PKI for improved cybersecurity in NATO Partner countries Software Arsen Hayrapetyan, ArmeSFo CA.

Slides:



Advertisements
Similar presentations
Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
Advertisements

Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien.
1 ASGCCA Self-Audit Report APGridPMA Jinny Chien March
CNIC Grid CA/SDG CA Self Audit Kejun (Kevin) Dong Computer Network Information Center (CNIC) Chinese Academy of Sciences APGridPMA F2F.
Deploying and Managing Active Directory Certificate Services
Identity Standards (Federal Bridge Certification Authority – Certificate Lifecycle) Oct,
PKI Administration Using EJBCA and OpenCA
DESIGNING A PUBLIC KEY INFRASTRUCTURE
1 REUNA Certificate Authority Juan Carlos Martínez REUNA Chile Rio de Janeiro,27/03/2006, F2F meeting, TAGPMA.
Chapter 9: Using and Managing Keys Security+ Guide to Network Security Fundamentals Second Edition.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
CS470, A.SelcukPKI1 Public Key Infrastructures CS 470 Introduction to Applied Cryptography Instructor: Ali Aydin Selcuk.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Configuring Active Directory Certificate Services Lesson 13.
NASA PKI for PKI FORUM Presenters: Paul Ma, NASA-Ames Research Center
UNAMgrid CA Juan Carlos Guel UNAM, México. Alejandro Núñez UNAM, México. Israel Becerril UNAM, México. DGSCA UNAM 31/08/06.
Tweaking the Certificate Lifecycle for the UK eScience CA John Kewley NGS Support Centre Manager & Service Manager for the UK e-Science CA
NECTEC-GOC CA APGrid PMA face-to-face meeting. October, Sornthep Vannarat National Electronics and Computer Technology Center, Thailand.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Chapter 9: Using and Managing Keys Security+ Guide to Network Security Fundamentals Second Edition.
Configuring Directory Certificate Services Lesson 13.
DataGrid WP6 CA meeting, CERN, 12 December 2002 IISAS Certification Authority Jan Astalos Department of Parallel and Distributed Computing Institute of.
XMPP Concrete Implementation Updates: 1. Why XMPP 2 »XMPP protocol provides capabilities that allows realization of the NHIN Direct. Simple – Built on.
March 27, 2006TAGPMA - Rio de Janeiro1 Short Lived Credential Services Profile Tony J. Genovese The Americas Grid PMA DOEGridsATF/ESnet/LBNL.
National Institute of Advanced Industrial Science and Technology Brief status report of AIST GRID CA APGridPMA Singapore September 16 Yoshio.
NECTEC-GOC CA Self Audit 7 th APGrid PMA Face-to-Face meeting March 8 th, 2010 Large-Scale Simulation Research Laboratory Sornthep Vannarat Large-Scale.
Maintaining Network Health. Active Directory Certificate Services Public Key Infrastructure (PKI) Provides assurance that you are communicating with the.
Module 9: Designing Public Key Infrastructure in Windows Server 2008.
IHEP Grid CA Status Report Wei F2F Meeting 8 Mar Computing Centre, IHEP,CAS,China.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Profile for Portal-based Credential Services (POCS) Yoshio Tanaka International Grid Trust Federation APGrid PMA AIST.
Sam Morrison APAC CA – APGridPMA - ISGC2010 APAC CA Self Audit and status update Sam Morrison ARCS.
HEPSYSMAN UCL, 26 Nov 2002Jens G Jensen, CLRC/RAL UK e-Science Certification Authority Status and Deployment.
National Computational Science National Center for Supercomputing Applications National Computational Science Credential Management in the Grid Security.
KISTI Grid CA Operation KISTI Supercomputing Center Sangwan Kim, Soonwook Hwang CA Operators Contact: Jan. 8, 2007.
CertWizard: a New Certificate Tool for the UK NGI User Community John Kewley ( ), Jens Jensen, David Meredith and Akay Okcun 16/11/20151EGI.
Who’s watching your network The Certificate Authority In a Public Key Infrastructure, the CA component is responsible for issuing certificates. A certificate.
Jens G Jensen UK e-Science Alternative CA software Jens G Jensen UK e-Science CA Rutherford Appleton Laboratory.
Grid Canada Certificate Authority Darcy Quesnel
Pkiuniversity.com. Alice Bob Honest Abe’s CA Simple PKI hierarchy.
Creating and Managing Digital Certificates Chapter Eleven.
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
APGrid PMA face-to-face meeting, 9/16/2008 PRAGMA-UCSD CA Team Pacific Rim Application and Grid Middleware Assembly
Community PKIs Initiatives Updates TF-EMC2 Meeting Loughborough, UK 6-7 May, 2009 Licia Florio, TERENA
1 Public Key Infrastructure Dr. Rocky K. C. Chang 25 February, 2002.
8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK
MICS Authentication Profile Maintenance & Update Presented for review and discussion to the TAGPMA On 1May09 by Marg Murray.
EMI is partially funded by the European Commission under Grant Agreement RI Common Authentication Library Daniel Kouril, for the CaNL PT EGI CF.
NIIF CA Status Update and Self-Audit Results 15 th EUGridPMA meeting Nicosia Tamás Máray NIIF Institute.
1 Progress of SAGrid CA Presenter: Tarirai Chani.
Baltic Grid Certification Authority 15th EUGridPMA, January 28th 2009, Nicosia1 Self-audit Hardi Teder EENet.
TR-GRID CA Self-Auditing Results and Status Update EUGridPMA Meeting September 12-14, 2011 Marrakesh Feyza Eryol, Onur Temizsoylu TUBITAK-ULAKBIM
HKU Computer Centre Grid Certificate Authority Status Update Lilian Chan IT Services, The University of Hong Kong APGrid.
FP6−2004−Infrastructures−6-SSA [ Empowering e Science across the Mediterranean ] Rome, Tutorial for Certification Authority Managers,
Summary of Poznan EUGridPMA32 September EUGridPMA Poznan 2014 meeting – 2 David Groep – Welcome back at PSNC.
18 th EUGridPMA, Dublin / SRCE CA Self Audit SRCE CA Self Audit Emir Imamagić SRCE Croatia.
NECTEC-GOC CA A Brief Status Report 13 th APGrid PMA Face-to-Face meeting March 24 th, 2014 Large-Scale Simulation Research Laboratory Information Communications.
UK e-Science Certification Authority Self Audit Jens Jensen EUGridPMA meeting, Berlin.
Jens' obligatory soap box Can't be a PMA without a SoapBox A random collection of Soapy things Nicosia, Jan 2009.
UGRID CA Self-audit report Sergii Stirenko 21 st EUGRIDPMA Meeting Utrecht 24 January 2011.
HellasGrid CA self Audit. In general We do operations well Our policy documents need work (mostly to make the text clearer in a few sections) 2.
News from EUGridPMA EGI OMB, 22 Jan 2013 David Kelsey (STFC) Using notes from David Groep 22/01/20131EUGridPMA News.
29 th EUGridPMA meeting, September 2013, Bucharest AEGIS Certification Authority Dušan Radovanović University of Belgrade Computer Centre.
AEGIS Certification Authority
UGRID CA Sergii Stirenko, Oleg Alienin
Tweaking the Certificate Lifecycle for the UK eScience CA
Southern and Eastern Mediterranean
MaGrid CA Self audit and update
Emir Imamagić University Computing Centre (Srce)
BG.ACAD CA Self-audit report 2018
Presentation transcript:

PKI for improved cybersecurity in NATO Partner countries Software Arsen Hayrapetyan, ArmeSFo CA

18th EUGridPMA meeting, Dublin, Ireland, Jan Beginning of the project Idea of the project originated in 2007 by Ara Grigoryan, ArmeSFo CA Manager Presented at NATO Information and Communication Security Panel meeting in September 2007, Istanbul, Turkey Presented and discussed at 12 th EUGridPMA meeting in Amsterdam, The Netherlands, in January 2008 Received the approval and support of the PMA Applied for NATO collaborative linkage grant (CLG) in January 2008 CLG awarded in June 2008 Principal investigators and co-directors from NATO country: Jens Jensen (UK) from NATO partner country: Arsen Hayrapetyan (Armenia)

18th EUGridPMA meeting, Dublin, Ireland, Jan Goals of the project Provide target countries of the project (next slide) with tools for deploying PKI as means of improving the level of cybersecurity Establishing CAs Contribute to their integration into EUGridPMA To achieve these goals, the target countries should be provided with: Software for CA operations Policy guidelines

18th EUGridPMA meeting, Dublin, Ireland, Jan Target countries Countries along the Virtual Silk Highway (large networking project under NATO funding since 1994): Armenia, Azerbaijan, Georgia, Kazakhstan, Kyrgyz Republic, Tajikistan, Turkmenistan, Uzbekistan, Afghanistan Mediterranean Dialogue countries Algeria, Egypt, Israel, Jordan, Mauritania, Morocco, Tunisia -- do have CA -- do not have CA

18th EUGridPMA meeting, Dublin, Ireland, Jan Software requirements The software should allow Easy deployment on both Windows and Linux Support for all CA operations required by off-line classic CA Easy configuration of CA root and EE certificates in accordance with IGTF standards Provide default configuration conforming to Grid Certificate Profile (GCP) Adding new features seamlessly and without extra effort (posed by the software itself)

18th EUGridPMA meeting, Dublin, Ireland, Jan Software choice Initially planned to use OpenCA and adapt it to IGTF standards Abandoned the idea of using OpenCA. Instead, own software is being developed. The software will be owned by EUGridPMA

18th EUGridPMA meeting, Dublin, Ireland, Jan Advantages of using own soft (1) Own software is designed with off-line CAs and IGTF standards in mind. It does not have OpenCA’s extra (and potentially confusing or not-easy-to-configure) features The software is being coded in PHP. Many PMA experts are experienced in PHP (more than in perl?), so they could contribute easily to the future versions of software The software is modular, it has the “core” part and uses SOAP to communicate with other modules performing specific tasks (signing CSR, issuing CRL, etc.). Specific modules can be implemented in any language supporting SOAP communications

18th EUGridPMA meeting, Dublin, Ireland, Jan Advantages of using own soft (2) Software is IGTF standards-centered. It should allow issuing GCP-compliant certificates, as well as support mechanisms for updating the configuration to match possible changes of GCP Software will be owned by PMA and can be modified or branched at any time without depending on third-party owner

18th EUGridPMA meeting, Dublin, Ireland, Jan What kind of CAs is the software for? We expect target countries to be off-line CAs with one or more RAs, with no subordinate CAs. The software will provide interfaces for CA operations RA operations User operations

18th EUGridPMA meeting, Dublin, Ireland, Jan Supported configuration The software is meant to be installed on two machines: offline (CA offline machine), for CA operations like signing certificates, issuing CRLs, etc. online interface for users to request, renew and revoke their certificates, etc. interface for RAs, to approve or reject certificates, etc. Interface for CA to publish CP/CPS, CRLs, send automatic notifications, etc.

18th EUGridPMA meeting, Dublin, Ireland, Jan CA operations (offline) Support for following operations: Generation of CA key pair and certificate Issuing EE certificates (X.509 v3) Revoking certificates Issuing CRLs (v1 & v2) Configuring certificate profiles Backup operations (making backup, CA recovery using backup, etc.)

18th EUGridPMA meeting, Dublin, Ireland, Jan CA operations (online) Support for following operations: Publishing CP/CPS, CRLs, other public info Sending automatic notifications about certificate expiration to certificate holders DB lookup operations

18th EUGridPMA meeting, Dublin, Ireland, Jan RA operations Support for following operations Approving or rejecting requests Requesting revocation of certificates DB lookup operations

18th EUGridPMA meeting, Dublin, Ireland, Jan User operations Requesting certificates Renewing certificates Requesting revocation of own certificate Verifying status of own certificate

18th EUGridPMA meeting, Dublin, Ireland, Jan GCP compliancy Support for a default EE certificate profile compliant with GCP Support for importing the profile (the form is not decided yet, e.g. XML) managed centrally (e.g. EUGridPMA repository) Application of GCP changes quickly Staying up-to-date with IGTF requirements to EE certificate profile

18th EUGridPMA meeting, Dublin, Ireland, Jan Comments, suggestions…?