Presentation is loading. Please wait.

Presentation is loading. Please wait.

Your university or experiment logo here IGTF CP/CPS Template Working Party Update II Jens Jensen EU GridPMA Lisbon 6-8 Oct 2008.

Similar presentations


Presentation on theme: "Your university or experiment logo here IGTF CP/CPS Template Working Party Update II Jens Jensen EU GridPMA Lisbon 6-8 Oct 2008."— Presentation transcript:

1 Your university or experiment logo here IGTF CP/CPS Template Working Party Update II Jens Jensen EU GridPMA Lisbon 6-8 Oct 2008

2 6-8 Oct 2008 2 Overview Overview (this page) ‏ Review of presentation from OGF –Apologies to people who already saw it –More meant for a general audience –Easily recognised, using NGS template New stuff since OGF –Easily recognised, uses GridPP template –More meant for CA managers and suchlike –(Confused? – stupid limitations of OpenOffice) ‏ The document itself Next steps

3 6-8 Oct 2008 3 Purpose Speed up accreditation of new CAs –Too much bad stuff gets copied around –Not enough good stuff gets copied around Known good stuff – can automate more stuff IGTF-blessed, documenting best practice Enable existing CAs to change –You'd do this only if there are benefits –(Or the PMA orders you to use it!) ‏ –Use this to improve existing Template

4 Background Expression of interest Reviewers assigned ReviewResponse Membership This is the simplified version! TAGPMA have a more detailed version created/edited by J Marsteller (PSC)‏

5 Why? ReviewResponse This part can take many iterations (10 is not unheard of)‏ Process can take years ! Reviewers comments not addressed CA manager needs several iterations Users wait for their certificates

6 Aims Develop template and “safe” text –Cloning is done all the time –Often bad stuff is cloned, too Express IGTF policy Easier to write CP –For old hands, easier to convert to 3647, too!

7 Aims Fewer errors, contradictions Quicker reviews Advanced goals: –Enable review checklist (reviewer must check) and comments (manager must address)‏

8 Aims Maintenance of IGTF-compliant CP/CPS –Update with new IGTF regulations? –(Not automatically of course!)‏ IGTF Template CA CP/CPS CA Manager Implementation Example: requirement for re-authentication to RA every N years

9 Status Template written in DocBook XML –Output to many formats –Somewhat limited markup?  –Needs XML editor  I used Emacs with nxml Follows RFC 3647

10 Experiences Use revisionflag to track changes (N Walsh)‏ –Sun tool to automatically update tags –changebars.xsl to view Define Meta-attrs (non-DocBook)? Optional/choice components –Implemented via attrs - or separate XML? –If separate, inspired by ASN.1?

11 Annotate Keep notes for: Document maintainers OGF and other publisher metadata CA Manager Reviewer Other PKI participant? Option: use DocBook tags

12 Experimental Note semantics not specified by DocBook - general annotation (3647 text?)‏ - suggestion to CA Manager - note for reviewer - suggestion to CA Manager/Reviewer - strong suggestion to Manager/Reviewer Rendering similar in XHTML Customise later? Rendering in WordML (Microsoft Word) limited?

13 Annotation flow IGTF Maintainers IGTF PMACA ManagerReviewer “Local” PKI participant Global PKI participant Document should enable communication - pass text/metadata - filters to avoid confusion

14 Experimental Really experimental stuff? –Adapt (selectively) semantic web tools and methods

15 Concerns No substitute for real understanding –Operational review and presentation at PMA will catch most non-understanding Too complex –Possibly, experience will tell All-in-one document –Provide/document translation tools

16 IPR Be careful about IPR and Copyright –Assign copyright to the OGF/IGTF? –Track “ownership” of contributions Clean(ish) room implementation? –Rewrite, or –Use existing text known to be written by contributor, or –Track original source of contribution if copied

17 Progress RFC 3647 converted to DocBook –Dropped the explanations but they could be added back in Experimental conversions checked Experimental annotations management –Can change how it’s done as long as it’s done consistently Profile from IGTF cert profile

18 Next steps Volunteer contributors to contribute text: –D O’Callaghan (TCD)‏ –D Groep (NIKHEF)‏ –M Helm (ESNET)‏ –J Jensen (RAL)‏ –V Rebello (UFF)‏ –M Sova (CESNET)‏ –H Teder (EENET)‏ –S Velichkevych (NTU-KPI Kiev)‏ –A Wäänänen (NBI)‏ Volunteer CAs to implement them! New or existing…

19 6-8 Oct 2008 19 Aspects of documentation (Currently) use “role” attribute to track “role” of text –igtf.ee.cl.minreq Documented in relevant section –igtf.ee.cl.cp ee = end entity issuing CA cl = classic profile –Subdivide into feature sections E.g. suspension, certificate modification, renewal, rekey Not using notes/warnings/cautions –But could convert Use “id” attribute to track original reference –But ensure unique in document –Need to build/stretch existing hierarchical roles –E.g. igtf.ee.cl.minreq.2.2.a

20 6-8 Oct 2008 20 Customising blessed text Built-in entities –Minor customisations of blessed text –Without un-blessing it –For things like CA name Enable or disable feature sets? –Conditional text –Experimental

21 6-8 Oct 2008 21 Writing and reviewing Distinguished added text and blessed text Default (empty) paras to “No stipulation.” Distinguish changes –Keep deleted text by maintaining revisions Ease of edit –Convert between DocBook and WordML Need Word “template” for header/footer? –Limited? –Highly experimental? Adapt existing XSLT for XHTML or WordML?

22 6-8 Oct 2008 22 Publishing document Draft → Final –Drop explanations, drop minreqs –Keep approved text and added text –Drop markup (or don't add it) ‏ E.g. run XSLT filters to drop minreq –Output as valid docbook –Then docbook can be converted to HTML


Download ppt "Your university or experiment logo here IGTF CP/CPS Template Working Party Update II Jens Jensen EU GridPMA Lisbon 6-8 Oct 2008."

Similar presentations


Ads by Google