Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

What credential service providers or certification authorities are acceptable?

0
Posted

What credential service providers or certification authorities are acceptable?

0

A. DEA expects that application providers will work with credential service providers or certification authorities to direct practitioners to one or more sources of two-factor authentication credentials that will be interoperable with their applications. For practitioners who are obtaining a two-factor authentication credential that does not include a digital certificate, DEA is requiring that they obtain their authentication credential from a credential service provider that has been approved by the General Services Administration Office of Technology Strategy/Division of Identity Management to conduct identity proofing that meets National Institute of Standards and Technology Special Publication 800-63-1 Assurance Level 3 or above. For practitioners obtaining a digital certificate, DEA is requiring that they obtain the digital certificate from a certification authority that is cross-certified with the Federal Bridge Certification Authority (FBCA) at a basic assurance level or higher

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123