pki for dummies

18

Upload: alex-de-jong

Post on 05-Dec-2014

5.413 views

Category:

Documents


7 download

DESCRIPTION

Slidedeck used at the Dutch Techdays Event in 2012.

TRANSCRIPT

Page 1: Pki for dummies
Page 2: Pki for dummies

PKI for Dummies

Alex de JongMicrosoft Freelance

Page 3: Pki for dummies

Agenda• PKI Overview• Your own PKI

Page 4: Pki for dummies

Public Key Infrastructure (PKI) is a set of hardware, software, people, policies, and

procedures needed to create, manage, distribute, use, store, and revoke

digital certificates

Page 5: Pki for dummies

Subject Valid from/to

Issuer

Serial Number

Page 6: Pki for dummies

Certificate Extensions

• Subject, Serial Number, Issuer, Valid From, Valid To• Public Key• Subject Alternative Names (SANs)• Authority Information Access (AIA)• Certificate Revocation Lists (CRLs)• Enhanced Key Usage

Page 7: Pki for dummies

Authentication Encryption

Authenticity

Page 8: Pki for dummies

3 Encryption “methods”• Symmetric

– 1 encryption key for encryption and decryption• Asymmetric

– 2 keys encryption keys: Public & Private• Hashing

– Used for Authenticity checking, passwords– Irreversible

Page 9: Pki for dummies

Authenticity• Digitally Signed Data– e-mail, documents, this PowerPoint

Page 10: Pki for dummies

About the Issuer

Page 11: Pki for dummies

DEMOPublic CA’s

Page 12: Pki for dummies

Building one of your 0wn3d• Stand alone vs. Enterprise• Design Considerations• Certificate Revocation Lists (CRL’s)

Page 13: Pki for dummies

Building one of your 0wn3d• Certificate Templates• Web Services• …

Page 14: Pki for dummies

DEMOPrivate CA’s

Page 15: Pki for dummies

Enrolling certificates• Web Services• Auto Enrollment• MMC Snap-in

Page 16: Pki for dummies

From the client side• Managing your own certificates• Checking the others

Page 17: Pki for dummies

DEMOManaging Certificates

Page 18: Pki for dummies