Top Banner
18

Pki for dummies

Dec 05, 2014

Download

Documents

Alex de Jong

Slidedeck used at the Dutch Techdays Event in 2012.
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Pki for dummies
Page 2: Pki for dummies

PKI for Dummies

Alex de JongMicrosoft Freelance

Page 3: Pki for dummies

Agenda• PKI Overview• Your own PKI

Page 4: Pki for dummies

Public Key Infrastructure (PKI) is a set of hardware, software, people, policies, and

procedures needed to create, manage, distribute, use, store, and revoke

digital certificates

Page 5: Pki for dummies

Subject Valid from/to

Issuer

Serial Number

Page 6: Pki for dummies

Certificate Extensions

• Subject, Serial Number, Issuer, Valid From, Valid To• Public Key• Subject Alternative Names (SANs)• Authority Information Access (AIA)• Certificate Revocation Lists (CRLs)• Enhanced Key Usage

Page 7: Pki for dummies

Authentication Encryption

Authenticity

Page 8: Pki for dummies

3 Encryption “methods”• Symmetric

– 1 encryption key for encryption and decryption• Asymmetric

– 2 keys encryption keys: Public & Private• Hashing

– Used for Authenticity checking, passwords– Irreversible

Page 9: Pki for dummies

Authenticity• Digitally Signed Data– e-mail, documents, this PowerPoint

Page 10: Pki for dummies

About the Issuer

Page 11: Pki for dummies

DEMOPublic CA’s

Page 12: Pki for dummies

Building one of your 0wn3d• Stand alone vs. Enterprise• Design Considerations• Certificate Revocation Lists (CRL’s)

Page 13: Pki for dummies

Building one of your 0wn3d• Certificate Templates• Web Services• …

Page 14: Pki for dummies

DEMOPrivate CA’s

Page 15: Pki for dummies

Enrolling certificates• Web Services• Auto Enrollment• MMC Snap-in

Page 16: Pki for dummies

From the client side• Managing your own certificates• Checking the others

Page 17: Pki for dummies

DEMOManaging Certificates

Page 18: Pki for dummies