Federal Electronic Authentication Policy (January 2001)

The second paragraph under scope of the Electronic Authentication Policy was revised by inserting one sentence.  This revision will be published in the Federal Register the week of January 29, 2001.  At that time, the PDF and TXT files will bbe updated.   The revised paragraph is as follows (the new sentence is highlighted):

Focus is also placed on the use of public key cryptographic techniques, which can provide for robust electronic authentication, and on the manner in which Federal agencies must go about obtaining public key digital certificates for payment, collection, and collateral transactions. (It should be noted that in establishing such guidance, our intent is not necessarily to dictate that a particular certification authority provider be used, but rather to try to follow a general principle that offers agencies some choice, particularly where commercial certification authorities must be relied upon. Specifically, it is our intent to foster a competitive environment that would allow agencies to have some choice when obtaining cryptographic credentials for collections as covered by this policy.)  In addition to public key cryptography, the policy covers other forms of remote electronic authentication and electronic signatures, including but not limited to knowledge-based authentication (Personal Identification Numbers (PINs) and passwords) and biometrics.