Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Illinois puts pizazz back in PKI

Program once hailed as leading-edge back on track after stumbles
By Ellen Messmer , Network World , 07/11/2007

In 1999 Illinois placed a big security bet on public-key infrastructure for e-commerce, but three years ago its PKI project faltered as state agencies foundered badly when issuing the digital certificates to citizens.

It wasn’t supposed to turn out that way. The state’s landmark Electronic Commerce Security Act had given digitally signed documents an equal legal status to wet-signature paper ones in 1999, putting Illinois on the cusp of the PKI revolution. “Over the next 18 months we hope to distribute over a million digital IDs to citizens and businesses to enable them to do business with the state of Illinois as an integrated secure Web-driven government,” proclaimed then-Governor George Ryan.

The idea was to decrease paper-based exchange in favor of electronic documents in every sphere of government on every level by having citizens submit digitally signed forms instead of written signatures.

In early 2001, that still sounded possible, as Illinois had the technology contracts in place -- primarily one with Entrust -- making digital-certificate registration, issuance and management software available to state agencies. But the agencies were flummoxed by the intricacies of PKI, in which sender and recipient can exchange encrypted and signed documents through a public-private key pair also used to verify contents haven’t been altered.

“By 2003, we had less than 6,000 certificates issued,” acknowledges Doug Kasamis, acting deputy director of the state's IT department, the Central Management Services (CMS) Bureau of Communication and Computer Services.

More wheels were coming off the wagon as Gov. Ryan, once praised for setting up a cabinet-level chief technology office, left office under a cloud of scandal that year, later being convicted of racketeering and fraud charges. By 2004, it was clear that something had to be done to save the PKI effort, whicht was failing despite the fact that Illinois was distributing certificates for free.

“We called this our ‘IT rationalization,’” says Mark Anderson, head of the PKI project. Basically, the state agencies and the IT department settled on a last-ditch plan to centralize the administration of PKI at the CMS level, having CMS do the technical work on behalf of the state agencies.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comments (3)
Login
Forgot your account info?

Illinois puts pizazz back in PKIBy olga13 on June 18, 2008, 4:17 amMy name is Olga and I work for a company that specializes in digital signatures. If you're interested, there's some useful background (non-commercial) information...

Reply | Read entire comment

Illinois puts pizazz back in PKIBy Brian Dilley on July 18, 2007, 2:19 pmMs. Messmer, I am Brian Dilley, the President and Founder of eValid8 Corporation, and I am writing you in regards to your recent article on the State of Illinois...

Reply | Read entire comment

RE: Illinois puts pizazz back in PKIBy Steve on July 12, 2007, 1:38 pmI'd like to hear how their users like dealing with PKI. From my own personal experience dealing with users and PKI it hasn't been pretty.

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

If the IT manager is knowledgeable regarding Cisco technology, he would have 2 options. Option 1 - Consult...- Anonymous

Join the Discussion