Internet2
Site Index |
Membership | Communities | Network | NET+ | Research | Events | News | About
 | Internet2 Home > Middleware

Middleware

>Home
>Middleware
   Overview
(PDF)
>Mailing Lists


Higher Education PKI
Technical Activities Group
(HEPKI-TAG)

A Joint Project of Internet2, EDUCAUSE, and Net@EDU

 

Mailing List || Completed Projects || Work in Progress || References || Minutes

PKI Early Adopters' Initiative: Call for Proposals (PDF)

Charter

HEPKI-TAG was created to investigate technical issues related to the deployment of Public Key Infrastructure in Higher Education. Some of the suggested topics include:
  • Open Source CA software
  • Interactions with directories
  • Client customization issues
  • Validity periods
  • Technical issues in cross-certification
  • Inter-institutional testbeds
  • Recommendations for higher education PKI deployments

NOTE WELL: All Internet2 Activities are governed by the Internet2 Intellectual Property Framework.


Working Group Chair
Jim Jokl, University of Virginia
Working Group Flywheel
Steve Olshansky, Internet2

Mailing List

To subscribe to the HEPKI-TAG mailing list, send email to pubsympa at internet2 dot edu, with the *subject line*:

subscribe <list name> <your name>
For example:

subscribe hepki-tag Jane Doe

To unsubscribe, send email to pubsympa at internet2 dot edu, with the *subject line*:

unsubscribe hepki-tag

Completed Projects

For more information on the status of these documents, see the Internet2 Document Guidelines. For reference see also the Internet2 Document Library.

  • Certificate Profile Maker (CPM) 1.1 (Part of NSF Middleware Initiative - NMI)
    CGI-program package for making a certificate profile in XML format. It simultaneously produces a sample X.509 certificate in XML format according to the certificate profile. CPM supports almost all of the standard extensions defined in RFC2459. Additional information about the Certificate Profile Maker is available in the README file. [Description || Service || Download]

  • Two mechanisms for installing a root certificate into Internet Explorer
    Schools planning to issue SSL server certificates as part of their PKI project may want to read this section on alternatives for the installation of campus root certificates into Internet Explorer. The less frequently used mechanism is likely to be the process that is easiest for your users to complete successfully. We use the CREN root certificate for the download demo and provide the code that implements the less frequently used mechanism.
  • PKI-Lite Campus Public Key Infrastructure Framework (Part of NSF Middleware Initiative - NMI)
    PKI-Lite focuses on employing PKI technology for standard assurance applications that already have established and implemented requirements for initial user authentication and overall system security. The idea behind the PKI-lite effort is that one of the barriers to the more rapid deployment of PKI on many campuses is likely to be the relatively intense policy, user identity verification, and practices frameworks that are typically associated with PKI deployments. PKI-lite recognizes that many useful applications can be supported using a Public Key Infrastructure that is based on a relatively brief policy and practices framework that emulates the mechanisms presently used on-campus to operate most existing campus central authentication services. The PKI-Lite framework facilitates the use of strong cryptography within a school's traditional authentication practices environment and assurance levels.

    The certificate profiles listed below were developed as part of the PKI-Lite effort. They have been designed to support a wide range of likely PKI-enabled campus applications and have been reviewed by several schools who have implemented campus PKI systems. By using these profiles and following the recommendations for PKI imlementors at the bottom of the documents, you will minimize the chance of running into interoperability problems with your deployment. These certificate profiles, updated with any local campus changes, should be incorporated into Section III of your PKI-Lite Policy and Practices document.

    See the PKI-Lite section below under Work In Progress for the draft PKI-Lite Implementation Recipe for additional helpful information.

    Also look in the References section below for pointers to open source Certificate Authority software.

Work in Progress

  • InCommon and Usher Certification Authority Draft Profiles
  • CA Private Key Protection
    A starting draft on CA Private Key Protection by Jeff Schiller at MIT.

  • Demonstration CA
    A demonstration CA issuing HEPKI certificates for testing and demonstration purposes by Eric Norman at Wisconsin. Eric has recently made the source code available for this CA. This CA is designed for demonstration purposes and isn't necessarily something that you should plan to download and install for a campus CA.

  • PKI-Lite Work in Progress
  • S/MIME Activities
  • PKI Bridge Trust Models and Windows XP
    • PKI Bridge Test Environment
      A test environment consisting of three hierarchical CAs, a bridge CA, a cross certificate repository (HTTP and LDAP), and test certificates from the various CAs with differing Authority Access Information profiles to test the various possible configurations. All certs and cross certs are available for download and further testing.

References: HEPKI-TAG Recommendations and Documents
TAG Recommendations

  • DC Naming

  • Certificate Profile Recommendations
    Work is presently in progress to develop a set of recommended profiles for identity certificates used in higher education. A collection of certificate profiles from various institutions is available here.

  • Browser Issues
    A document describing various credential management issues in current browsers with recommendations for browser implementors. A great reference for campus PKI developers.

Information and Suggestions for Institutional PKI Implementors

Some Recommended PKI and Related Reference Documents

Minutes of HEPKI-TAG Conference Calls

2006 2006 2007

 

2003 2004 2005
2000 2001 2002

© 1996 - 2010 Internet2 - All rights reserved | Terms of Use | Privacy | Contact Us
1000 Oakbrook Drive, Suite 300, Ann Arbor MI 48104 | Phone: +1-734-913-4250