Practicalities of Deployment (5)
Standards versus Profiles
- standards are good but also useless in many respects
- profiles provide interoperability
- useful profiles only just emerging e.g. PKIX, S/MIME
- industry specific profiles need to be finalized
Many vendors have missed the point
- Too much resistance from vendors fighting to keep lock-in
User/Customer Education
- how many end-users would know what to do when they’re told a signature verification has failed
- how many end-users understand certificate acquisition dialogs
- not enough central policy management tools