Coder Social home page Coder Social logo

Comments (6)

lachellel avatar lachellel commented on July 21, 2024

Scope?

  • Is there an existing guide this is intended to replace, or
  • Is this specific to Non-Person / Device certificates issued from Agency internal certificate authorities
    • Less than medium hardware assurance certificates from an agency internal CA
    • No cross-boundary trust
  • Will this include setup procedures and types of certificate profiles generally needed for devices and network security

from fpki-guides.

MattKing1 avatar MattKing1 commented on July 21, 2024

Answers to LaChelle's questions:

  1. No. There is no existing guide
  2. No. This should be focused on guidance for device certificates issued under the FBCA or Common Device policy OIDs
  3. I don't think we can include that level of detail, but perhaps we should discuss so I can get a better idea of your intent, since we may be able to provide some high level of direction.

from fpki-guides.

dasgituser avatar dasgituser commented on July 21, 2024

Assigned to John Killian

from fpki-guides.

lachellel avatar lachellel commented on July 21, 2024

BTW - this doc is on idmanagement

I think it's OBE and would like to archive or repurpose any items as needed.

from fpki-guides.

weirdscience avatar weirdscience commented on July 21, 2024

Comments from duplicate issue.

Some guidance here: https://https.cio.gov/certificates/ Though it touches on some topics beyond best practices for device certificates.

There are two different use cases:

  1. Public Trust SSL
  2. Network (intranet) devices which include many more endpoints and non-http protocols and devices
    So you're right eric - we should link to the https.cio.gov site for the web pki best practices as this also includes configuration best practices. For internal only locally trusted CAs, the only playbook we've put together is reusing one from DHS (that I send out / not posted) and a very short writeup for setting up a CA for domain controller certs (network auth).

Sounds like creating a page with pointers to where can get guidance or profile for device certs such as M-15-13, NIST 800-52, HTTPS CIO Memo and maybe NCCOE TLS project.

from fpki-guides.

idmken avatar idmken commented on July 21, 2024

This document is deprecated.

from fpki-guides.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.