-
Notifications
You must be signed in to change notification settings - Fork 68
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #592 from GSA/1002-h1-seo-updates
1002-h1-seo-updates
- Loading branch information
Showing
3 changed files
with
15 additions
and
15 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -77,7 +77,7 @@ subnav: | |
| 1.0 | 02/14/2023 | Initial draft | --> | ||
|
||
|
||
# Overview | ||
## Overview | ||
|
||
The General Services Administration (GSA), Office of Government-wide Policy, manages the Public Key Infrastructure (PKI) Shared Services Provider (SSP) program. The primary program focus is to help agencies meet the policy intent of Homeland Security Presidential Directive 12, as well as achieve digital signature interoperability. | ||
|
||
|
@@ -87,7 +87,7 @@ A GSA PKI SSP is a commercial PKI provider who has completed Federal PKI complia | |
- [Section 2](#section-ii-ssp-application-and-maintenance-activities) -Defines the application and ongoing maintenance process to apply and stay in the GSA PKI SSP Program. | ||
- [Section 3](#section-iii-digital-certificate-services) -Lists available services that a SSP should offer. | ||
|
||
# Audience | ||
## Audience | ||
|
||
This document is primarily for the following audience: | ||
|
||
|
@@ -97,7 +97,7 @@ This document is primarily for the following audience: | |
|
||
If you have questions about this document or the outlined process, contact [[email protected]](mailto:[email protected]). | ||
|
||
# Section I: GSA PKI SSP Program | ||
## Section I: GSA PKI SSP Program | ||
|
||
The GSA SSP Program has a long history of successfully providing digital certificate services for employees, contractors, and affiliates. The program was started in December 2004 when the Office of Management and Budget (OMB) issued a directive, M-05-05, directing federal agencies to buy their digital certificate services through the SSP Program. Almost 20 years later, the program is a cornerstone for some federal agencies despite the drive to expand new services in a thin market. | ||
|
||
|
@@ -144,7 +144,7 @@ The GSA, Office of Chief Information Security Officer (OCISO) provides securit | |
|
||
The GSA Federal Acquisition Service (FAS) connects government buyers with the GSA PKI SSPs. The FAS organization captures the GSA PKI SSP services and sets prices, terms, and conditions of the Special Item Number (SIN) on the [GSA Multiple Award Schedule](https://www.gsaelibrary.gsa.gov/ElibMain/sinDetails.do?scheduleNumber=MAS&specialItemNumber=541519PKI&executeQuery=YES){:target="_blank"}{:rel="noopener noreferrer"}{:class="usa-link usa-link--external"}. The SSP SIN is intended to make it easier for potential buyers to search for the digital certificate services offered by the GSA PKI SSPs. | ||
|
||
# Section II: SSP Application and Maintenance Activities | ||
## Section II: SSP Application and Maintenance Activities | ||
|
||
Federal agencies requiring digital certificate services from a SSP will send a Request for Quotation or a Request for Proposal based on the SSP SIN—sending alerts to SSPs. Federal agencies can expect a response from the SSPs that reflects the due diligence completed by the Federal Acquisition Service (FAS) to offer SSPs that satisfy federal requirements. | ||
|
||
|
@@ -275,7 +275,7 @@ The GSA PKI SSP Program Office and GSA’s security team perform continuous mon | |
|
||
The vendor must maintain its GSA PKI SSP MAS Contract to stay in compliance with the GSA PKI SSP MOA. If a vendor cannot maintain a GSA PKI SSP MAS Contract, the PKI vendor will coordinate decommission activity through the GSA PKI SSP Program Office with customer agencies, the Federal PKI Policy Authority, and supporting GSA offices. | ||
|
||
# Section III: Digital Certificate Services | ||
## Section III: Digital Certificate Services | ||
|
||
While the SSP Program has primarily focused on digital certificates for Personal Identity Verification (PIV) cards, the [COMMON CP] provides opportunities (and supporting Object Identifiers (OIDs) for SSPs to offer additional services to federal agencies. | ||
|
||
|
@@ -335,11 +335,11 @@ A digital signature certificate is used to digitally sign documents such as PDF | |
|
||
Key Management Services store and manage private keys associated with encryption certificates. Examples might include Key Escrow and Recovery, Key History, and Data Decryption Services. | ||
|
||
# Conclusion | ||
## Conclusion | ||
|
||
GSA established the GSA PKI SSP Program to help agencies identify and procure federally-compliant PKI services and digital certificates. There may be multiple types of PKI SSPsrs, but only one type of GSA PKI SSP. This clear definition not only helps agencies identify approved services, but also leverage the governmentwide acquisition vehicles for customer agencies to receive consistent pricing, terms, and services. The GSA PKI SSP Program Office maintains the SSP Program and coordinates government activity on behalf of the GSA PKI SSPs. | ||
|
||
# Appendix A - Sample MOA | ||
## Appendix A - Sample MOA | ||
|
||
<p align="center"> | ||
<b> | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters