Disclaimer
Contents:
We are struggling to rollout some system testing even while serious problems are still being investigated. The initial rollout should be thought of as a Limited Production System (LPS). LPS certainly won't meet all of everyone's needs and serious compromises may need to be made as pieces do or don't all into place! These efforts and targets are relevant:
We envision a hierarchy (schematically):
A draft policy exists.
It includes a
certificate payload
Currenty, work is going into:
Everyone needs to realize that LPS will NOT meet all
authentication/authorization needs.
Among the important items probably not supported:
At the moment, this is an unsorted laundry list.
AWG#2 is working on some of them:
Send your questions, comments, and suggestions to
IR&C
LPS Components Being Pursued at UCOP
UCOP is actively working on three infrastructure components:
In addition, two applications are being "certified":
A major project to provide a directory which (eventually) lists
every person ever associated with UC.
A "Day 1" UDIR has been designed
with the limited
objective of making NetID's for (most) employees
available.
A strategy/schedule for students is being devised.
More UDir details.
The PKI will issue/manage UCCerts for people and applications.
Technology/vendor for the LPS is
Netscape (which is free) for the initial rollout.
If campuses intend to use a different technology/vendor,
we should be careful to check interoperation.
Longer-term, UCOP is assembling a
list of requirements/desiderata.
This might lead to an RFI/RFP for future technology/vendor.
|--campus1CA
|
|--campus2CA---|--subsidiaryCA1?
| |
|--... |--etc...
RootCA.ucal.edu ---|
|--campus9CA
|
|--ucopCA
|
|--(possibly labCA's eventually...)
Note - one main CA per campus!
We expect campuses to certify subsidiary CA's, but policy
needs to be developed.
We are working on certifying RootCA.ucal.edu with
some outside authority (so that users don't get
"do you trust this certificate"
warnings from their browser),
but may not succeed.
Functional Specification for UCCAP Attribute Server
and Attribute Query Protocol - a draft spec for review -
and
The Limited Production System:
Authentication and Authorization
Employeed self-service is a major project
and will go on over a long period of time.
See
ESTF Report
Short-term, a web package
(
Online Enrollment)
which new employees
can use to specify their benefits package using the web
has been selected to be "certified" and it has been in production
since Sept 1998.
Schedule, Work in Progress
Past accomplishments:
see
University Directory Data Element Documents for details.
Functional Specification for UCCAP Attribute Server
and Attribute Query Protocol - a draft spec for review -
and
The Limited Production System:
Authentication and Authorization
Caveats
signed, encrypted email
signed web pages
signed java applets
wide distribution of certs
legacy apps (all non-web apps?)
portability?
the workstation problem
external services (Britannica)
key archival/recovery/escrow
workflow
non-repudiation
privacy, anonymous transactions, ...
attribute certs
role-based authentication
distributed authorization (meta-directories, etc)
fine-grained authorization (by course enrollment)
commerce, money xfer (charge by the drink), ...
Yes, we all want these some day, and we hope not to preclude them
with anything done with LPS, just don't expect the moon from LPS.
Assumptions
Issues, Open Problems, Random Questions
$one-million/year @ UMinn? (rumor 9.1M)
Maybe those aren't accurate, but we could be talking
about real money...
$59/seat (Entrust)
$100/seat (Gartner)
Miscellaneous Resources
[UCCAP Home]
[UCCAP References]
[UCCAP Acronyms, Glossary]
Last updated November 4, 1999