what implementers should have ready when establishing their PKI, what auditors will expect from implementers, and what auditors will provide to implementers. It will also offer some illustrative real-world scenarios. You'll hear from an auditor from a Big Four firm and the CIO of a PKI shop who worked with auditors.

View this resource:

PKI and Grids

Added by the EDUCAUSE Librarian
Title:PKI and Grids (ID: PKI08003)
Author(s):James A. Jokl (University of Virginia) and Scott A. Rea (Dartmouth College)
Origin:Presented at PKI Meetings (04/16/2008)
Type:Presentations/Speeches
Abstract:

Do you already have a grid-computing deployment on campus? Or do you have researchers who need to access grid-computing resources from high-performance computing centers around the globe? In this session, you will find out how to configure your CA to issue International Grid Trust Federation (IGTF)-compliant certificates and join over a hundred CAs currently certified under approved IGTF profiles. Hear real-life experiences from SURAgrid, see bridge PKIs in action, and learn how to leverage your campus PKI infrastructure to facilitate access to worldwide grid-computing efforts.

View this resource:

Campus Success Stories: How We Did It Here

Added by the EDUCAUSE Librarian
Title:Campus Success Stories: How We Did It Here (ID: PKI08004)
Author(s):William A. Weems (The University of Texas Health Science Center at Houston), Phil Saunders (University of Wisconsin-Madison), and Scott A. Rea (Dartmouth College)
Origin:Presented at PKI Meetings (04/16/2008)
Type:Presentations/Speeches
Abstract:

Deploying PKI can be complex and tricky, but more and more campuses are solving the technical and logistical problems and reporting positive outcomes. This session will feature representatives from three campuses where PKI has been successfully rolled out. They'll tell you how they did it.

View this resource:

Usability and User Education and Support

Added by the EDUCAUSE Librarian
Title:Usability and User Education and Support (ID: PKI08005)
Author(s):Brian Rust (University of Wisconsin-Madison) and James Lowe (University of Wisconsin-Madison)
Origin:Presented at PKI Meetings (04/16/2008)
Type:Presentations/Speeches
Abstract:

From digital signatures to encrypted VPN sessions, PKI can only be successful if the computing community understands how to use it effectively. Cultivating this understanding requires careful planning, training, and even some creative motivational strategies. In this session, representatives from our host campus will describe how they met this challenge.

View this resource:

CA Options: Buy or Build, and Signed by Whom?

Added by the EDUCAUSE Librarian
Title:CA Options: Buy or Build, and Signed by Whom? (ID: PKI08001)
Author(s):James A. Jokl (University of Virginia), Paul Caskey (University of Texas System), and Nicholas Davis (University of Wisconsin-Madison)
Origin:Presented at PKI Meetings (04/16/2008)
Type:Presentations/Speeches
Abstract:

One of the first decisions facing campuses that have decided to deploy a PKI is whether to build their PKI in house, with the necessary personnel and infrastructure it entails, or to buy their PKI from a vendor, which can have a seemingly high sticker price. What are the driving factors behind this decision? How do you accurately assess all costs, both short- and long-term? How do you measure the benefits/ROI of a given choice? What signing options should you consider? Come to this session to participate in a discussion with panelists who have made decisions in each of these directions.

View this resource:

Campus Applications 1: Network Authentication with PKI

Added by the EDUCAUSE Librarian
Title:Campus Applications 1: Network Authentication with PKI (ID: PKI0511)
Author(s):Robert J. Brentrup (Dartmouth College) and James A. Jokl (University of Virginia)
Origin:Presented at PKI Meetings (07/27/2005)
Type:Presentations/Speeches
Abstract:PKI enables strong authentication for wireless network users via 802.1x EAP/TLS and for VPN users via the PKI capabilities of standard IPSEC. Implementers of these practical and very secure solutions will explain how they deployed them.
View this resource:

Campus Applications 2: Web Application Authentication with PKI

Added by the EDUCAUSE Librarian
Title:Campus Applications 2: Web Application Authentication with PKI (ID: PKI0512)
Author(s):Mark Franklin (Dartmouth College) and William A. Weems (The University of Texas Health Science Center at Houston)
Origin:Presented at PKI Meetings (07/27/2005)
Type:Presentations/Speeches
Abstract:The popular Web server platforms implement client-side PKI authentication via SSL, and schools that have successfully implemented this strong authentication mechanism in various different ways will describe their solutions and lessons learned.
View this resource:

Campus PKI Audits Panel

Added by the EDUCAUSE Librarian
Title:Campus PKI Audits Panel (ID: PKI0513)
Author(s):Patrick Cain and Noel Nazario
Origin:Presented at PKI Meetings (07/27/2005)
Type:Presentations/Speeches
Abstract:A requirement for auditing is integral to all PKI deployments. This panel will discuss campus audit requirements and options, including the various types and frequency of audits, likely costs, and in-house versus external approaches.
View this resource:

Nuts and Bolts of PKI Files

Added by the EDUCAUSE Librarian
Title:Nuts and Bolts of PKI Files (ID: PKI0505)
Author(s):Eric J. Norman (University of Wisconsin-Madison)
Origin:Presented at PKI Meetings (07/26/2005)
Type:Presentations/Speeches
Abstract:This talk will explain what you really need to know about various PKI data formats such as DER, CER, PEM, P12, and so forth, as well as the tools to manipulate and convert them.
View this resource:

Interinstitutional Trust Fabric

Added by the EDUCAUSE Librarian
Title:Interinstitutional Trust Fabric (ID: PKI0506)
Author(s):Mark Franklin (Dartmouth College), John C.W. Krienke (Internet2), Scott A. Rea (Dartmouth College), Russel F. Weiser, and Steven L. Worona (EDUCAUSE)
Origin:Presented at PKI Meetings (07/26/2005)
Type:Presentations/Speeches
Abstract:This session describes the Higher Education Bridge Certification Authority (HEBCA) and the U.S. Higher Education Root (USHER) Certification Authority (CA) and how they enable verification and trust of credentials among higher education institutions and with government and industry institutions. It will also provide details about the Secure Access for Everyone (SAFE) bridge CA operated by our colleagues in the pharmaceutical industry.
View this resource:

Levels of Assurance (LOAs) and Their Relevance to PKI

Added by the EDUCAUSE Librarian
Title:Levels of Assurance (LOAs) and Their Relevance to PKI (ID: PKI0507)
Author(s):Peter Alterman and Nicholas F. Piazzola (VeriSign, Inc.)
Origin:Presented at PKI Meetings (07/26/2005)
Type:Presentations/Speeches
Abstract:The Federal PKI Bridge recognizes four levels of assurance based on NIST guidelines. Commercial PKI systems also support different trust levels, not necessarily identical to the NIST definitions. This panel will consider how levels of assurance impact campus PKI deployment, including inter-PKI bridging, buy/build issues, and general campus options.
View this resource:

EDUCAUSE Negotiated Vendor Programs

Added by the EDUCAUSE Librarian
Title:EDUCAUSE Negotiated Vendor Programs (ID: PKI0508)
Author(s):Mark A. Luker (EDUCAUSE) and Steven L. Worona (EDUCAUSE)
Origin:Presented at PKI Meetings (07/26/2005)
Type:Presentations/Speeches
Abstract:One of the most frequently cited impediments to deploying off-the-shelf PKI solutions is cost, which has traditionally been set by vendors with an eye to the commercial marketplace rather than higher education. For many months, EDUCAUSE has been negotiating with several vendors to provide special campus discounts on PKI services and related products, and this session will provide a status report on those negotiations.
View this resource: