OSG PKI RA Training Mine Altunay, Jim Basney OSG PKI Team October 1, 2012.

Slides:



Advertisements
Similar presentations
Help File For User Creation Click the “Course” button for Creating/Add User.
Advertisements

Using the UIM – A guide for Pharmacies. Creating a New User Ref to UIM helpsheet.
User Registration. Click on ‘Sign Up’ button. Enter Registration details and click on submit button.
Northwest Nazarene University introduces PDLearn The CPD’s web access course selection and registration system for students and instructors Affiliated.
Grid Computing Basics From the perspective of security or An Introduction to Certificates.
Steps to Recover Private Encryption Keys
This demonstration will help you understand and perform (Internet Explorer Users: Click Browse, then Full Screen, to enlarge your view of this presentation.)
SPOT Registration and Log in Quick Guide The SPOT quick guide is targeted to provide the three main community users, Contractor Company, Government Organization,
16.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
Summer School Certificates Diego Romano & Gilda Team.
HP Asset Hub Support through Service Central
This demonstration will help you understand and perform (Internet Explorer Users: Click Browse, then Full Screen, to enlarge your view of this presentation.)
OSG Area Coordinators Meeting Security Team Report Mine Altunay 01/29/2014.
Role of Account Management at ERCOT Market Participant Identity Management Overview (MPIM)
UNAMgrid CA Juan Carlos Guel UNAM, México. Alejandro Núñez UNAM, México. Israel Becerril UNAM, México. DGSCA UNAM 31/08/06.
OSG PKI Grid Admin (GA) Training Mine Altunay, Jim Basney OSG PKI Team October 8, 2012.
CILogon OSG CA Mine Altunay Jim Basney TAGPMA Meeting Pittsburgh May 27, 2015.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 12/21/2011.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 06/25/2014.
OSG RA plans Doug Olson, LBNL May Contents RA, agent, sponsor layout & OU=People use case Sample web form Agent Role GridAdmin Role Questions.
OSG Security Kevin Hill. Goals Operational Security – Identify software vulnerabilities – observing the practices of our VOs and sites, and sending alerts.
Blueprint Meeting Notes Feb 20, Feb 17, 2009 Authentication Infrastrusture Federation = {Institutes} U {CA} where both entities can be empty TODO1:
Evolution of the Open Science Grid Authentication Model Kevin Hill Fermilab OSG Security Team.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay OSG Security Officer.
PKI Activities at Virginia September 2000 Jim Jokl
Rob Quick OSG Operations Area Coordinator Manager High Throughput Computing Indiana University Integrating OSG Operational Services Rob Quick OSG Operations.
Training by the Office of Library and Information Services Contact for more information: karen.gardner- or
OSG Area Coordinators Meeting Security Team Report Mine Altunay 8/15/2012.
OSG PKI Contingency and Recovery Plans Mine Altunay, Von Welch October 16, 2012.
16 th Biennial FTA State Programs Meeting State Public Transit Partnerships Conference Washington, DC Keith Gates NTD Program Manager Office of Budget.
Who’s watching your network The Certificate Authority In a Public Key Infrastructure, the CA component is responsible for issuing certificates. A certificate.
LIGO's Evolving Certificate Authority and Account Management Needs Warren G. Anderson University of Wisconsin-Milwaukee LIGO Scientific Collaboration.
OSG RA, DOEGrids CA features Doug Olson, LBNL August 2006.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Partner Ready Portal: New Partner Registration Process
Last update 21/01/ :05 LCG 1Maria Dimou- cern-it-gd Current LCG User Registration, VO management and Authorisation Procedures VOMS workshop
OSG Area Coordinators Meeting Security Team Report Mine Altunay 02/13/2012.
8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK
Global Transaction Bank Deutsche Bank Investor Reporting Demo.
EGI-InSPIRE RI Grid Training for Power Users EGI-InSPIRE N G I A E G I S Grid Training for Power Users Institute of Physics Belgrade.
© 2015 Eaton. All Rights Reserved.. Supplier Registration and Access.
PKI Services for CYPRUS STOCK EXCHANGE Kostas Nousias.
NIMAC for Accessible Media Producers: February 2013 NIMAC 2.0 for AMPs.
X509 Web Authentication From the perspective of security or An Introduction to Certificates.
Trusted Organizations In the grid world one single CA usually covers a predefined geographic region or administrative domain: – Organization – Country.
OSG PKI Transition Impact on CMS. Impact on End User After March , DOEGrids CA will stop issuing or renewing certificates. If a user is entitled.
OSG Security: Updates on OSG CA & Federated Identities Mine Altunay, PhD OSG Security Team OSG AHM March 24, 2015.
Welcome We will wait a few minutes for participants to log on and call in. –Call in: –Pass code: *6 to mute your line #6 to.
B2access.eudat.eu B2ACCESS User Training How to register with B2ACCESS Version 1 February 2016 This work is licensed under the Creative Commons.
OSG PKI Transition Mine Altunay OSG Security Officer
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
EduBrite Training for Group Admins. Dashboard Reports Groups Enrolled courses More items under this menu.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 8/15/2012.
Certificate Security For Users Obtaining and Using Your Personal Certificate using the OSG PKI Kyle Gross – OSG Operations Support Lead Elizabeth Prout.
New OSG Virtual Organization Security Training OSG Security Team.
Kamdhenu Website is used to Add agent in Kamdhenu offer under Group head Pfiger Software Technologies Pvt. Ltd.
OSG PKI Transition: Status and Next Steps (and Lessons Learned) Von Welch OSG PKI Transition Lead Indiana University Center for Applied Cybersecurity Research.
Creating a new Central Data Exchange (CDX) Account (to access NetDMR)
Broker training for Callidus Cloud EnvisionRxPlus for 2018
OSG Security Kevin Hill.
Transfer Students Between Districts
01 Registration & My Profile
Registration Comba FC Teams.
CRC exercises Not happy with the way the document for testbed architecture is progressing More a collection of contributions from the mware groups rather.
Advanced Invitations.
Creating a new Central Data Exchange (CDX) Account (to access NetDMR)
KELLER WILLIAMS REALTY
01 Registration & My Profile
How to Create and Start a Test Session
Home Page of HR Web. Home Page.
Presentation transcript:

OSG PKI RA Training Mine Altunay, Jim Basney OSG PKI Team October 1, 2012

The OSG PKI Transition from DOEGrids CA to OSG PKI. – Registration Authority Agents (RA Agent)/Grid Admins (GA) will interface directly with OSG and OSG Information Management System (OIM). – The back end CA, DigiCert CA, is invisible to RA Agents and GAs for their work. – Most of the RA Agent/GA functions remain the same. New user interface at OSG OIM, but basic functionalities are the same Using GOC ticketing system instead of mailing lists – Separation of RA Agent and GA duties: RA Agents only approve User certs, does not approve host certs anymore. GAs only approve host certs. – An RA Agent can be assigned to one or more VOs A GA can be assigned to one or more network domains (e.g. fnal.gov) and a domain can be approved by one or more GAs A person can be an RA Agent and GA simultaneously 10/1/122OSG PKI RA Training

The OSG PKI A GA can be assigned to one or more network domains (e.g. fnal.gov) and a domain can be approved by one or more GAs A person can be an RA Agent and GA simultaneously Quotas for the number of certificates: There is no quota for RA agent Each user can request up to 25 per year For GridAdmin, it's 50 per day, 1000 per year. 10/1/123OSG PKI RA Training

Training Goals and Outline Perform the RA Agent duties in OSG PKI. You will also act as an non-privileged user briefly. – Everything we perform in training is in ITB instance. No Production certs will be issued. – Request to become an RA Agent – Request a test cert for yourself, acting as a non-privileged user. – Approve the cert as an RA Agent – Revoke the cert as an RA Agent. Go over the policies and requirements of the new PKI After the training, request to become an RA Agent in the Production system. 10/1/124OSG PKI RA Training

Request to Become a RA Agent Check if you already done this: – Go to – Under your VOs, you should be listed as an RA Agent If you are not an RA Agent yet, request it now – Visit select your VO, then click the "Request for RA Enrollment" button in the upper right hand corner, and complete the form. Read the Agreement before you click yes. Tell us what you think about it. Agreement can be found at 10/1/125OSG PKI RA Training

Request a Test User Cert Request a user certificate: Go to itb.grid.iu.edu/oim/certificaterequestuser. itb.grid.iu.edu/oim/certificaterequestuser You will do this as a normal non-privileged user. In the CN field, add “RA Training” next to your name. Select your VO. Check the "I AGREE" box and click Submit. 10/1/126OSG PKI RA Training

Approve the Test User Cert You are acting as an RA Agent. Check your for a message from OSG containing: "An OIM Authenticated user... has requested a user certificate. Please determine this request's authenticity, and approve / disapprove at URL.” Look for a from “FootPrints” Open the URL from the message. (Your browser might already be on the right page.) For Training, we will NOT sponsors, but normally, you will: Select a Sponsor who is best suited to perform the identity vetting. You can find sponsors at Click on your VO and capture the list of Sponsors. All sponsors are cc’ed on the ticket, you should clarify which sponsor is responsible for vettinghttps://oim-itb.grid.iu.edu/oim/vo 10/1/127OSG PKI RA Training

Approve the Test User Cert When sponsor responds with a signed about their decision, go to Under “User Certificate Requests that I Approve”, click on the request. In the Action Note Field, write down the sponsors name and his/her response. For training, we do not use the sponsors. Just type "OSG RA Training” in the Action Note Field and click the Approve button. No need to send a separate to GOC ticketing system (or update GOC ticket) or to Action note will be added to the corresponding GOC ticket automatically. osg-ra list if you have questions & need help. 10/1/12OSG PKI RA Training8

Retrieve the Test Cert Back to being a regular non-privileged user. Check your for a message from OSG containing: "To retrieve your certificate please visit the URL” Open the URL from the message. (Your browser might already be on the right page.) Enter a 12 character or longer password / pass phrase. Click the "Issue Certificate" button. Click the "Download Certificate & Private Key" button. 10/1/129OSG PKI RA Training

Revoke the Test Cert Revoke the cert with your RA Agent privileges. Review circumstances under which RA Agents should revoke certificates. Open Click the "Others" tab. Enter your name in "DN Contains" and click the "Search" button. Click on the line for your certificate. Enter an "Action Note" ("OSG RA Training") and click the "Revoke" button. Do not forget to remove the test certificate from your browser. It is only good for testing environment 10/1/1210OSG PKI RA Training

After the training: Request a User cert in Production System Obtain a real user certificate from r. r Note the difference between OIM-ITB and OIM Apply to become an OSG RA Agent. Go to Select your VO and then click “Request for RA Enrollment" button in the upper right hand corner, and complete the form. 10/1/1211OSG PKI RA Training

New Distinguished Names: Will NOT Affect the RAs, but affect your VOs Certificates from new OSG PKI will have new Distinguished Names – Users will need to register new certificate DNs in VOMS Current DOEGrids DNs: – Issuer: /DC=org/DC=DOEGrids/OU=Certificate Authorities/CN=DOEGrids CA 1 – Subject: /DC=org/DC=doegrids/OU=People/CN=full name DOEGRIDS-ID# New OSG PKI DNs: – Issuer: /DC=com/DC=DigiCert-Grid/O=DigiCert Grid/CN=DigiCert Grid CA-1 – Subject: /DC=com/DC=DigiCert-Grid/O=Open Science Grid/OU=People/CN=full name OSG-OIM-ID# More details at: n n Testing so far has found no issues related to this DN change

End of the Training You are now Ready to handle production requests DOEGrids CA will shut down in mid-March and transition will start slowly after that – As users certs expire, they will start using OSG PKI Useful URLs: – – – edAgent edAgent 10/1/1213OSG PKI RA Training