Giter VIP home page Giter VIP logo

Comments (8)

idmken avatar idmken commented on September 3, 2024

@ryancdickson is this similar to the script to import certs for altsecids?

from ficam-playbooks.

ryancdickson avatar ryancdickson commented on September 3, 2024

@idmken - Not quite.

I think the goal described in this issue would automatically assign a friendly name to a user's PIV credential certificates upon logging onto the intended system.

Populating the "Friendly Name" attribute can make it easier for end-users to distinguish certificates (i.e., authentication versus signature). Not all products support use of "Friendly Name" --- looking quickly, it seems as if IE does, but Chrome does not.

Sample screenshots of manually setting "friendly name" --- and IE presenting it are attached.

Friendly-1
Friendly-2
Friendly-3

from ficam-playbooks.

maxwellfunk avatar maxwellfunk commented on September 3, 2024

potentially test with Edge to see if friendly name is still applicable, if not close.

from ficam-playbooks.

ryancdickson avatar ryancdickson commented on September 3, 2024

Edge presents friendly name, observed in the following image:

edge-friendly-name-07232021

from ficam-playbooks.

maxwellfunk avatar maxwellfunk commented on September 3, 2024

We believe this issue to be OBE due to the following reasons:

  1. the Common (and soon to be bridge) profile updates which disallowed any key usage in EKU has been in effect for almost 3 years
  2. recent updates to the profiles have incorporated specific EKUs for the signing cert which would prevent them from being presented in a credential tile screen upon mutual TLS auth
  3. Several PIV issuers already append the CN with (A, E, S) for its specific use

from ficam-playbooks.

grandamp avatar grandamp commented on September 3, 2024

Some notes:

  • 2: Unless the issuer asserts TLS Client EKU in signature cert.

  • 3: Only one issuer (HHS) appends -A, -E, -S

from ficam-playbooks.

maxwellfunk avatar maxwellfunk commented on September 3, 2024

we also know that modifying the friendly name will not affect the experience for chrome users (assumedly 90% of the user base), and we have no known cert examples of user signature certs with SC auth or TLS client auth in the EKU currently.

from ficam-playbooks.

maxwellfunk avatar maxwellfunk commented on September 3, 2024

Closing issue per previous discussions and lack of impact.

from ficam-playbooks.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.