Higher
Education PKI
Technical Activities
Group
(HEPKI-TAG)
A
Joint Project
of Internet2,
EDUCAUSE, and
Net@EDU |
|
Mailing List
|| Completed Projects
|| Work in Progress
|| References
|| Minutes
PKI
Early Adopters' Initiative:
Call
for Proposals
(PDF)
Charter
HEPKI-TAG was created
to investigate technical
issues related to the
deployment of Public
Key Infrastructure in
Higher Education. Some
of the suggested topics
include:
- Open Source CA
software
- Interactions with
directories
- Client customization
issues
- Validity periods
- Technical issues
in cross-certification
- Inter-institutional
testbeds
- Recommendations
for higher education
PKI deployments
NOTE WELL:
All Internet2 Activities
are governed by the
Internet2
Intellectual Property
Framework.
Mailing
List
To subscribe to the
HEPKI-TAG mailing
list, send email to
pubsympa at internet2 dot edu,
with the *subject
line*:
subscribe
<list name>
<your name>
For example:
subscribe
hepki-tag Jane Doe
To unsubscribe, send
email to pubsympa at internet2 dot edu,
with the *subject
line*:
unsubscribe
hepki-tag
Completed
Projects
For
more information on
the status of these
documents, see the
Internet2
Document Guidelines.
For reference see
also the Internet2
Document Library.
- Certificate Profile
Maker (CPM) 1.1
(Part of NSF
Middleware Initiative
- NMI)
CGI-program package
for making a certificate
profile in XML format.
It simultaneously
produces a sample
X.509 certificate
in XML format according
to the certificate
profile. CPM supports
almost all of the
standard extensions
defined in RFC2459.
Additional information
about the Certificate
Profile Maker is
available in the
README
file. [Description
|| Service
|| Download]
- Two
mechanisms for installing
a root certificate
into Internet Explorer
Schools planning
to issue SSL server
certificates as
part of their PKI
project may want
to read this section
on alternatives
for the installation
of campus root certificates
into Internet Explorer.
The less frequently
used mechanism is
likely to be the
process that is
easiest for your
users to complete
successfully. We
use the CREN root
certificate for
the download demo
and provide the
code that implements
the less frequently
used mechanism.
Work
in Progress
- InCommon and Usher
Certification Authority
Draft Profiles
- CA
Private Key Protection
A starting draft
on CA Private Key
Protection by Jeff
Schiller at MIT.
- Demonstration
CA
A demonstration
CA issuing HEPKI
certificates for
testing and demonstration
purposes by Eric
Norman at Wisconsin.
Eric has recently
made the source
code available
for this CA. This
CA is designed for
demonstration purposes
and isn't necessarily
something that you
should plan to download
and install for
a campus CA.
- PKI-Lite
Work in Progress
- S/MIME
Activities
- PKI-lite Inter-institutional
S/MIME
Test Project
- A
wish list of S/MIME
functionality
for Outlook and
Outlook Express
- Mailing List
Software
Some experiments
with various email
list processing
software has found
that some software
modifies the message
body and thus
causes signature
verification failures.
Suspected problems
include the accidental
removal of trailing
spaces and tabs.
Known to work:
- Listproc
with all email
clients except
Eudora with
the Tumbleweed
plugin.
Testing in progress:
- PKI Bridge Trust
Models and Windows
XP
- PKI
Bridge Test
Environment
A test environment
consisting of
three hierarchical
CAs, a bridge
CA, a cross
certificate
repository (HTTP
and LDAP), and
test certificates
from the various
CAs with differing
Authority Access
Information
profiles to
test the various
possible configurations.
All certs and
cross certs
are available
for download
and further
testing.
References:
HEPKI-TAG Recommendations
and Documents
TAG Recommendations
- DC
Naming
- Certificate Profile
Recommendations
Work is presently
in progress to develop
a set of recommended
profiles for identity
certificates used
in higher education.
A collection of
certificate profiles
from various institutions
is available here.
- Browser
Issues
A document describing
various credential
management issues
in current browsers
with recommendations
for browser implementors.
A great reference
for campus PKI developers.
Information
and Suggestions for
Institutional PKI
Implementors
Some Recommended
PKI and Related Reference
Documents
Minutes
of HEPKI-TAG Conference
Calls
2003
- December
17, 2003
- December
3, 2003
- November
19, 2003
- November
5, 2003
- October
22, 2003
- October
14, 2003
(Fall Member Meeting)
- October
8, 2003
- September
10, 2003
- August
27, 2003
- August
13, 2003
- July
30, 2003
- July
16, 2003
- July
2, 2003
- June
18, 2003
- June
4, 2003
- May
22, 2003
- May
7, 2003
- April
23, 2003
- March
26, 2003
- March
12, 2003
- February
26, 2003
- February
12, 2003
- January
29, 2003
|
2004
- November
17, 2004
- November
3, 2004
- September
27, 2004
(Fall Member
Meeting)
- September
22, 2004
- September
8, 2004
- August
25, 2004
- July
28, 2004
- June
2, 2004
- May
19, 2004
- April
19, 2004
(Fall Member
Meeting)
- April
7, 2004
- February
25, 2004
- February
11, 2004
- January
28, 2004
|
2005
- November 30, 2005
- November 2, 2005
- October 19, 2005
- October 5, 2005
- September 19, 2005
(Fall Member Meeting)
- August 24, 2005
- August 10, 2005
- June 29, 2005
- June 1, 2005
- May
18, 2005
- May
2, 2005
- April
6, 2005
- March
23, 2005
- March
9, 2005
- February
23, 2005
- February
9, 2005
- January
26, 2005
- January
12, 2005
|
2000
- December
20, 2000
- December
6, 2000
- November
22, 2000
- November
8, 2000
- October
25, 2000
- October
11, 2000
- September
27, 2000
- September
13, 2000
- August
30, 2000
- August
16, 2000
- August
2, 2000
- July
19, 2000
- July
5, 2000
- June
21, 2000
- June
6, 2000
- May
23, 2000
|
2001
- December
19, 2001
- December
5, 2001
- November
21, 2001
- November
7, 2001
- October
24, 2001
- October
10, 2001
- September
26, 2001
- August
15, 2001
- August
1, 2001
- July
18, 2001
- June
20, 2001
- June
6, 2001
- May
23, 2001
- April
25, 2001
- April
11, 2001
- March
28, 2001
- March
14, 2001
- February
14, 2001
- January
31, 2001
- January
17, 2001
- January
3, 2001
|
2002
- December
18, 2002
- November
20, 2002
- November
6, 2002
- October
23, 2002
- October
9, 2002
- September
25, 2002
- September
11, 2002
- August
28, 2002
- August
14, 2002
- July
17, 2002
- July,
3 2002
- June
19, 2002
- June
5, 2002
- May
22, 2002
- March
27, 2002
- March
13, 2002
- February
27, 2002
- February
13, 2002
- January
16, 2002
- January
2, 2002
|
|