D
D
doexec2019-08-28 03:29:00
Electronic digital signature
doexec, 2019-08-28 03:29:00

Storage, accounting, monitoring of EDS in small/medium business?

Share your experience - who, how (and where) stores EDS at their enterprises?
There are several legal entities, they have several electronic signatures, in the IT department there are 2-3 people of different competence, distributed offices and people.
Ideally, I see an internal web server and a couple of php pages with sessions and authorization, where there will be a list of legal entities (let's say tabs), then grouping by Certification Authorities (let's say accordions), and then the certificates themselves: owner's name, date-time of issue and endings, a link to CER, PFX, root certificates and a link to the CA (so as not to search if something happens).
You can sit and build on a framework like Yii quickly and beautifully.

Answer the question

In order to leave comments, you need to log in

6 answer(s)
K
krosh, 2019-08-28
@krosh

That's right - store the private part of the key only on physical tokens, not on the server, not in the registry. Especially when it comes to GOST.
What is the purpose of your event - accounting or mobile use? If there is a reasonable amount of certificates, then you should not bother further than a regular table. The main thing you need to monitor is the expiration date of the certificate and to whom it was issued. When accounting for an ES, it is necessary to record both the name of the subject and the username of who uses the ES (it is not necessary to do this, but it happens), and the number of the carrier / token, which means that carriers must also be taken into account separately.
Buy tokens for offices and make copies (this is also not correct, but it will allow you to work in different places). Better yet, issue an ES to each person in charge and a power of attorney for the type of work.

A
Andrey Ermachenok, 2019-08-28
@eapeap

Why does the IT department have to do this?
Banking, for tax, etc. EDS is received, used, stored and tracked.
EDS for trading floors - salesmen and buyers. And they are tracking.
In principle, you do not need to store other people's EDS. Well, money will leave the account to the left - do you want to be extreme along with your department?

V
Vladimir, 2019-08-28
@SibUrsus

If you have Persian. employee data - it means it is already ISPD. And this means that there is a non-zero probability that the inspectors will come with instruction 152 FAPSI at the ready and make you a bo-bo.
Everything must be done according to it, the rest is a game with the state "who has a higher jet." The state always wins, for some reason.

I
Igor, 2019-08-28
@Lopar

You are overcomplicating. Restricted folder. There are keys and a textbook with a description. If panic is panic and you don’t need to stop re-issuing something (although panic is usually the domain of accounting), create a reminder in your calendar that will yell for a month / for a week.

D
Dmitry Shumov, 2019-08-28
@dshumov

Colleagues, why didn't anyone mention the Excel + calendar link? In excel we keep a list and record of what is, and in the calendar we put a reminder about the deadlines for the expiration of certificates and digital signatures. I have such a bunch of works for 3 years and everything is ok. And no extra information in the public domain and release dates will be lost ....

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question