How FBCA works

When one agency receives a transaction from another that is signed with

a private key that corresponds to a public key in a certificate issued by

the sender's certificate authority, the receiving agency has to determine

that the certificate can be trusted, something that the Federal Bridge Certification

Authority enables through a trust path.

The receiving agency must determine that the certificate has sufficient

trust, which is done by comparing the receiving agency's trust policy to

that of the FBCA.

Finally, the FBCA allows the receiving agency to determine that the

certificates in the trust path are still valid. If all three of these

elements are met — something the FBCA determines automatically — the transaction

can be completed.

The prototype has two CA products supplied through Baltimore Technologies

and Entrust Technologies Inc., which interoperate within the FBCA. Any agency

CAs that interoperate with either product will be able to interoperate with

each other. The intent is to include a range of other CA products in the

FBCA, with the goal of allowing interoperability with any CA product or

service an agency may choose to work with.

About the Author

Brian Robinson is a freelance writer based in Portland, Ore.

Featured

  • Workforce
    Shutterstock image 1658927440 By Deliris masks in office coronavirus covid19

    White House orders federal contractors vaccinated by Dec. 8

    New COVID-19 guidance directs federal contractors and subcontractors to make sure their employees are vaccinated — the latest in a series of new vaccine requirements the White House has been rolling out in recent weeks.

  • FCW Perspectives
    remote workers (elenabsl/Shutterstock.com)

    Post-pandemic IT leadership

    The rush to maximum telework did more than showcase the importance of IT -- it also forced them to rethink their own operations.

Stay Connected