26
Communications-Electronic s Security Group

Communications-Electronics Security Group

  • Upload
    edison

  • View
    36

  • Download
    0

Embed Size (px)

DESCRIPTION

Communications-Electronics Security Group. PKI interoperability issues for UK Government … again. Richard Lampard [email protected]. … or, The triumphant return of Richard Lampard!. Richard Lampard [email protected]. - PowerPoint PPT Presentation

Citation preview

Page 1: Communications-Electronics Security Group

Communications-Electronics Security

Group

Page 2: Communications-Electronics Security Group

PKI interoperability issues for UK Government … again

Richard Lampard

[email protected]

Page 3: Communications-Electronics Security Group

… or,

The triumphant return of Richard Lampard!

Richard Lampard

[email protected]

Page 4: Communications-Electronics Security Group

… or,

Oh dear, Lisa must really be scraping the barrel.

Richard Lampard

[email protected]

Page 5: Communications-Electronics Security Group

Structure

1. Quick introduction

2. Why is interoperability crucial?

3. ALICE

4. Vendor interoperability trial

5. Summary

Page 6: Communications-Electronics Security Group

1. Quick introduction

• Communications-Electronics Security Group– a government agency– UK national Infosec authority– operates on a cost-recovery basis– aims to encourage adoption of PKI and related technologies by UK

government, the armed forces and wider public sector

Capitalising on the UK’s Sigint knowledge base, we will help to protect the nation’s security and safety, and deny foreign Sigint success

Page 7: Communications-Electronics Security Group

2. Why is interoperability crucial?

CA

CA

CA CA CA CA

CA CA

CA CA

CA

Repository

TSP

Page 8: Communications-Electronics Security Group

2. Why is interoperability crucial?

• Encoding– DER versus BER– GeneralizedTime vs UTCTime– DN ordering– Base 64 vs ASN.1– PrintableString vs TeletextString– RFC 822 address included in DN

Page 9: Communications-Electronics Security Group

2. Why is interoperability crucial?

• Implementation problems– misinterpretations of standards, crass mistakes,

incorrect assumptions, or “short cuts”

– ASN.1 compiler bugs– arbitrary or machine limitations e.g. serial number

length

– inability to deal with incorrect or unexpected behaviour e.g. bad certification requests

Page 10: Communications-Electronics Security Group

2. Why is interoperability crucial?

• Directories (gulp!)– inability to use same Directory– schema clashes

• Proprietary private key token formats

Page 11: Communications-Electronics Security Group

2. Why is interoperability crucial?

Client Client Client Client

CA

CA CA

Repository

Page 12: Communications-Electronics Security Group

2. Why is interoperability crucial?

Client Client Client Client

CA

CA CA

Repository

Page 13: Communications-Electronics Security Group

3. ALICE

• Test level of interoperability provided by national implementations of international and NATO standards

• Hence, reduce risk to national procurements and developments

Page 14: Communications-Electronics Security Group

3. ALICE

Page 15: Communications-Electronics Security Group

3. ALICE

STANAG 4406interoperability

Page 16: Communications-Electronics Security Group

3. ALICE

STANAG 4406PCT with basic

certificateexchange

Page 17: Communications-Electronics Security Group

3. ALICE

STANAG 4406S/MIME and basic

certificate exchange

Page 18: Communications-Electronics Security Group

3. ALICE

STANAG 4406S/MIME and full

PKI support

Page 19: Communications-Electronics Security Group

3. ALICE

SMTP S/MIME and fullPKI support

Page 20: Communications-Electronics Security Group

3. ALICE

Page 21: Communications-Electronics Security Group

4. Vendor interoperability trial

• Previous interoperability work attracted some criticism– we didn’t always have most up to date version or

based on beta code– not enough vendor involvement– test scenario did not present a level playing field

Page 22: Communications-Electronics Security Group

4. Vendor interoperability trial

Invite vendorsto participate

Agree scenario

Agree config- uration

Internet dry run

Assemble testbed

Bake-off

Open to HMG users!

Page 23: Communications-Electronics Security Group

4. Vendor interoperability trial

• Why are we doing this?– give vendors the chance to prove their claims

– … or enough rope to show otherwise

– provides an up to date view of interoperability for products out of the box

– shows CESG’s commitment to working with multiple vendors

– shows CESG’s departmental customers the state of play

– does anyone want to play?

Page 24: Communications-Electronics Security Group

5. Summary

• Lack of interoperability will still be a major problem for UK Government

• Key HMG efforts:– ALICE– vendor interoperability trial– and of course, participation in PKI Forum

Page 25: Communications-Electronics Security Group

5. Summary

PKI is done neither for personal acclaim (because the applications get all the glory), nor for financial gain (if you’re a civil servant).

Therefore, CESG PKI experts must be the purest form of security consultant.

Discuss.

Page 26: Communications-Electronics Security Group

Communications-Electronics Security

Group