NIST: Personal Identity Verification (PIV) of Federal Employees and Contractors
nvlpubs.nist.gov
nvlpubs.nist.gov
So many forms. Randomly imposed, arbitrary deadlines that were utterly impossible. (And … not really deadlines, since you can just email and say a polite "how about no" & magic extensions happen.) Forms that were submitted by encrypting them into a zip, and then sending zip+password in an email…?
The person who fingerprinted me was royally annoyed at me for showing up with all the materials their office had told me to show up with, but not having the materials that I wasn't told to show up with. (And that I wasn't "in the system" — okay. I'm new! I don't know why that is, nor who to ask, nor what 98% of the acronyms mean.)
You want to stop being a contractor, and give the PIV card back? More forms.
I started jokingly wondering when signatures in blood happen.
Definitely wasn't worth it, in my case.
And at the same time support this widespread would not exist without the U.S. using PIV, so I'm glad people bother :D I also recall some U.S. government site recommending a small and sleek card reader designed here (folds into an USB-stick shape).
Hopefully these processes improve and systems become more interoperable cross-borders at some point.
Mine used to issue PIV smartcards (I think; at least there was a PKCS#11 driver for it available), but discontinued it in favor of server-hosted “private keys” unlocked via SMS-OTP (I wish I was kidding).
I suspect that’s not too uncommon.
1. create a plaintext ZIP
2. completely overwrite the file created in #1 with an encrypted ZIP
so if you followed the instructions, one of the steps was utterly pointless, too.[1] https://www.icao.int/publications/Documents/9303_p4_cons_en.... (page 30)
Why so much Australian in this example?!
I must be misunderstanding what you mean by this, because I'm struggling to fathom what possible use a "personal identity verification badge" could possibly have _other_ than as a means of identifying yourself.
The real reason not to use your PIV for ID in random places is that it's meant to be used as an ID for you acting as your official capacity. This can also be seen in the case where people have multiple PIVs to represent their multiple identities, like National Guard who may have a PIV as a contractor and a PIV as a National Guard -- they would use the correct one depending on what capacity they are acting, or none if it's not part of their official duties.
There can still be a root password for emergencies, but it wouldn't be available for remote access -- ILOM or some other BMC (or even a serial port concentrator) would be configured for HSPD-12-compliant auth for remote console access, then you would use the root password for system access (though you could also just reboot into a separate operating system, since disk encryption isn't required except for mobile devices).
I'm not sure what the above poster's command or organization was doing to comply with HSPD-12, but they were most likely doing something. The compliant reports are generally public, also.
CAC login is for web only in most cases.
In my experience, at every place we had a different approach but all satisfied HSPD-12 and did not use passwords shortly after the various directives were promulgated through the various channels, except on classified systems since there wasn't a procedure at the time to declassify the CAC/PIV after periods processing -- though there were plans for changing that, and it may be resolved by now.
Nice theory, but has no actual connection to the real world.
Surprised no one has mentioned the open sourcing of the Orb in this context https://worldcoin.org/blog/engineering/worldcoin-foundation-...