|
|||||||||||||||||||||||||||||||||||
|
14 Reviews
|
Average Customer Review
Share your thoughts with other customers
Create your own review
|
|
Most Helpful First | Newest First
|
|
57 of 62 people found the following review helpful:
5.0 out of 5 stars
Great PKI Project Manager's Guide/tutorial/overview,
By Smiling Hotei (Grass Valley, CA) - See all my reviews
Amazon Verified Purchase(What's this?)
This review is from: Understanding the Public-Key Infrastructure: Concepts, Standards, and Deployment Considerations (Hardcover)
I gave this five stars for the breadth of coverage. I don't need yet another book on cryptography -- I already have a shelf full. Carlisle and Steve cover the PKI turf without getting unnecessarily bogged down in technical details. For example, they cover the functions and differences of ECDSA versus ECDH in about a paragraph. If you want to know how the algorithms work, read Applied Cryptography. This has a clear, concise, and non-technical explanation of just about every concept, standard, and issue a project manager would need to know about PKI. I give credit for not trying to cover the technical issues in depth -- rather, this takes the approach of: here's the issue, here are the alternatives, and if you want to know more read ...The concepts and issues are very current, and cover proposed and draft standards, including Privilege Management Infrastructure, certificate revocation mechanisms, trust models, etc. Excellent coverage!
22 of 23 people found the following review helpful:
5.0 out of 5 stars
comprehensive and still very readable: a must!,
By A Customer
This review is from: Understanding the Public-Key Infrastructure: Concepts, Standards, and Deployment Considerations (Hardcover)
I'm giving courses on PKI. I was looking for a good reference for my students. Finally found one! I read it cover to cover: comprehensive, very easy to read, vendor-neutral (very important to me), not biaised: also gives you the pros and cons, issues with PKI. A must to read if interested in PKI.
7 of 7 people found the following review helpful:
3.0 out of 5 stars
Has value for Technical Architects / Security Analysts,
This review is from: Understanding the Public-Key Infrastructure: Concepts, Standards, and Deployment Considerations (Hardcover)
I think there's some merit to people expecting a more hands on approach in a book like this. But those expectations seems unrealistic. The book is not titled "Implementing PKI," it's called "Understanding PKI."There is value in a concepts book. For experienced technical professional trying to get a grip on the terminologies and concepts of security and PKI, this book is succinct and touches all the major points. For those looking for screenshots of people right clicking icons, there's a thousand other books like that! Most of those so called "technical books" are not that technical. It's nice to have a book that's not product specific for a change. This book does what it intends to do well. There is a need for more technical books but this book is valuable in it's present form. I have given several copies to peers. I hope this review helps you balance out your opinions before deciding for or against this book.
9 of 10 people found the following review helpful:
5.0 out of 5 stars
Complete and succinct discussion of PKI,
This review is from: Understanding the Public-Key Infrastructure: Concepts, Standards, and Deployment Considerations (Hardcover)
"Understanding Public-Key Infrastructure" is well written and is a terrific book. It is the most complete and succinct book available on the subject of PKI. Other books deal with various detailed aspects of Public-Key Infrastructure, but this particular book is the best available in forming a clear overall perspective of the subject area. A great book for managers or technical readers which are looking for good, solid information but which don't want excessive details. I enjoyed the book, and feel the authors did an excellent job in describing the subject of PKI. The approach taken in this book is useful, not hyped. The coverage is broad and extensive but not encumbered by inordinate detail about algorithms and protocols. Explanations are clear and concise. I am pleased to recommend the book to anyone looking for a very good, succinct but thorough treatment of the subject area.
25 of 32 people found the following review helpful:
1.0 out of 5 stars
Nearly worthless,
By A Customer
This review is from: Understanding PKI: Concepts, Standards, and Deployment Considerations (2nd Edition) (Hardcover)
I bought this book because of the excellent reviews it got. However upon reading this I can't see any justification for these reviews. First of all it is very high level; I mean appropriate for your manager's, manager's manager maybe. This book is all about fawning over Diffie Hellman and philosophizing about how pki should be used etc. There is no technical information in this book, no code, no flow charts, no diagrams, no data structures. It doesn't even explain how pki is applied, for example to ssl. All the real information in this book could have been condenced to a few pages. I really needed this book to be good and it was not. Look if you want to go to a cocktail party and impress someone with no technical exposure then maybe this is your book. Otherwise there must be better choices.
21 of 27 people found the following review helpful:
5.0 out of 5 stars
Excellent PKI reference,
This review is from: Understanding the Public-Key Infrastructure: Concepts, Standards, and Deployment Considerations (Hardcover)
Pundits, the press, and other elements of the cognoscenti invariably attempt to make every year "the year of" something. For whatever else 2000 might be the year of, many technology periodicals have proclaimed it the year of public key infrastructure, or PKI. Didn't know that? Many people don't even understand the term, which is neither descriptive nor intuitive.In the physical world, trust is built through a complex web of social, legal, national, international, and business transactions that can take years or decades to develop. Items such as driver's licenses or passports create trust, because they are underwritten by the issuing authority. Unfortunately, the same level of trust is much harder to implement in the electronic world. One way to do so is via PKI. As an example, one can use a passport for identification in the physical world. The cyberspace equivalent could be a digital certificate for authentication. Similarly, ink-based signatures are used on binding contracts. In the digital world, digital signatures are used to ensure a concept called nonrepudiation, by which the party involved in a process cannot later deny that he or she took part in it. Understanding Public-Key Infrastructure is a guide to the effective deployment of PKI. The authors do a great job of covering the critical areas of PKI, including certification, operational considerations, standardization efforts, and deployment issues. The authors deserve credit for producing a guide that avoids getting bogged down in minutiae and other technical details. Their approach is to cover a topic at a broad level, delve into some detail, then refer the reader to an appropriate source for particulars. They are also obsessively vendor-neutral. This is an important book for those who expect to do e-commerce. Because whether anyone realizes it or not, this is the year of the PKI. This review of mine originally appears at http://www.securitymanagement.com/library/000859.html
9 of 11 people found the following review helpful:
5.0 out of 5 stars
Wonderful overview,
By
This review is from: Understanding the Public-Key Infrastructure: Concepts, Standards, and Deployment Considerations (Hardcover)
This is an excellent summary and overview of a difficult topic. It simplifies and explains without removing important detail or obscuring unsolved problems. It's an excellent book for technical people new to PKI, or for manager/business types who need a deeper understanding of the technology. I bought extra copies to hand out at work to people who needed to know this stuff.
6 of 9 people found the following review helpful:
5.0 out of 5 stars
PKI book that makes sense,
By david mckee (Huntsville,Al) - See all my reviews
This review is from: Understanding the Public-Key Infrastructure: Concepts, Standards, and Deployment Considerations (Hardcover)
Carlisle and his co authors have written a book that will allow the Security practioner, as well as the Security techie, to understand the basics of PKI Infrastrucutres. I had the opportunity to meet Carlisle at the Secure Summit this past Jan., and we had a very interesting dicussion about this book, how he came to write it, etc. Just sorry I didn't have my copy for an autograph. I have ordered my 2d copy, sent the first copy I bought to a buddy who needed to understand the innnards of PKI. This book is an easy read but loaded with good data on PKI. I would recommend this book to managers who need to understand PKI but don't need to do the technical pieces. For my part, I am Security professional with over 30 years experience.
2 of 3 people found the following review helpful:
5.0 out of 5 stars
Terrific explanation of PKI,
By
Amazon Verified Purchase(What's this?)
This review is from: Understanding PKI: Concepts, Standards, and Deployment Considerations (2nd Edition) (Hardcover)
This book does a terrific job of explaining how various applications can use PKI and what PKI requires from an infrastructure stapoint. Part III, Deployment COnsiderations, is exceptionally good at how can PKI can be used from a practical standpoint. Strikes just the right balance between theoretical and practical. Technical detail was totally sufficient for me and included everything up to but not including a discussion of the actual mathematics behind public key encyrption.
Highly recommended!!
2.0 out of 5 stars
Do you really need this book ?,
This review is from: Understanding PKI: Concepts, Standards, and Deployment Considerations (paperback) (2nd Edition) (Paperback)
I think this is the real question you should answer before to buy this book. If you are an IT project Manager in the security space, or a pre-sale guy used to join and drive round-tables and chat sessions where the security is the main topic, or even you you are used to hi-level discuss with CTOs around their security infrastructure, then this book might be useful for you. This is a very hi-level overview of the concepts that sits behind a Public Key Infrastructure, where "infrastructure" is the main point. There's nothing technical here inside, it's really focused on the concepts of a PKI, providing you all the terminology, the various different components and topics that a PKI includes and that you need to know, evaluate and choose when approaching a PKI implementation, but you will not find anything about the implementation itself, nothing that will explain how all these wonderful PKI theory and concepts are applied to the real world using the current technologies. I probably did a mistake myself when I bought this book, but I was at least expecting a bit more about SSL, TLS and similar protocols that are a fundamental element of any secure transaction and therefore of any security infrastructure, but I was wrong. Even accepted that this was something different then I expected, I didn't even find the writing style too good, being honest, I don't know how many times the authors use the expression "that is," to clarify a statement, but definitely too many, and in general I found the way used to describe the concepts to make this matter even more boring than normally is.
|
|
Most Helpful First | Newest First
|
|
Understanding the Public-Key Infrastructure: Concepts, Standards, and Deployment Considerations by Carlisle Adams (Hardcover - November 12, 1999)
Used & New from: $0.01
| ||