Educause Security Discussion mailing list archives

Re: Digital signatures....??


From: Valdis Kletnieks <Valdis.Kletnieks () VT EDU>
Date: Wed, 11 Aug 2010 13:46:58 -0400

On Tue, 10 Aug 2010 23:47:04 MDT, "SCHALIP, MICHAEL" said:

Is anyone out there using digital signatures - I'm familiar with Entrust 

We've deployed the Alladin e-Token for our leave tracking system in some
departments.  We haven't deployed it university wide because we hit a few snags
along the way - for instance, trying to do digital signatures on leave reports
is... problematic.. for some of our business units such as Housekeeping and the
grounds crews, where there is no expectation of even basic computer literacy
(and quite often no generic literacy either) - training them how to fill out an
online form and sign it, and all the little challenges (like making sure they
understand *they* are to sign it, not their supervisor who understands the
process, etc etc etc).  It's rumored we still have some deans and department
heads who would need intensive training too.. :)

We also handed out the first deployment of e-Tokens intentionally crippled
to be able to sign only and not encrypt, because if we allowed them to
encrypt business information (which overall would be a Good Thing),
we'd have to address the problem of key escrow, which we don't have
an enterprise-grade production handle on yet.

I'll make a special note - all the problems we've had with the eToken have
been integration problems into our business environment.  The hardware
works fine, and the worst problem I'm aware of software-wise is that they
only ship 32-bit Linux driver libraries, no 64-bit.  But I'm told that only
3 people are affected - me, myself, and I.  So I keep a 32-bit Firefox
binary around.


Attachment: _bin
Description:


Current thread: