scep

8
SCEP Simple Certificate Enrollment Protocol

Upload: onslow

Post on 06-Jan-2016

84 views

Category:

Documents


0 download

DESCRIPTION

SCEP. Simple Certificate Enrollment Protocol. Widely Deployed. Cisco routers, VPN client, and CA Microsoft CA Entrust CA RSA toolkit and CA Netscape CA Verisign CA Baltimore/Unicert. Features. Initial Enrollment Renewal (including client key rollover) - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: SCEP

SCEPSimple Certificate Enrollment Protocol

Page 2: SCEP

Widely DeployedCisco routers, VPN client, and CA

Microsoft CA

Entrust CA

RSA toolkit and CA

Netscape CA

Verisign CA

Baltimore/Unicert

Page 3: SCEP

Features

Initial Enrollment

Renewal (including client key rollover)

CA and Client Certificate retrieval

CA key and certificate rollover

Extensible

Page 4: SCEP

Mature Protocol

Has Been in use for over 7 years

many interoperable implementations

Now on draft 15

Page 5: SCEP

Enrollment

PKCS-10 to specify what should be in the cert

Signed and Encrypted with PKCS-7

Can Use One-Time Password for authentication

Page 6: SCEP

Renewal

Signed by prior client certificate

Page 7: SCEP

CA Key Rollover

“Next” CA Certificate generated ahead of time

Clients Can Retrieve “Next” CA Certificate

Response is signed by current CA certificate

Roll Over when Old Certificate Expires

Can roll over “early” if Root CA compromised

Page 8: SCEP

Current draft

draft-nourse-scep-15.txt

Informational

[email protected]