Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

DHS Goes PKI

Entrust, XTec to deploy PKI and provide secure smartcard login, encrypted communication

Nov 19, 2009 | 08:58 PM

DALLAS — November 17, 2009 — Drawing on years of success securing various U.S. federal agencies and

departments, Entrust, Inc., and their proven public key infrastructure technology, will now provide the unified

security infrastructure for the U.S. Department of Homeland Security (DHS) components. This agreement helps

DHS enable cost-savings, meet HSPD-12 requirements, encrypt communications and data, and deploy secure

credentials for both physical and logical access.

"PKI technology remains such a valuable and versatile tool, regardless of the scope or type of environment it

secures," said Entrust President and CEO Bill Conner. "The Department of Homeland Security should be lauded

for not only unifying their security architecture, but for doing so in a manner that enhances cross-component

efficiency and helps save money by reducing the number of solutions securing different offices and locations."

Facilitated by partner XTec Inc., who is the key HSPD-12 solution provider for DHS, the Entrust deployment will

provide PKI services and digital certificates for all DHS components and their employees. The two-year

implementation will leverage Entrust's PKI architecture, Entrust Authority, as well as Entrust Entelligence

Security Provider and XTec's AuthentX platform for the management and secure distribution of the agency's

internal digital certificates. These certificates will provide DHS proven smartcard login, network authentication,

as well as encryption for e-mail and desktop environments.

"XTec has years of proven experience as a security solutions provider for the U.S. government, and opting for a

strong, proven PKI will help DHS meet their immediate and long-term security needs," said XTec CEO Albert

Fernandez. "We're looking forward to collaborating with Entrust on this critical government project, and our team

innovation will serve as a strong security model for other U.S. agencies to follow."

Entrust's PKI solution has been implemented to perform critical security tasks in various U.S. federal agencies,

including the U.S. Department of State for advanced ePassports and the Shared Service Provider (SSP) PKI for the

U.S. Department of Treasury. Entrust's hosted PKI service is also identified by the U.S. General Services

Administration (GSA) as an approved SSP for use within federal environments.

Additional state and federal PKI deployments include the State of Illinois, State of Virginia, the Departments of

Energy and Justice, NASA, the Government Printing Office, U.S. Department of Labor, U.S. Patent and

Trademark Office and the Federal Bureau of Investigation.

XTec provides the knowledge, products and experience to help U.S. federal departments and agencies deploy

solutions to comply with HSPD-12 and PIV requirements, as defined in FIPS 201 and related NIST standards. The

specific solution, XTec's AuthentX Identity Management System, includes all required components for an HSPD-

12 PIV II solution. XTec was among the first companies — and was the first small business — to be certified by

GSA to provide a "complete end-to-end solution," including each of the HSPD-12/PIV system components. XTec

(continued) /2

Version: 11/17/2009 @ 10:20 AM CDT

also has a long-standing relationship with the DHS for document security, which relies on XTec technology to

assist in the forensic tracing of counterfeit cards.

Entrust Entelligence Security Provider is an enterprise-wide security platform for Microsoft Windows desktops,

domain controllers and authentication servers that allows organizations to deploy the digital identities that enable

the strong authentication, encryption and digital signature capabilities within a number of authentication

applications and other applications such as data encryption and secure e-mail.

Entrust's first public key infrastructure — the world's first commercially available PKI — was released in 1994.

Now in its eighth edition, the Entrust Authority public key infrastructure product portfolio is the industry's most

relied upon PKI solution. By managing the full lifecycles of digital certificate-based identities, Entrust Authority

PKI enables encryption, digital signature and certificate authentication capabilities to be consistently and

transparently applied across a broad range of applications and platforms.

The U.S. Department of Homeland Security leverages resources within federal, state and local governments,

coordinating the transition of multiple agencies and programs into a single, integrated agency focused on

protecting the American people and their homeland. More than 87,000 different governmental jurisdictions at the

federal, state and local level have homeland security responsibilities. The comprehensive national strategy seeks to

develop a complementary system connecting all levels of government without duplicating effort.

About XTec

XTec is a leader in secure, interoperable authentication and verification systems. XTec develops, produces and

licenses enterprise-level security solutions for credentialing, access control, information systems and electronic

commerce for a wide range of government and commercial uses. XTec's focus is on providing a foundation from

which customers can build secure, Web-based enterprise applications and cryptographic systems. XTec is a

recognized leader in both government and commercial circles for its expertise and products for credentialing,

identity, secure payment and access control. For more information visit www.xtec.com.

About Entrust

Entrust provides trusted solutions that secure digital identities and information for enterprises and governments

in 2,000 organizations spanning 60 countries. Offering trusted security for less, Entrust solutions represent the

right balance between affordability, expertise and service. These include SSL, strong authentication, fraud

detection, digital certificates and PKI. For information, call 888-690-2424, e-mail entrust@entrust.com or visit

www.entrust.com.

Entrust is a registered trademark of Entrust, Inc. in the United States and certain other countries. In Canada, Entrust is a registered

trademark of Entrust Limited. All Entrust product names are trademarks or registered trademarks of Entrust, Inc. or Entrust Limited.

All other company and product names are trademarks or registered trademarks of their respective owners.

For more information:

Lindsey Jones

Media Relations

972-728-0374

lindsey.jones@entrust.com


Subscribe to RSS










Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:suse linux
Published:2010-01-22
Severity:High
Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
Vulnerability:bind
Published:2010-01-22
Severity:Medium
Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)