Secure Messaging Challenge Technical Demonstration



Similar documents
Exostar LDAP Proxy / Secure Setup Guide. This document provides information on the following topics:

AT&T Global Network Client for Windows Product Support Matrix January 29, 2015

COMPARISON OF FIXED & VARIABLE RATES (25 YEARS) CHARTERED BANK ADMINISTERED INTEREST RATES - PRIME BUSINESS*

COMPARISON OF FIXED & VARIABLE RATES (25 YEARS) CHARTERED BANK ADMINISTERED INTEREST RATES - PRIME BUSINESS*

Analysis One Code Desc. Transaction Amount. Fiscal Period

Installing your Digital Certificate & Using on MS Out Look 2007.

ACTIVE MICROSOFT CERTIFICATIONS:

Case 2:08-cv ABC-E Document 1-4 Filed 04/15/2008 Page 1 of 138. Exhibit 8

Enhanced Vessel Traffic Management System Booking Slots Available and Vessels Booked per Day From 12-JAN-2016 To 30-JUN-2017

The GlobalCerts TM Secur Gateway TM

Spine Warranted Environment Specification

GlobalSign Enterprise Solutions

How To Get A Certificate From Ms.Net For A Server Server

ACTIVE MICROSOFT CERTIFICATIONS:

ACTIVE MICROSOFT CERTIFICATIONS:

AgriLife Information Technology IT General Session January 2010

2014 IBM Corporation


encryption with business partners

CENTERPOINT ENERGY TEXARKANA SERVICE AREA GAS SUPPLY RATE (GSR) JULY Small Commercial Service (SCS-1) GSR

Security Policy Revision Date: 23 April 2009

Carillon eshop User s Guide

Centers for Disease Control and Prevention, Public Health Information Network Messaging System (PHINMS)

Deploying Microsoft Windows Rights Management Services

PTC Creo 2.0 Hardware Support Dell

SAP NetWeaver Identity Management Experiences from an Implementation at Colgate-Palmolive Company

Configure SecureZIP for Windows for Entrust Entelligence Security Provider 7.x for Windows

Quickstream Connectivity Options

EMC Software Release and Service Dates for NetWorker and NetWorker Modules Last Updated on August 16, 2012

Ashley Institute of Training Schedule of VET Tuition Fees 2015

PrivaSphere Gateway Certificate Authority (GW CA)

Client side. DESlock + Data Encryption

BlackBerry Enterprise Server for Microsoft Exchange Version: 5.0 Service Pack: 2. Feature and Technical Overview

5053A: Designing a Messaging Infrastructure Using Microsoft Exchange Server 2007

Department of Defense SHA-256 Migration Overview

Trends in Global Capacity Availability and Trading. Bruce Girdlestone VP Network Trading Band-X

EMC Software Release and Service Dates for NetWorker and NetWorker Modules Last Updated on February 21, 2013

Council, 6 February IT Report. Executive summary and recommendations. Introduction

MS Configuring, Managing and Troubleshooting Microsoft Exchange Server 2010

Access to Front Office services

Implementing a Desktop Infrastructure

How to use Certificate in Microsoft Outlook

Deep Security Vulnerability Protection Summary

S/MIME on Good for Enterprise MS Online Certificate Status Protocol. Installation and Configuration Notes. Updated: October 08, 2014

Human Resources Management System Pay Entry Calendar

How to Install Microsoft Mobile Information Server 2002 Server ActiveSync. Joey Masterson

Test Plan for Department of Defense (DoD) Public Key Infrastructure (PKI) Interagency/Partner Interoperability. Version 1.0.3

VMware Virtual Desktop Infrastructure (VDI) - The Best Strategy for Managing Desktop Environments Mike Coleman, VMware (mcoleman@vmware.

Deep Security/Intrusion Defense Firewall - IDS/IPS Coverage Statistics and Comparison

Computing & Telecommunications Services Monthly Report March 2015

RSA Digital Certificate Solution

SAP Business Planning and Consolidation Version 10.0 for NetWeaver. Platform Information, Support Pack Dates and Maintenance Dates.

Employers Compliance with the Health Insurance Act Annual Report 2015

How To Deploy Cisco Jabber For Windows On A Server Or A Network (For A Non-Profit) For A Corporate Network (A.Net) For Free (For Non Profit) For An Enterprise) Or

Enterprise Security Critical Standards Summary

Digital certificates and SSL

Deep Security Intrusion Detection & Prevention (IDS/IPS) Coverage Statistics and Comparison

Deploy Remote Desktop Gateway on the AWS Cloud

Citrix MetaFrame XP Security Standards and Deployment Scenarios

Deploying iphone and ipad Apple Configurator

6445A - Implementing and Administering Small Business Server 2008

Hybrid Architecture. Office 365. On-premises Exchange org (Exchange 2007+) Provisioned via DirSync. Secure Mail flow

Kaspersky Endpoint Security 10 for Windows. Deployment guide

Neuroworks / Sleepworks Microsoft Windows Update Guide

Feature and Technical

McAfee Endpoint Protection Products

MS-10135: Configuring, Managing and Troubleshooting Microsoft Exchange Server Course Objectives. Price. Duration. Methods of Delivery

Using MobileIron Sentry for Control and Visibility into ActiveSync Devices

Ciphire Mail. Abstract

Deploying and Managing a Public Key Infrastructure

MS 10135B Configuring, Managing and Troubleshooting Microsoft Exchange Server 2010

A new Secure Remote Access Platform from Giritech. Page 1

Administration Guide Certificate Server May 2013

Softline VIP Payroll System Requirements v2.9a January 2010

Auditing Microsoft Exchange. Presented by Brian Thomas, featuring Shohn Trojacek from PivotPoint Solutions

Axway Validation Authority Suite

General Specifications

Cost effective methods of test environment management. Prabhu Meruga Director - Solution Engineering 16 th July SCQAA Irvine, CA

Alcatel-Lucent Extended Communication Server Active directory synchronization : installation and administration

MOC 6436A: Designing Active Directory Infrastructure and Services in Windows Server 2008

POSTX SECURE BUSINESS COMMUNICATION

Consumer ID Theft Total Costs

SharePoint 2013 Infrastructure Planning

Diploma in Computer Science

MCITPEXCH - Exchange Bootcamp Design, Configure, and Manage (10135/10233)

Implementing and Managing Microsoft Desktop Virtualization

CAFIS REPORT

EMC Celerra Version 5.6 Technical Primer: Public Key Infrastructure Support

Transcription:

Secure Messaging Challenge Technical Demonstration The Open Group EMA Forum

Boeing s Messaging Needs Provide access to strongly encrypted e-mail outside the enterprise Reduce complexity of deploying secure e-mail Present a single solution which can span the enterprise Provide broadly acceptable solution to customers, partners, suppliers

Technical Requirements Use X.509 v3 CA Services Self-signed or purchased commercial certificates RSA algorithm with minimum 1024-bit key length Provide standards-based directory services accessible via the public Internet Certificate stored in standard usercertificate attribute Provide S/MIME compliant messaging client capable of requesting certificates from the directory Provide S/MIME compliant email system Follow current standards regarding S/MIME, X.509 v3 and LDAP v3 COTS or open source products only

Scope Organization 2 Intranet Challenge Boundary Organization 1 Intranet Request to LDAP proxy with recipient's address External LDAP Proxy Internal LDAP Proxy LDAP Server with User Entries & Certificates LDAP Server or Proxy x509 v3 Public Key Desktop PC Desktop PC Network Firewall Public Network Network Firewall S/MIME Compliant Email Server Normal Message Route Normal Message Route Messaging Backbone Services Exchange Server

Deliverables Toolkit PKI Overview Certificate practices, guidelines and recommendations Lessons Learned Example architectures Comprehensive testing results Peer reviewed report of findings and recommendations

EMA Challenge Timeline Recruiting Scope Initial Architecture Testing and Validation Reporting and Demonstration Deployment Jul Sep Oct Nov Dec Jan Feb 2001 2002 Mar Apr

Lynx Systems Lotus Notes and Test Solution A: Server: Lotus Notes 5.0.8 Client: Lotus Notes 5.0.8 LDAP: Lotus Notes 5.0.8 Microsoft Exchange Test Solution B: Server: Microsoft Exchange 2000 Client: Microsoft Outlook 2000 SR1 and Security Patch LDAP: Linux with Open LDAP PKI Self-Signed Signed Root Certificate Authority on Microsoft Windows 2000 CA Server, Standalone

Email Server Lotus Notes DMZ A Notebook Mobile User Intranet Firewall Notebook Work Station Firewall Internet MS Windows 2000 PKI Linux Server + Open LDAP DMZ B Email Server Exchange

Boeing Demo Environment Messaging Environment Server: Microsoft Exchange 2000, and Key Management Server Client: Outlook 2000 SP2 Directory Environment Windows 2000 Active Directory PKI Environment Boeing Self-signed Root Microsoft Windows 2000 Standalone Subordinate CA Server LDAP presence Internal and External LDAP Proxy Servers Maxware Virtual Directory

Boeing Demo Environment Boeing Test Self-Sign Root Certificate Authority Internet Microsoft Windows 2000 Test Standalone Subordinate Certificate Authority External LDAP Proxy Maxware Virtual Directory Internal LDAP Proxy Maxware Virtual Directory Microsoft Windows 2000 Active Directory Microsoft Exchange 2000 Workstation With Microsoft Outlook 2000 SP2 Firewall Microsoft Exchange 2000 Key Management Server

SMTP/Vendor Certificate Architecture Messaging Environment Server: Sendmail 8.11.0 and POP3 daemon on Linux Client: Outlook 2000 SP2 Directory Environment Directory.verisign verisign.com Directory server for Verisign issued certificates PKI Environment Purchased Verisign Class 1 X.509 V.3 certificates

SMTP/Vendor Certificate Architecture Purchased user certificates from directory.verisign.com Internet Workstation with Microsoft Outlook 2000 SP2 Linux with Sendmail 8.11 & POP3 daemon

Demonstration Scenario 1 Boeing Exchange to Lynx Exchange Directory lookup Send/Receive encrypted message Scenario 2 Lynx Notes to Smtptestbed.com Directory lookup Send/Receive encrypted message Scenario 3 Smtptestbed.com to Boeing Exchange Directory lookup Send/Receive encrypted message Scenario 4 Lynx Exchange to Lynx Notes Directory lookup Send/Receive encrypted message

Lynx Test Environment Demonstration Environment Notebook Mobile User Intranet Email Server Lotus Notes DMZ A Notebook Firewall Boeing Test Environment MS Windows 2000 PKI Linux Server + Open LDAP DMZ B Email Server Exchange Internet Boeing Test Self-Sign Root Certificate Authority Microsoft Windows 2000 Test Standalone Subordinate Certificate Authority SMTPTESTBED.COM Test Environment External LDAP Proxy Maxware Virtual Directory Internal LDAP Proxy Maxware Virtual Directory Firewall Microsoft Windows 2000 Active Directory Microsoft Exchange 2000 Workstation With Microsoft Outlook 2000 SP2 Workstation with Microsoft Outlook 2000 SP2 Linux with Sendmail 8.11 & POP3 Daemon Purchased user certificates can be found at directory.verisign.com Microsoft Exchange 2000 Key Management Server

Scenario 1 Boeing to Lynx Exchange Directory Lookup

Scenario 1 Boeing to Lynx Exchange Read Encrypted Message

Scenario 2 Lynx Notes to Smtptestbed.com Directory Lookup

Scenario 2 Lynx Notes to Smtptestbed.com Read Encrypted Message

Scenario 3 Smtptestbed.com to Boeing Directory Lookup

Scenario 3 Smtptestbed.com to Boeing Recipient Read Encrypted Message

Scenario 4 Lynx Exchange to Notes Encrypted Message

Scenario 4 Lynx Microsoft Exchange to Lotus Notes Encrypted Mail