Educause Security Discussion mailing list archives
Re: Time and labor commitment to stand up a PKI
From: "Gioia, Matthew P." <MGioia () STLCC EDU>
Date: Wed, 13 Jun 2012 14:11:59 -0500
Gary, 1)It is a significant learning curve up front. We assembled a group, read the book (the one Brian referenced is very good), developed documentation and design, then ended up needing to scrap it all after going over our design with Microsoft. If you have any kind of Premier agreement, or can afford to dedicate some resources for consulting for this I highly recommend it. 2)Once we had everything figured out, implementation was a snap. It took 2 days. Personnel commitments are fairly small - we had 2 people do the implementation. 3)Ongoing maintenance isn't much - there's the need to generate new certificate templates infrequently, sometimes manage permissions on certificate templates, then periodically updating the CRL manually (if you're using an offline root CA). Our process went a little like this (which was the most creative way I could think of to best spend the training/consulting money that we had available): PKI Homework Develop Policy and Procedures Create Policy, Procedure and Design on our own Bring in MS to tear our policies, procedures and design to shreds and make recommendations (a fantastic learning experience). Redesign & Get MS to sign off on the design (this and the previous step were all done as part of the same 1 week consultation with MS) Implement Bring in MS to do a PKI Health check following implementation. It took about 8 months to complete the project, but it was almost entirely in getting the policy, procedures and design right. Implementation and review took about a week total. From my understanding, that's how it should be. The policy and procedure can make or break an implementation. If you get it wrong at the start, you're likely going to need to rip it out and start over. If you can get him, I highly recommend Amer Kamal from MS - the guy really knows his stuff and has authored several articles on the MS PKI technet blog. We ended up with a very simple design. If you would like to see any of our CPS, Policy, etc, shoot me a message off-list. Matthew Gioia Network Security Analyst St. Louis Community College -----Original Message----- From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Gary Flynn Sent: Wednesday, June 13, 2012 1:03 PM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: [SECURITY] Time and labor commitment to stand up a PKI Hi, We've gone without a PKI a long time because every use case that came up couldn't justify the outlay to stand up a PKI and alternatives were always found. Sometimes the concern over the operational costs and risks associated with failures overrode the perceived benefits. We're using Incommon for server certificates and plan to use them for user and code signing certificates. EFS certificates for the few places we implemented it were created on an ad-hoc basis and manually backed up. Once again, a use case has come up causing us to revisit the decision for a campus PKI. This time to support management of off-campus Windows computers through Microsoft's Direct Access feature. We currently manage almost all on-campus JMU owned Windows computers using SCCM/SUP and Secunia and would like to extend that to JMU owned computers off-campus. Given the Incommon services, I don't see a huge need for something on campus other than to handle machine certificates (for Direct Access and IPSEC) and possibly to help distribute Incommon user certificates. EFS and Bitlocker key management may enter the picture too but they're not strategic encryption options at this point. But maybe I'm missing something. I'd like to get a feel from those of you who have gone through this process of the time and labor commitments necessary to: 1) Get up to speed on the intricacies of implementing and operating a PKI. Frankly, I find it daunting. Sure, we could copy others' CPS, bring one up, and have it operating fairly quickly. But the complexities of merging technologies with business policies in things like certificate contents and practices statements and the somewhat questionable compatibility and finish of various "standards" and products concerns me. I'm very worried about what we don't know and I want to make sure we do it right the first time. 2) Actual implementation time and personnel commitments. 3) Ongoing operating, maintenance, and support time and costs. I'd also like to ask if you know of a consultant who has actually gone through this process in a higher education environment who helped you set up something that lasted through subsequent changes in use cases, policies, integrations, and product changes and that you'd recommend to others. We'd probably be implementing using the Microsoft Certificate Services product due to pricing and compatibility with the perceived primary use cases. Thanks in advance for any advice. -- Gary Flynn Security Engineer James Madison University
Current thread:
- Time and labor commitment to stand up a PKI Gary Flynn (Jun 13)
- Re: Time and labor commitment to stand up a PKI Brian Desmond (Jun 13)
- Re: Time and labor commitment to stand up a PKI Gioia, Matthew P. (Jun 13)
