[3381] in WWW Security List Archive

home help back first fref pref prev next nref lref last post

Re: Entrust and Microsoft ISAPI

daemon@ATHENA.MIT.EDU (Doug Rosenthal)
Fri Oct 25 16:14:29 1996

Date: Fri, 25 Oct 1996 12:39:42 -0500 (CDT)
From: Doug Rosenthal <rosenthl@tradewave.com>
To: davek@healthmagic.com
CC: www-security@ns2.rutgers.edu
In-reply-to: <01BBC0F5.276AECE0@VASUDEV> (davek@healthmagic.com)
Errors-To: owner-www-security@ns2.rutgers.edu


    Dave> We are thinking about using Nortel's Entrust in a web
    Dave> application that would use Microsoft's ISAPI and IIS web
    Dave> server. But how well does Entrust work with ISAPI?  Does
    Dave> anyone have experience with calling the Entrust toolkit APIs
    Dave> from an ISAPI filter?

Dave,

We have Entrust-ified the Microsoft (and Netscape) Web server via the
ISAPI (and NSAPI), as well as the browser(s).  Works great; let me
know if you would like more info.

    Dave> If we build the web app using a different API set than
    Dave> Entrust's, how interoperable are X.509 certificates
    Dave> generated by Nortel's Entrust CA product with applications
    Dave> developed on a security framework like Microsoft's
    Dave> CryptoAPI?  Are there any major caveats with "mixing and
    Dave> matching" security products of different vendors like
    Dave> Entrust and Microsoft?

Someone else on this list has already addressed some of these issues, 
i.e. wrt the CryptoAPI, Nortel's free Web certificate service, etc.
An additional note though - there's a big difference between a free
certificate with no accountability and one that is backed by strong
key management, policies and procedures, etc., at least wrt trust
models for intra/inter-enterprise applications. 


- Doug

-- 
Doug Rosenthal
Director, Product Development
TradeWave Corporation                 |  Email: rosenthal@tradewave.com
3636 Executive Center Dr., Suite 100  |  Voice: 512-433-5347
Austin, TX  78731  USA                |  Fax:   512-433-5303
-----------------------------------------------------------------------
                       http://www.tradewave.com/
                       http://galaxy.tradewave.com/
-----------------------------------------------------------------------

home help back first fref pref prev next nref lref last post