Making NAC Standard Progress: IETF accepts two TNC specs
comment No Comments Written by jj on March 11, 2010 – 3:41 pm

I’m excited to share with you this press released, jointly announced by TNC and IETF. Internet Engineering Task Force Publishes Network Access Control Standards Based on Trusted Computing Group Specifications. Keep reading to find out exactly what this means.

The roles of TNC and IETF
As many of you know from my posts and talks, I always distinguish between frameworks and standards. TNC is a consortium that created a framework for NAC communications and endpoint checks. Many vendors have already bought in to the TNC specifications, but there have been a few holding out; Cisco being the largest and most influential. Strangely enough, Cisco wanted to have a standard in place, versus a less formal framework. Ironic, I know. In any event, the IETF (in the form of IETF’s NEA) has been trying to fill that gap of true NAC standards. The problem has been that, although vendors said “yes” to the IETF standards, no one was contributing any new specifications for it. Here’s where TNC reenters the picture. Slowly but surely, the IETF has been adopting the TNC’s frameworks as accepted specs for the standards.

The importance of this announcement
Today’s news demonstrates one more big step in the right direction for TNC, IETF and all the vendors participating. With the acceptance of two more TNC specifications into the IETF standard, we can expect to round out the full IETF NAC Standard by the close of 2010. With a full set of standards, vendors will be able to offer scalable, evolving solutions that integrate more seamlessly with the rest of the infrastructure. Exciting, isn’t it!?

The announcement begins

Internet Engineering Task Force Publishes Network Access Control Standards Based on Trusted Computing Group Specifications

PORTLAND, MARCH 11, 2010 - Trusted Computing Group today announced that two specifications created by its Trusted Network Connect (TNC) work group have been accepted and published as specifications by the Internet Engineering Task Force (IETF). This means that developers and OEMs wanting to create network access control products now will have a single set of standards to support.
“Enterprise users are the real winners; the agreement on a single standard for network access control and endpoint assessment will provide consistency across products from leading networking vendors,” said Russ Housley, chairman of the IETF.

Noted Steve Hanna, co-chairman of the TCG TNC work group and of the IETF working group on this topic, “This industry-wide agreement on standards will increase the number of vendors and customers adopting standards-based network security. In addition, products developed for the new standards can be deployed with the many existing products using TNC specifications to protect the network and critical assets from a myriad of threats.”

The first standard (called PB-TNC by the IETF and IF-TNCCS 2.0 by the TCG) defines a standard way to perform a health check of a network “endpoint” such as a laptop computer or printer. If the endpoint is not healthy, it can be fixed or have its network access restricted. The second standard (called PA-TNC by the IETF and IF-M 1.0 by the TCG) defines a standard set of health checks that are commonly performed, such as checking anti-virus status. These newest standards are based on the TNC standards that customers have been using for years.
continued

You can read the full press release online at: http://www.trustedcomputinggroup.org/media_room/news/113

Look for more information and content soon about TCG’s TNC, IETF and NAC standards, including a video interview with TNC’s Steve Hanna.

Resources and links:

 # # #

Maker Faire Comes to NC April 25th
comment No Comments Written by jj on March 10, 2010 – 1:22 pm

That’s right! Maker Faire is coming to the East Coast April 25, 2010 right here in the Triangle of NC. Keep reading to learn about this GREAT event and how you can participate!

 

What is it?
Maker Faire:NC is a newfangled fair that brings together science, art, craft and engineering plus music in a fun, energized, and exciting public forum. The aim is to inspire people of all ages to roll up their sleeves and become makers. This family-friendly event showcases the amazing work of all kinds of makers–anyone who is embracing DIY and wants to share their accomplishments with an appreciative audience.

Costs and Participation
Attend: FREE
Makers: FREE
Exhibitors: $50 - $200 (100-1600 sq ft)

A note from the organizer:

Maker Faire is an annual event organized by the people who bring us MAKE Magazine.  Maker Faire:NC is a fully sanctioned event but is being planned and coordinated by Raleigh/Durham locals.  Our goal is to bring together Makers, Crafters, Inventors, Evil Geniuses, Scientists, Artists, and anyone else interested in learning from NC, SC, VA, DC, and beyond.

Just like the bigger Left-Coast version, Maker Faire:NC celebrates things people create themselves — from James Bond-worthy electronic gizmos to Martha Stewart-quality “slow made” foods and homemade clothes. Inspiration is ubiquitous at the festival and there are surprises around every corner for people of all ages.

“At the surface, Maker Faire is a fun event for people of all ages,” explained (San Mateo 2009) Event Director Sherry Huss. “But we want people to experience more than just a weekend of creative entertainment, we want them to leave feeling inspired — that they too can create things, express themselves, and engage the world around them. Our goal is to resuscitate the spirit of American creativity and innovation.”

This video from the Full Size Maker Faire held in 2009 in California will give you a little idea of what we’re all about.

Ideas for Makers who want to participate (remember, it’s FREE)!

  • Green Tech and Clean Tech
  • Robotics
  • Music Performance and Participation
  • 3D Printers and CNC Mill
  • Textile Arts and Crafts
  • Home Energy Monitoring
  • Rockets and RC Toys
  • Radios, Vintage Computers and Game Systems
  • Electronics
  • Electric vehicles
  • Biology/Biotech and Chemistry Projects
  • Food and Beverage Makers
  • Kites
  • Shelter (Tents, Domes, etc.)
  • Unusual Tools, Machines, or Techniques
  • How to Fix Things or Take them Apart (Vacuums, Clocks, Washing Machines, etc.)

Links and Resources

# # #

Event Postponed: CSO Executive Seminar in DC

February 8, 2010 – 7:27 pm

Just a quick note to those of you planning to attend the CSO Executive Seminar in DC this Thursday. Due to the rather ominous forecast for an additional 10-20 inches of snow in ...

The Rugged Software Manifesto: Walking the Walk

February 5, 2010 – 5:31 pm

I was excited recently when I learned a group of trustworthy, security-minded people had committed to a meme to promote the ideas and culture of secure coding. We hear talk daily among practitioners ...

Terrorizing Martin During My Interview by SFS Podcast

February 5, 2010 – 3:48 pm

If you're up for a bit of audible Friday humour, check out the SFSP (Southern Fried Security Podcast) Episode 5, where I try to terrorize Martin with off-the-wall responses while he's interviewing me. ...

Contribute: Join the Securosis User Panel

February 4, 2010 – 4:26 pm

Hi everyone. Some of my friends over at Securoris are putting together what I'm sure will prove to be an insightful user panel to participate in information security discussions and surveys. As part ...

The Skinny on Security BSides San Francisco

February 1, 2010 – 2:36 pm

Hi everyone! I'm hoping to catch up soon on some other important updates here, but I did want to be sure I included information on the upcoming Security BSides Conference, coinciding with RSA ...

JJ at The CSO Executive Seminar on Data Protection and Encryption

January 14, 2010 – 7:36 pm

Next month, I'll be joining a great lineup of speakers for a packed one-day conference, hosted by CSO Magazine. There are several individual sessions, interspersed with breakfast, lunch and short 30-minute technology briefings. ...

RSA 2010 Discount Code, Save $600

January 14, 2010 – 12:44 pm

Geez. I meant to include this in the first RSA post, but I fell victim to a multitasking failure, yet again. As most of you know, if you're planning to attend RSA, you want ...

More not-to-be-missed RSA 2010 Sessions

January 14, 2010 – 11:50 am

In addition to the oh-so-exciting session I'm hosting, several friends and colleagues are hosting other sessions at RSA 2010 you don't want to miss.  What other sessions are on your 'don't miss' list?  My don't-miss sessions at ...

Hosting a NAC and Endpoint Security Session at RSA 2010

January 14, 2010 – 11:22 am

Hello everyone and happy 2010. I owe you all a few updates and they're coming; I promise. I've been tied up with work, the holidays, miscellaneous house tasks and quite a bit of ...

Four Options for Secure Wireless Authentication with 802.1X

December 4, 2009 – 1:40 pm

The use of 802.1X in wireless is currently the most widely accepted method for secure authentication and key exchange in enterprise environments. I would say the only other "industry-approved" method for secure wireless ...

Get Uncorked!

Subscribe to JJ's Security Uncorked via email or by RSS feed.

Want to subscribe?

 Subscribe in a reader Or, subscribe via email:
Enter your email address:  
Find entries :