[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RFDC Scenario two




 Scenario 2:

The concept of a central key server involves the following problems: 

Assuming full-time 24x7 IP availability of the central site as a
requisite, at least three levels of fail-over site replication will be
required to insure availability.

Who would assume the equipment and staffing costs of establishing and
aintaining those sites?

Who would assume the responsibilities for access failure, data
compromise, security breaches, liability on compromise, et cetera,
associated with a central site?

	How frequently will key-changes be allowed, collected and
redistributed?

	How will the updated key ring be deployed (i.e., push, pull,
secure, on-line open-access)?

	How will failures by subscribers to receive the updated key-ring
be dealt with?

	Who would manage and set standards and policies for a
key-server(s)?  Would the committee do it? Could we contract the tasks?
What other means are available?