7-Jan-04Paul Hill1 MIT’s use of Public Key Technologies Support issues.

10
7-Jan-04 Paul Hill 1 MIT’s use of Public Key Technologies Support issues

Transcript of 7-Jan-04Paul Hill1 MIT’s use of Public Key Technologies Support issues.

Page 1: 7-Jan-04Paul Hill1 MIT’s use of Public Key Technologies Support issues.

7-Jan-04 Paul Hill 1

MIT’s use of Public Key Technologies

Support issues

Page 2: 7-Jan-04Paul Hill1 MIT’s use of Public Key Technologies Support issues.

7-Jan-04 Paul Hill 2

Topics

• Use of certificates at MIT– Where we use them– Where we don’t use them

• Some casetracker data

Page 3: 7-Jan-04Paul Hill1 MIT’s use of Public Key Technologies Support issues.

7-Jan-04 Paul Hill 3

Authenticating Servers

• IS&T centrally operated and maintained servers

• eCommerce

• Departments, Labs, and Centers

• Student owned machines

• Apache and IIS

Page 4: 7-Jan-04Paul Hill1 MIT’s use of Public Key Technologies Support issues.

7-Jan-04 Paul Hill 4

Services that use client certificates for authentication

• Central web server (optional), provides access to:– AFS (hence any static file that the content provider

chooses to make available) – Software distribution

• Financial system (MIT SAPWeb, ITS)• TechTime• Event Calendar providers• Casetracker• Moira, Active Directory, Data Warehouse, Roles

Page 5: 7-Jan-04Paul Hill1 MIT’s use of Public Key Technologies Support issues.

7-Jan-04 Paul Hill 5

Services continued

• Online purchasing– BOC gases– Dell Computer– DHL– GovConnection (computers, software, supplies)– Apple– Grainger– Minuteman Press (MIT stationary and business cards)– Office Depot– VWR International

Page 6: 7-Jan-04Paul Hill1 MIT’s use of Public Key Technologies Support issues.

7-Jan-04 Paul Hill 6

IS&T Services that prompt for username/password

• The CA server (bootstrap issue, necessary to obtain your certificate)

• Student DHCP registration (another bootstrap issue)

• Webmail (multi-tier issue)

• TechTime (also supports certificates)

• Mailman list administration

• VPN authentication

Page 7: 7-Jan-04Paul Hill1 MIT’s use of Public Key Technologies Support issues.

7-Jan-04 Paul Hill 7

UI Issues, obtaining a certificate

1) Find the “obtain a certificate page”

2) Fill out the form

3) Click next

4) Click OK

5) Click OK

6) Click Yes

7) Go on with your work

Page 8: 7-Jan-04Paul Hill1 MIT’s use of Public Key Technologies Support issues.

7-Jan-04 Paul Hill 8

How widely used is this really?

• The number of hits on the ‘certificate’ related pages:– Total 2002 = 252,043– Total 2003 = 233,434– August 2002 = 33,813– September 2002 = 37,966– August 2003 = 37,034– September 2003 = 22,813

Page 9: 7-Jan-04Paul Hill1 MIT’s use of Public Key Technologies Support issues.

7-Jan-04 Paul Hill 9

What happens when certificates expire?

• Casetracker Help Desk dataYear Total cases related to certificates– 1997 13– 1998 60– 1999 204– 2000 208– 2001 241– 2002 279– 2003 211

Page 10: 7-Jan-04Paul Hill1 MIT’s use of Public Key Technologies Support issues.

7-Jan-04 Paul Hill 10

Casetracker: Business Liaison Team

• Year Total cases

2001 348

2002 329

2003 309