An enterprise (such as an institute of higher education) wishing to deploy PKI must choose between several options, all expensive and awkward. It might outsource certification to a third-party company; it might purchase CA software and appliances from a third-party company; it might try to build and maintain its own CA. In the latter two options, the enterprise faces the additional challenge of showing sufficiently safe practices to have its CA certified or crosscertified, for broader inter-operability. This paper presents our research and development effort to address this problem. We use OpenCA to provide the basic functionality; we package it on a Linux
Mark Franklin, Kevin Mitcham, Sean W. Smith, Joshu