GSA / GSA/modernization

Suggest focus on non-PKI approaches to multi-factor authentication

Open
#22 0 comments 0 reactions 0 assignees View on GitHub
Public comment
Dominant language
CSS
Stars
59
Forks
8
PR merge metrics
No merged PRs in 30d

Description

The Draft Report rightfully focuses on the importance of Multi-Factor Authentication (MFA) as a "foundational capability" (per page 29), and flags the importance of strong authentication as a key tool to reduce the Federal attack surface through enhanced application and data-level protections.

To date, the government has made great progress toward deployment of MFA through its investments in PKI and the PIV and CAC platforms. These PKI-based solutions have been very secure, however, in practice, they have also presented a number of challenges and shortcomings in implementation and deployment. As a result, there are still many spots where MFA use is not ubiquitous across the Federal enterprise. The Report to the President should address this issue, as should the updated identity policy guidance that the Draft Report notes will be issued by OMB following the approval of the Report by the President.

While PIV should remain the credential of choice for eligible employees or contractors, in instances where PKI authentication is not practical, alternatives should be used that can extend the benefits of authentication based on asymmetric, public-key (PK) cryptography – without requiring PKI.

Earlier this year we published a white paper entitled “Leveraging FIDO Standards to Extend the PKI Security Model in United States Government Agencies,” which detailed one approach for the Federal government to leverage new, next-generation authentication standards to extend the benefits of authentication rooted in public key cryptography to a wider array of applications and users, without sacrificing the well-known benefits of PKI. Rather than detail every element of the case for PKI alternatives here, we suggest a review of the paper, which can be viewed at https://fidoalliance.org/wp-content/uploads/White-Paper-Leveraging-FIDO-Standards-to-Extend-the-PKI-Security-Model-in-US-Govt-Agencies.pdf

We note that NIST has already set the stage for this approach in the Draft of NIST SP 800-53, Revision 5; Control Number IA-5(2) focuses on Authenticator Management of “Public Key-Based Authentication” rather than “PKI-based Authentication” and lays out how both PK and PKI-based solutions can be used. However, a change in the NIST guidance is only one element of what is needed; it should be backed by updated OMB identity policy and also reflected in the final Report to the President.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.