You might be ready to embark down the PKI path if several of the following conditions are true:
You''ve migrated your application interfaces to Web browser technology, including the access to mainframe and midrange system applications. This is a requirement to permit the use of directory services, like LDAP, to enable a single sign-on capability that not only identifies the requester, but also determines their rights and provides for access control.
You''re migrated to browser based e-mail systems that support S/MIME and digital signing of messages.
You''ve migrated to application software that can deal with signed documents and messages to eliminate the routing of paperwork for authority determination purposes.
You''re prepared for logical access controls via SmartCards or token devices (see SmartCards For Smarter E-commerce) that store private keys and digital certificates.
Build or Buy?
As you see from the PKI dissection, developing one is far from trivial. More than a few companies have tried to build one on their own only to discover that trust is tenuous without the ultimate protection of CA private keys. Many have turned to outside firms who specialize in offering CA services to corporations around the world. In the next installment, we''ll look at some of these companies, what you may expect from them, and what they''ll expect from you.
Add ecommerce-guide.com to your favorites Add ecommerce-guide.com to your browser search box IE 7 | Firefox 2.0 | Firefox 1.5.xReceive news via our XML/RSS feed