Huh? PKI is relatively simple technology. Usually both parties need to trust a 
mutual third party (a CA). A similar concept to Kerberos or even AD in general 
(both clients and servers trust DCs)

The tricky part about PKI is all the processes you have around managing your 
CA, key escrow etc. What is the actual issue you are facing?

Cheers
Ken

-----Original Message-----
From: Maglinger, Paul [mailto:pmaglin...@scvl.com] 
Sent: Friday, 21 August 2009 10:12 PM
To: NT System Admin Issues
Subject: Still struggling with iPhone, ISA and SSL certs...

As the Security Admin and I are still trying to get the 
hell-spawned-demonic-iPhone-from-the-putrid-cesspool-of-caustic-industri
al-waste-products to work through our ISA, we referred back to the ISA
2006 Migration Guide by Syngress.  The SA came in the morning and showed me the 
following section in the book:
 
"The topic of Certificate Authorities (CAs)and PKI (Public Key
Infrastructure) is usually enough to drive many administrators away from even 
considering SSL.  There are a number of reasons for this:
 - The available documentation on certificate authorities and PKI, in general, 
is difficult to understand.
 - The subject has the potential to be extremely complex.
 - You need to learn an entirely new vocabulary to understand the CAs and PKI.  
Often the documentation on these subjects doesn't define the new words, or they 
use equally arcane terms to define the arcane term for which you're trying to 
get the definition.
 - There doesn't seem to be any support for the network and firewall 
administrator who just wants to get a CA setup and running so that he can use 
certificates for SSL and L2TP/IPSec authentication and encryption."


Boy, that just seems to sew it up in a nutshell, doesn't it?  You'd think that 
if this opinion is as common as I believe it to be, somebody out there could 
simplify the process somewhat...

*thunk* *thunk* *thunk*  (head banging against desk...)


~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to