International Grid Trust Federation Session GGF 19 Chapel Hill, NC, USA Thursday, Feb. 1 2007 CAOPS-WG session #1.

Slides:



Advertisements
Similar presentations
Resource WG Breakout. Agenda How we will support/develop data grid testbed and possible applications (1 st day) –Introduction of Gfarm (Osamu) –Introduction.
Advertisements

National Institute of Advanced Industrial Science and Technology Asia Pacific Grid PMA Yoshio Tanaka APGrid PMA, Chair Grid Technology Research Center,
Demonstrations at PRAGMA demos are nominated by WG chairs Did not call for demos. We will select the best demo(s) Criteria is under discussion. Notes.
Resource/data WG Summary Yoshio Tanaka Mason Katz.
2 nd APGrid PMA F2F Meeting Osaka University Convention Center October 15 09: :20 # Participants: 26.
Resource WG Summary Mason Katz, Yoshio Tanaka. Next generation resources on PRAGMA Status – Next generation resource (VM-based) in PRAGMA by UCSD (proof.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks MyProxy and EGEE Ludek Matyska and Daniel.
Usage of PGP in TACAR 19th OGF Meeting Chapel Hill, USA February 1, 2007 Licia Florio Project Development Officer
© 2006 Open Grid Forum OGF20 LoA-RG Monday 11:00am Charter Suite 4 Chairs: Ning Zhang and Yoshio Tanaka.
Updates of the APGrid PMA Catania March 3, 2009 Yoshio Tanaka APGridPMA Chair, AIST, Japan.
International Grid Trust Federation Session GGF 20 Manchester, UK Wednesday, May CAOPS-WG session #2.
© 2007 Open Grid Forum CAOPS-WG Christos Kanellopoulos - Yoshio Tanaka Security Area coordination & outreach OGF25, Catania March 2 nd – 3 rd, 2009.
Grid Computing in Higher Education (Scott Rea) EDUCAUSE PKI Deployment Forum Madison, WI - April 15, 2008.
National Institute of Advanced Industrial Science and Technology Proposals for auditing Yoshio Tanaka Grid Technology Research.
4 th APGrid PMA F2F Meeting Academia Sinica, Taipei, Taiwan April 8, 2008 Agendahttp:// Call for note takers!
National Institute of Advanced Industrial Science and Technology Status and plans of the APGrid PMA Yoshio Tanaka Grid Technology.
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
National Center for Supercomputing Applications Integrating MyProxy with Site Authentication Jim Basney Senior Research Scientist National Center for Supercomputing.
Levels of Assurance OGF Activity Michael Helm ESnet/LBNL 27 Feb 2007.
2 nd APGrid PMA F2F Meeting Osaka University Convention Center October 15 Wireless LAN SSID: PRAGMA11 Wep key: PRAGMA11JAPAN.
National Institute of Advanced Industrial Science and Technology Auditing, auditing template and experiences on being audited Yoshio Tanaka
TeraGrid ’06 National Center for Supercomputing Applications Managing Credentials on the TeraGrid with MyProxy Jim Basney.
How Grid Security works in GEO Sciences N. Yamamoto, Y. Tanaka, I. Kojima, S. Sekiguchi AIST Oct. 28, 2009.
Updates of APGrid PMA 22 June, Members (15 + 1) 15 Accredited CAs AIST (JP) APAC (AU) ASGC (TW) CNIC (CN), SDG IGCA (IN) IHEP (CN) KEK (JP) KISTI.
National Institute of Advanced Industrial Science and Technology Self-audit report of AIST GRID CA Yoshio Tanaka Information.
National Institute of Advanced Industrial Science and Technology Updates of the APGrid PMA Yoshio Tanaka Grid Technology Research.
GEON meeting - May 22, 2006 GAMA 2.0 Features and Status Kurt Mueller SDSC.
March 27, 2006TAGPMA - Rio de Janeiro1 Short Lived Credential Services Profile Tony J. Genovese The Americas Grid PMA DOEGridsATF/ESnet/LBNL.
PRAGMA 17 – PRAGMA 18 Resources Group. PRAGMA Grid 28 institutions in 17 countries/regions, 22 compute sites (+ 7 site in preparation) UZH Switzerland.
NECTEC-GOC CA Self Audit 7 th APGrid PMA Face-to-Face meeting March 8 th, 2010 Large-Scale Simulation Research Laboratory Sornthep Vannarat Large-Scale.
Ning Zhang, the University of Manchester, UK David Groep, National Institute for Nuclear and High Energy Physics, NL Blair Dillaway, OGF Security Area.
Profile for Portal-based Credential Services (POCS) Yoshio Tanaka International Grid Trust Federation APGrid PMA AIST.
All Hands Meeting 2005 BIRN Portal Architecture: Security Jana Nguyen
TAGPMA & the Bridge WG (Scott Rea – Dartmouth College) Internet2 Member Meeting, Dec 2006 PKI Activities and Applications Update - Chicago, IL.
National Institute of Advanced Industrial Science and Technology Some topics from the OGF20 and the EUGrid PMA F2F Meeting Yoshio Tanaka Grid Technology.
SC2008 (11/19/2008) Resources Group Pacific Rim Application and Grid Middleware Assembly Reports.
International Grid Trust Federation Session GGF 20 Manchester, UK Wednesday, May CAOPS-WG session #2.
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
National Institute of Advanced Industrial Science and Technology Updates of the APGrid PMA Yoshio Tanaka APGrid PMA, Chair Grid Technology Research Center,
National Institute of Advanced Industrial Science and Technology GGF12 Workshop on Operational Security for the Grid Cross-site authentication and access.
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
Opening Remarks and Updates of the APGrid PMA 5 th APGridPMA September 16, 2008 Yoshio Tanaka APGridPMA Chair, AIST, Japan.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
Community PKIs Initiatives Updates TF-EMC2 Meeting Loughborough, UK 6-7 May, 2009 Licia Florio, TERENA
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
0 NAREGI CA Status Report APGrid F2F meeting in Singapore June 4, 2007 Rumiko Masuko.
Update of APGridPMA APGridPMA Meeting Academia Sinica, Taiwan 22 March,
APGridPMA Update Eric Yen APGridPMA August, 2014.
Summary of Poznan EUGridPMA32 September EUGridPMA Poznan 2014 meeting – 2 David Groep – Welcome back at PSNC.
Security Bob Cowles
A Study of Certification Authority Integration Model in a PKI Trust Federation on Distributed Infrastructures for Academic Research Eisaku SAKANE, Takeshi.
Update of APGridPMA Eric Yen 25 th EUGridPMA & IGTF All Hands Meeting KIT, Germany 7 May, 2012.
APGridPMA Update Eric Yen 35 th Amsterdam, NL September 7, 2015.
News from EUGridPMA EGI OMB, 22 Jan 2013 David Kelsey (STFC) Using notes from David Groep 22/01/20131EUGridPMA News.
Updates of APGrid PMA 18 th EUGridPMA Meeting 18 th EUGridPMA Meeting 18 January, 2010 Eric Yen ASGCCA Taiwan.
29 th EUGridPMA meeting, September 2013, Bucharest AEGIS Certification Authority Dušan Radovanović University of Belgrade Computer Centre.
PRACE user authentication and vetting Vincent RIBAILLIER, 29 th EUGridPMA meeting, Bucharest, September 9 th, 2013.
Agenda Status of CAOPS-WG – Darcy (1’) Status of Documents – Darcy (5’) OCSP Requirements for OCSP – Olle (20’) Authentication Profiles – Tony (20’) Auditing.
Levels of Assurance OGF Activity
JRA3 Introduction Åke Edlund EGEE Security Head
Classic X.509 AP updates (v4.1)
Updates of the APGrid PMA
Grids & PKI: TAGPMA & Bridges (Scott Rea – Dartmouth College) Internet2 Member Meeting, Dec 2006 PKI Implementers Workshop - Chicago, IL.
Guidelines for auditing Grid CAs
NAREGI-CA Development of NAREGI-CA NAREGI-CA Software CP/CPS Audit
The IGTF Charter Name uniqueness throughout the IGTF is anchored in the Charter Current Charter assigns a namespace to an Authority, implying that the.
EUGridPMA 41 and IGTF All-Hands Meeting
Emir Imamagić University Computing Centre (Srce)
Bill Yau HKU Grid Certificate Authority (HKU Grid CA) Self Audit & Status Report Bill Yau
BG.ACAD CA Self-audit report 2018
Presentation transcript:

International Grid Trust Federation Session GGF 19 Chapel Hill, NC, USA Thursday, Feb CAOPS-WG session #1

Agenda Updates from regional PMAs (5”) –APGrid PMA (Yoshio) –EUGrid PMA (David) –TAGPMA (Darcy) IGTF Key Registry and TACAR (20”) –Background (Yoshio) –TACAR experiences (Licia) Authentication Profiles –Classic AP (David) (10”) –Member Integrated Credential Services AP (Darcy?) (10”) –Portal-based Credential Services AP (Yoshio) (10”) Levels of Assurance in certs (15”) –Report from the LoA BOF (Yoshio) What exactly are Host/Service certificates? (Mike) (15”)

Agenda Updates from regional PMAs (5”) –APGrid PMA (Yoshio) –EUGrid PMA (David) –TAGPMA (Darcy) IGTF Key Registry and TACAR (20”) –Background (Yoshio) –TACAR experiences (Licia) Authentication Profiles –Classic AP (David) (10”) –Member Integrated Credential Services AP (Darcy?) (10”) –Portal-based Credential Services AP (Yoshio) (10”) Levels of Assurance in certs (15”) –Report from the LoA BOF (Yoshio) What exactly are Host/Service certificates? (Mike) (15”)

IGTF Key Registry Proposal by Mike –Should we establish a registry of certs (a key registry) for members/operators? Agree? How? –Can we take advantage of Milan’s key-ring? –Can we borrow TACAR’s efforts? Where? See Licia’s experience on TACAR

Agenda Updates from regional PMAs (5”) –APGrid PMA (Yoshio) –EUGrid PMA (David) –TAGPMA (Darcy) IGTF Key Registry and TACAR (20”) –Background (Yoshio) –TACAR experiences (Licia) Authentication Profiles –Classic AP (David) (10”) –Member Integrated Credential Services AP (Darcy?) (10”) –Portal-based Credential Services AP (Yoshio) (10”) Levels of Assurance in certs (15”) –Report from the LoA BOF (Yoshio) What exactly are Host/Service certificates? (Mike) (15”)

Agenda Updates from regional PMAs (5”) –APGrid PMA (Yoshio) –EUGrid PMA (David) –TAGPMA (Darcy) IGTF Key Registry and TACAR (20”) –Background (Yoshio) –TACAR experiences (Licia) Authentication Profiles –Classic AP (David) (10”) –Member Integrated Credential Services AP (Darcy?) (10”) –Portal-based Credential Services AP (Yoshio) (10”) Levels of Assurance in certs (15”) –Report from the LoA BOF (Yoshio) What exactly are Host/Service certificates? (Mike) (15”)

Reports from the LoA BOF Date: Jan 31, 14:00-15:30 #participants: 18 Ning Zhang (Manchester Univ.) lead the discussion. Summary –OGSA-AuthN WG: conveyance of LoA in AuthN in protocols, consumption. –CAOPs: CP/CPS guidance –IGTF: Defining the identity levels. –LoA WG (new): criteria that go into LoA assessing & risk vs gap –Authors: MH identification of the gaps between NIST&like standards and grid usage of Ids and assersion –Authors: MJ, NZ –Use case gathering: MH Co-chairs: –Ming Zhang, Yoshio Tanaka

What’s the next step? Todo: Define the identity levels. What should we do before the criteria document will be available? –Survey other definitions (NIST, etc.)?

Agenda Updates from regional PMAs (5”) –APGrid PMA (Yoshio) –EUGrid PMA (David) –TAGPMA (Darcy) IGTF Key Registry and TACAR (20”) –Background (Yoshio) –TACAR experiences (Licia) Authentication Profiles –Classic AP (David) (10”) –Member Integrated Credential Services AP (Darcy?) (10”) –Portal-based Credential Services AP (Yoshio) (10”) Levels of Assurance in certs (15”) –Report from the LoA BOF (Yoshio) What exactly are Host/Service certificates? (Mike) (15”)

Updates of the APGrid PMA OGF19 IGTF Yoshio Tanaka

Events since OGF18 F2F October 15 th, in OsakaAudit KISTI CA (September) IGTF CA distribution available from the APGrid PMA web site (mirror of EUGrid PMA web site).

2 nd APGrid PMA F2F Meeting Date: October 15 th Place: Osaka, Japan Participants: 26 Co-located with PRAGMA 11 Workshop

Agenda of the F2F meeting 09: :15 Welcome Shinji Shimojo 09: :45 Status Updates All CAs 09: :30 Recap of PMA/IGTF Yoshio Tanaka 11: :45 Accreditation NECTEC GOC CA 11: :30 In Depth Report KISTI Grid CA 13: :15 Invited Talk Yasuo Okabe 14: :20 Open Discussions - Procedures for Incident Response - Procedures for Incident Response - Grid Certificate Profile - Grid Certificate Profile - Classic Authentication Profile - Classic Authentication Profile - Short Lived Credential Services AP - Short Lived Credential Services AP - Member Integrated Credential Services AP - Member Integrated Credential Services AP

Highlights of the meeting NECTEC GOC CA (Thailand) was accredited as an IGTF-Classic compliant Certificate Authority. Agreed that KISTI Grid CA will be removed from a list of accredited CAs due to some fundamental problems Yoshio reported the results of auditing Sangwan gave a presentation on how to improve their operation No concrete procedures, timeline were presented We decided to remove KISTI CA by voting All members agreed Recommended to launch a new CA (re-accreditation is required). Approved the proposed Classic AP version 4.1-b4 under the two conditions “ keyUsage of CA Cert. MUST be marked as critical ” “ MUST ” should be drop-off to “ SHOULD ”. Retention period of audit log In PRAGMA WS Discussions on writing a new Authentication Profile appropriate for Portal architecture (e.g. GAMA, PURSE).

Members (13 + 4) 9 Accredited CAs In operation AIST (Japan) APAC (Australia) ASGCC (Taiwan) CNIC (China) IHEP (China) KEK (Japan) NAREGI (Japan) NECTEC (Thailand) Will be in operation NCHC (Taiwan) 1 CA under review NGO (Singapore) Will be re-accredited KISTI (Korea)Planning PRAGMA (USA) ThaiGrid (Thailand) General membership Osaka U. (Japan) U. Hong Kong (China) U. Hyderabad (India) USM (Malaysia)

Portal-based Credential Services (tentative) Profile Yoshio Tanaka International Grid Trust Federation APGrid PMA AIST

Motivation There are many Grid project which provide portal-based user registration system. GEON Grid, Earth System Grid, etc. These portals issue certificates for users using credential management systems such as GAMA and PURSE, but there is no appropriate profile recognized by IGTF. Key pair is generated not at the client side but at the centralized server. Users do not need to take care about their certificates and private keys. Method of identity vetting can be flexible, but these portals are not doing strict vetting. They use online CA without HSM. Furthermore, some portals do not have a dedicated CA server. No CP/CPS. …

Motivation (cont ’ d) Some projects are going to collaborate with the other projects. Need trust federation. PRAGMA is planning to develop a PRAGMA Grid portal which is a single entry point to various PRAGMA applications (e.g. bio, geo science, telescience, etc.). My interest is to define IGTF profile for portal-based credential services to classify their assurance level.

Portal server 2 GAMA architecture Portal server 1 GAMA server CACL MyProxyCAS AXIS Web Services wrapper … Servlet container import user retrieve credential Stand-alone applications retrieve credential DB gridportlets Java keystore gama GridSphere Servlet container create user

PURSE (Portal-based User Registration Service)

Issues need to be considered (1/2) Key generation Not at the client ’ s side but at the central server. Login password for the portal is used as a ass phrase of the private key CA operational requirements Online, but may not use HSM. CA signing machine may not be a dedicated machine. PURSE running the CA signing and MyProxy on the same machine. Identity Vetting GEON uses address as a source of identity. ESG requests users to put information about PI. But I could obtain a test account (and my certificate) on ESG by verification. I could not see my certificate … Appropriate ID vetting may differ between projects. How can we define in the profile?

Issues need to be considered (2/2) Lifetime of EE cert. Should depend on the identity vetting. If identity vetting is time consuming, it should be long lived. Otherwise, it should be short-lived.Revocation May not be necessary for short-lived certs. Publication and repository Current portals do not provide information about the CA (CP/CPS, CA cert, CRL, etc.) These are completely hidden from users. These must be available as the first step of trust federation. Probably more issues …