【24h】

CA-in-a-Box

机译:盒装CA

获取原文
获取原文并翻译 | 示例

摘要

An enterprise (such as an institute of higher education) wishing to deploy a PKI must choose between several options, all expensive and awkward. It might outsource certification to a third-party company; it might purchase CA software and appliances from a third-party company; it might try to build and maintain its own CA. In the latter two options, the enterprise faces the additional challenge of showing sufficiently safe practices to have its CA certified or cross-certified, for broader inter-operability. This paper presents our research and development effort to address this problem. We use OpenCA to provide the basic functionality; we package it on a Linux installation on a bootable CD; we use the 1.1b TCG trusted platform module (standard on many desktop and laptop machines) to hold the private key; we also use the TPM to add assurance that the key can only be used when the system is correctly configured as the CA. This tool enables an enterprise to operate a CA possessing a degree of physical security and the ability to attest proper configuration to a remote certifier simply by booting a CD in a commodity machine. The code (and CD image) are all open-source, and will be available for free.
机译:希望部署PKI的企业(例如高等教育机构)必须在多种选择中选择,这些选择既昂贵又笨拙。它可能会将认证外包给第三方公司;它可能会从第三方公司购买CA软件和设备;它可能会尝试建立并维护自己的CA。在后两种选择中,企业面临另外的挑战,即显示足够的安全实践以使其CA认证或交叉认证,以实现更广泛的互操作性。本文介绍了我们为解决此问题而进行的研究和开发工作。我们使用OpenCA提供基本功能;我们将其打包在可引导CD上的Linux安装中;我们使用1.1b TCG可信平台模块(许多台式机和笔记本电脑的标准配置)来保存私钥;我们还使用TPM来确保只有在将系统正确配置为CA时才能使用该密钥。该工具使企业能够通过简单地通过在商用机器中引导CD来操作具有一定程度的物理安全性并能够向远程验证者证明正确配置的CA。该代码(和CD映像)都是开源的,将免费提供。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号