iOS 5, Apple’s new operating system for iPad, iPhone, and iPod Touch, will be released “soon” – Apple officially says “this Fall”, and many prognosticators are pointing to sometime in October. While the new release has hundreds of new features, the feature that’s of particular interest to digital identity practitioners such as CSS is one that’s received very little press to date.
Continue Reading »
Part 2 of Apple’s iOS Devices and Certificate Lifecycle Planning blog.
CSS created the Certificate Reporting Tool (CRT) a few years ago, to help organizations get a better handle on certificate expiration. Below are examples of two different architectures that leverage CRT to help with certificate issuance and renewal for iOS-based certificates.
Continue Reading »
iOS devices such as iPads and iPhones are quickly becoming a part of the enterprise IT landscape, in a trend sometimes referred to as “the consumerization of IT.” From a security practitioner’s standpoint, there are a number of factors here that are cause for concern, including the prospect of unmanaged or “under-managed” devices accessing corporate data, the variety of devices and form factors involved, and the rapid pace of adoption, to name a few.
Enterprise Public Key Infrastructure (PKI) and digital certificates can help. iPhones and iPads are natively capable of using digital certificates for authentication to corporate networks and data in a variety of ways:
Corporate wireless networks (802.1X and EAP-TLS)
VPN gateways via the built-in Cisco client
Microsoft ActiveSync
Mutually-authenticated SSL web sites via the Safari browser
Continue Reading »