Re: [TLS] EU cards

Anders Rundgren <anders.rundgren@telia.com> Sat, 30 July 2011 07:16 UTC

Return-Path: <anders.rundgren@telia.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D6E8621F8CCE for <tls@ietfa.amsl.com>; Sat, 30 Jul 2011 00:16:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.554
X-Spam-Level:
X-Spam-Status: No, score=-3.554 tagged_above=-999 required=5 tests=[AWL=0.045, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ma738qGFAlqs for <tls@ietfa.amsl.com>; Sat, 30 Jul 2011 00:16:36 -0700 (PDT)
Received: from smtp-out11.han.skanova.net (smtp-out11.han.skanova.net [195.67.226.200]) by ietfa.amsl.com (Postfix) with ESMTP id 114BD21F8CCA for <tls@ietf.org>; Sat, 30 Jul 2011 00:16:36 -0700 (PDT)
Received: from [192.168.0.202] (81.232.44.37) by smtp-out11.han.skanova.net (8.5.133) (authenticated as u36408181) id 4E305E97000CA048; Sat, 30 Jul 2011 09:16:30 +0200
Message-ID: <4E33AFBC.3070900@telia.com>
Date: Sat, 30 Jul 2011 09:16:12 +0200
From: Anders Rundgren <anders.rundgren@telia.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.18) Gecko/20110616 Thunderbird/3.1.11
MIME-Version: 1.0
To: Peter Gutmann <pgut001@cs.auckland.ac.nz>
References: <E1Qn3Yq-0007dr-2v@login01.fos.auckland.ac.nz>
In-Reply-To: <E1Qn3Yq-0007dr-2v@login01.fos.auckland.ac.nz>
X-Enigmail-Version: 1.1.1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Cc: tls@ietf.org
Subject: Re: [TLS] EU cards
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 30 Jul 2011 07:16:37 -0000

On 2011-07-30 09:02, Peter Gutmann wrote:
<snip>

> I got three off-list responses from people who'd
> worked with it which included comments like "When we rolled out CAC, our
> support costs skyrocketed. It cost us more to support the damn thing than to
> roll it out" (quoted verbatim from email).

<snip>

>From a .SE watchtower I believe that the cost per seat usually exceeds
$500 over five years when all the *consultant fees* have been added.
For small agencies I believe it could easily reach $2000!

Even if you have W2KSR2 (with "CertServ") you need a $25 000 Microsoft
"Forefront Identity Manager" in order to get a MS-only card solution going.

There surely must be something seriously wrong here...

Competition: N/A.

Anders