Information resources on PKI and related issues 


Back to PKI page




Information pages about PKI and PKI related projects Internet2 PKI/Middleware Initiative

PKI: News from the Front and Views from the Back (PDF)

CREN Certification Authority

CSG Projects
          The Authentication Project
          Java Kerberos
          (see also http://security.dstc.edu.au/projects/java/jcsi.html for an alternative v5 implementation
          which also includes PKI-based security components)

Governmental Programmes

NIST PKI Program
NIST is currently concentrating on PKI architectures, security requirements for PKI components, and PKI-enabled applications. The PKI architecture work is divided between development of complex PKIs based on the bridge CA concept and theoretical modeling of PKI performance. The goal of NIST's security requirements work is a Common Criteria Protection Profile.
NIST is also pursuing XML digital signatures using PKI to verify the identity of the signer.

Federal Public Key Infrastructure
Access Certificates for Electronic Service (ACES) - ACES facilitates secure on-line access to Government information and services by the Public through the use of public key infrastructure/digital signature technology
Department of Justice Encryption Issues FAQ

Canadian Government Communications Security Establishment
GOC PKI Initiative

UK Government Communications-Electronics Security Group

ITU: X.509 (2000)



PKI related IETF WGs and some RFC's

Public-Key Infrastructure (X.509) (pkix)
http://www.ietf.org/html.charters/pkix-charter.html

Request For Comments (until 2001):

Internet X.509 Public Key Infrastructure Certificate and CRL Profile (RFC 2459)
Internet X.509 Public Key Infrastructure Certificate Management Protocols (RFC 2510)
Internet X.509 Certificate Request Message Format (RFC 2511)
Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework (RFC 2527)
Internet X.509 Public Key Infrastructure Representation of Key Exchange Algorithm (KEA) Keys in Internet X.509 Public Key Infrastructure Certificates (RFC 2528)
Internet X.509 Public Key Infrastructure Operational Protocols - LDAPv2 (RFC 2559)
Internet X.509 Public Key Infrastructure Operational Protocols: FTP and HTTP (RFC 2585)
Internet X.509 Public Key Infrastructure LDAPv2 Schema (RFC 2587)
X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP (RFC 2560)
Certificate Management Messages over CMS (RFC 2797)
Diffie-Hellman Proof-of-Possession Algorithms (RFC 2875)
Internet X.509 Public Key Infrastructure Data Validation and Certification Server Protocols (RFC 3029)
Internet X.509 Public Key Infrastructure Qualified Certificates Profile (RFC 3039)

SS/MIME Mail Security (smime)
http://www.ietf.org/html.charters/smime-charter.html

An Open Specification for Pretty Good Privacy (openpgp)
http://www.ietf.org/html.charters/openpgp-charter.html

Request For Comments (until 2001):

OpenPGP Message Format (RFC 2440)
 

XML Digital Signatures (xmldsig)
http://www.ietf.org/html.charters/xmldsig-charter.html

Request For Comments:

XML-Signature Syntax and Processing
Canonical XML Version 1.0
XML-Signature Requirements (RFC 2807)


Digital Signature

Information and documents related to the European Directive for Electronic Signatures




Legal issues

Forums and Mailing lists


Additional information

Information resources on LDAP and related issues


Updated