Many organizations invest in Public Key Infrastructure (#PKI) to enable #certificate-based authentication (#CBA). CBA provides a high level of assurance and strong #authentication fulfilling the mandates by numerous security and privacy #regulations agencies around the world. PKI is used broadly in many sectors, including banks, healthcare, and energy, to secure data access using strong two-factor or #multi-factor authentication. Using hardware security devices with a Public Key Infrastructure is still considered the most secure multi-factor authentication method.
The benefits of PKI with requirements to manage cloud-based applications have extended the use of digital certificates, but at times have made managing PKI environments complex. Due to these complexities, enterprises are often forced to make certain adjustments or tradeoffs between business functionality and security, which can create infrastructure gaps exposed to cyber-attacks. Combining PKI with #FIDO2, is a great way to bridge these gaps where enterprises can take advantage of their existing infrastructure and extend their existing security modern authentication methods that safeguard access to #cloud-based apps.
Versasec’s flagship product vSEC:CMS integration with Gluu Casa (@GluuOrg) provides support and management of PKI and FIDO credentials, providing coverage for any open gap in an organizations’ security infrastructure. The integration includes the ability to enroll users' FIDO credentials into the Gluu #IdP for authentication to access websites, cloud-based apps and data.
Combining FIDO2 authentication with hardware-based PKI addresses the needs of an organization for a variety of applications and use cases:
Email encryption and document signing,
Web and SaaS applications access,
Mobile applications, offline and online desktop logon,
Access to shared workstations, and
Strong authentication for remote employees, ensuring the highest level of multifactor authentication.
John Asan, Technical Leader at Versasec
John Asan is a Technical Leader at Versasec. He brings nearly two decades of experience in successfully implementing strategic IT initiatives that improve business processes and productivity to his role. His specialties include identity and access management (IAM), cryptography, certificates, PKI, HSMs and user credentials. At Versasec, John works closely with sales prospects, identifying their technical and business requirements and guiding them to the right solutions. He also assists the company’s R&D team in designing customized IAM solutions.
Davin Cooke, Business Development Director at Gluu Inc.
Davin Cooke leads the Business Development strategy for Gluu. His experience spans over 20 years in IT Software Security sales and Partner development. Davin is well connected in the infosec community and champions best practices for Data Governance, Identity and Access Management, and Compliance. An active member of ISC2, and the International Association of Microsoft Channel Partners. Davin holds a current CISSP and specializes in data discovery and forensics for regulated industries, like State and Local Government, HealthCare, and K-12 Higher Education. After studying Electronics Engineering in Canada, Davin held supply chain procurement roles meeting demands for circuit board manufacturing and PC related repairs for Nortel, Compaq, and Digital Equipment Corporation.