Three Preliminary Recommendations
1. Develop a strategy and associated policies for PKI implementation that includes a roadmap for trust relationships and the development of relying party trust requirements in communications external to DoD using PKI
- This strategy and associated policy should consider the use of the Federal Bridge CA for interoperating the DoD PKI with non-DOD Federal agency PKIs, and even PKIs external to the Federal government.
- Define requirements for use/acceptance of non-DoD PKI certificates for communications external to DoD
- Specifically not preclude the acceptance and reliance on Class 2 and 3 equivalent PKI certificates where their use in an external eB environment is appropriate