A history of the CACG, EUGridPMA, and the IGTF (and some next steps) First APGridPMA Face-to-Face Meeting Beijing David Groep, 2005-11-29.

Slides:



Advertisements
Similar presentations
2 nd APGrid PMA F2F Meeting Osaka University Convention Center October 15 09: :20 # Participants: 26.
Advertisements

Usage of PGP in TACAR 19th OGF Meeting Chapel Hill, USA February 1, 2007 Licia Florio Project Development Officer
International Grid Trust Federation Session GGF 20 Manchester, UK Wednesday, May CAOPS-WG session #2.
INFSO-RI Enabling Grids for E-sciencE Portals and Authentication Issues and Solution Directions from a CA and IGTF Perspective David.
4 th APGrid PMA F2F Meeting Academia Sinica, Taipei, Taiwan April 8, 2008 Agendahttp:// Call for note takers!
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
2 nd APGrid PMA F2F Meeting Osaka University Convention Center October 15 Wireless LAN SSID: PRAGMA11 Wep key: PRAGMA11JAPAN.
1 REUNA Certificate Authority Juan Carlos Martínez REUNA Chile Rio de Janeiro,27/03/2006, F2F meeting, TAGPMA.
NRENs supporting Grids using current Grid technology TERENA NREN-GRID Workshop Amsterdam Milan Sova CESNET.
Authentication Policy David Kelsey CCLRC/RAL 15 April 2004, Dublin
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Policy Issues for Identity Management (and other attributes) EGI Technical.
The EU Grid PMA David Kelsey CCLRC/RAL 16 April 2004, Dublin
The TERENA Academic CA Repository. eIRG Meeting. Dublin, 16/04/2004 Diego R. Lopez – TF-AACE  Task Force on Authentication and.
Grid Trust Fabric TNC 2006, Catania 16 May 2006 David Kelsey CCLRC/RAL, UK
Updates from the EUGridPMA David Groep, Apr 8 nd, 2008.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
12-May-03D.P.Kelsey, SCG Online Authentication1 Online Authentication SCG Meeting EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
Identity Management Levels of Assurance WLCG GDB CERN, 8 Apr 2009 David Kelsey STFC/RAL david.kelsey AT stfc.ac.uk.
National Institute of Advanced Industrial Science and Technology Self-audit report of AIST GRID CA Yoshio Tanaka Information.
The CA Distribution Process David Groep, July 2007.
Chapter 23 Internet Authentication Applications Kerberos Overview Initially developed at MIT Software utility available in both the public domain and.
March 27, 2006TAGPMA - Rio de Janeiro1 Short Lived Credential Services Profile Tony J. Genovese The Americas Grid PMA DOEGridsATF/ESnet/LBNL.
National Institute of Advanced Industrial Science and Technology Brief status report of AIST GRID CA APGridPMA Singapore September 16 Yoshio.
DOE Grids New subordinate CP/CPS v2.3 New subordinate CP/CPS v2.3 New name DOEGrids.org New name DOEGrids.org Old name DOESciencegrid.org Old name DOESciencegrid.org.
NECTEC-GOC CA Self Audit 7 th APGrid PMA Face-to-Face meeting March 8 th, 2010 Large-Scale Simulation Research Laboratory Sornthep Vannarat Large-Scale.
TERENA TF-EMC2 Workshop David Groep,
Grid and NREN operational support Tony Genovese ATF team ESnet Lawrence Berkeley National Laboratory.
Updates from the EUGridPMA David Groep, July 16 st, 2007.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
Profile for Portal-based Credential Services (POCS) Yoshio Tanaka International Grid Trust Federation APGrid PMA AIST.
TAGPMA & the Bridge WG (Scott Rea – Dartmouth College) Internet2 Member Meeting, Dec 2006 PKI Activities and Applications Update - Chicago, IL.
European Grid Policy Management Authority. Event - 2/total Speaker Name – Coverage of the EUGridPMA Green: Countries with an accredited.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
ESnet RAF and eduroam ™ Tony J. Genovese ATF Team ESnet/Lawrence Berkeley National Laboratory.
National Institute of Advanced Industrial Science and Technology Some topics from the OGF20 and the EUGrid PMA F2F Meeting Yoshio Tanaka Grid Technology.
International Grid Trust Federation Session GGF 20 Manchester, UK Wednesday, May CAOPS-WG session #2.
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
Distribution Repository Structure David Groep,
Updates from the EUGridPMA David Groep, May 9 st, 2007.
NRENs, Grids and Integrated AAI In Search For the Utopian Solution Christos Kanellopoulos AUTH/GRNET October 17 th, 2005 skanct at physics.auth.gr 2nd.
2-Sep-02D.P.Kelsey, WP6 CA, Budapest1 WP6 CA report Budapest 2 Sep 2002 David Kelsey CLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE Security Summary Åke Edlund, JRA3 4 th EGEE Conference Pisa, Italy 28 th October 2005.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Updates from the European Side of the Pond David Groep, November 2006.
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
Community PKIs Initiatives Updates TF-EMC2 Meeting Loughborough, UK 6-7 May, 2009 Licia Florio, TERENA
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
12-Jun-03D.P.Kelsey, CA meeting1 CA meeting Minimum Requirements CERN, 12 June 2003 David Kelsey CCLRC/RAL, UK
TACAR Updates version David Groep, NIKHEF. 9 th EUGridPMA ‘RAL’ meeting – Jan David Groep – TACAR Aims  Trusted and.
7-May-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Issues and Planning or Report from the Security Group CERN, 8 May 2003 David Kelsey CCLRC/RAL, UK.
FP6−2004−Infrastructures−6-SSA E-infrastructure shared between Europe and Latin America The Latin American Catch-all Grid Certification.
APGridPMA Update Eric Yen APGridPMA August, 2014.
Summary of Poznan EUGridPMA32 September EUGridPMA Poznan 2014 meeting – 2 David Groep – Welcome back at PSNC.
18 th EUGridPMA, Dublin / SRCE CA Self Audit SRCE CA Self Audit Emir Imamagić SRCE Croatia.
Update of APGridPMA Eric Yen 25 th EUGridPMA & IGTF All Hands Meeting KIT, Germany 7 May, 2012.
UGRID CA Self-audit report Sergii Stirenko 21 st EUGRIDPMA Meeting Utrecht 24 January 2011.
News from EUGridPMA EGI OMB, 22 Jan 2013 David Kelsey (STFC) Using notes from David Groep 22/01/20131EUGridPMA News.
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
Updates from the EUGridPMA David Groep, Oct 17 st, 2007.
IGTF in 10 years enabling the interoperable global trust federation Nikhef, Amsterdam supported the Dutch national e-Infrastructure funded and coordinated.
Classic X.509 AP updates (v4.1)
Updates of the APGrid PMA
Grids & PKI: TAGPMA & Bridges (Scott Rea – Dartmouth College) Internet2 Member Meeting, Dec 2006 PKI Implementers Workshop - Chicago, IL.
HellasGrid CA & euGridPMA
EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.
MaGrid CA Self audit and update
Presentation transcript:

A history of the CACG, EUGridPMA, and the IGTF (and some next steps) First APGridPMA Face-to-Face Meeting Beijing David Groep,

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – A brief history … From the CACG to EUGridPMA to IGTF …  The EU DataGrid CACG  The EUGridPMA: charter and growth  IGTF Foundation on October 5 th, 2005 The Federation: structure and documents  Common guidelines  Authentication Profiles  Distribution and common naming  Related bodies: GGF and TACAR Current issues and new challenges

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – In the Beginning: the EU DataGrid CACG The EU DataGrid in 2000 needed a PKI for the test bed Both end-user and service/host PKI CACG (actually David Kelsey) had the task of creating this PKI for Grid Authentication only no support for long-term encryption or digital signatures Single CA was not considered acceptable Single point of attack or failure One CA per country, large region or international organization CA must have strong relationship with RAs Some pre-existing CAs A single hierarchy would have excluded existing CAs and was not convenient to support with existing software Coordinated group of peer CAs was most suitable choice History

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Five years of growth December 2000: First CA coordination meeting for the DataGrid project March 2001: First version of the minimum requirements 5 CAs: France (CNRS), Portugal (LIP), Netherlands (NIKHEF), CERN, Italy (INFN), UK (UK eScience) December 2002: Extension to other projects: EU-CrossGrid … History

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – ‘Reasonable procedure … acceptable methods’  Requirements and Best Practices for an “acceptable and trustworthy” Grid CA Minimum requirements for RA - Testbed An acceptable procedure for confirming the identity of the requestor and the right to ask for a certificate e.g. by personal contact or some other rigorous method The RA should be the appropriate person to make decisions on the right to ask for a certificate and must follow the CP. Communication between RA and CA Either by signed or some other acceptable method, e.g. personal (phone) contact with known person Minimum requirements for CA - Testbed The issuing machine must be: a dedicated machine located in a secure environment be managed in an appropriately secure way by a trained person the private key (and copies) should be locked in a safe or other secure place the private keu must be encrypted with a pass phrase having at least 15 characters the pass phrase must only be known by the Certificate issuer(s) not be connected to any network minimum length of user private keys must be 1024 min length of CA private key must be 2048 requests for machine certificates must be signed by personal certificates or verified by other appropriate means... History

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Building the initial trust fabric  Identity only, no roles or authorization attributes (that’s left for other mechanisms) – goal is a single common identity for every person  PKI providers (‘CAs’) and Relying Parties (‘sites’) together shape the minimum requirements  Authorities testify compliance with these guidelines  Peer-review process within the federation to (re) evaluate members on entry & periodically  Reduce effort on the relying parties  single document to review and assess for all CAs  Reduce cost on the CAs:  no audit statement needed by certified accountants ($$$)  but participation in the Federation does come with a price  Requires that the federation remains manageable in size  Ultimate decision always remains with the RP History

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – March 2003: The Tokyo Accord  … meet at GGF conferences. …  … work on … Grid Policy Management Authority: GRIDPMA.org  develop Minimum requirements – based on EDG work  develop a Grid Policy Management Authority Charter  [with] representatives from major Grid PMAs:  European Data Grid and Cross Grid PMA: 16 countries, 19 organizations  NCSA Alliance  Grid Canada  DOEGrids PMA  NASA Information Power Grid  TERENA  Asian Pacific PMA: AIST, Japan; SDSC, USA; KISTI, Korea; Bll, Singapore; Kasetsart Univ., Thailand; CAS, China History

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – At The End of Data Grid … In December 2003, the EU DataGrid project ended … … and the Grid and CA arena had changed:  the new EGEE project was just one of 3 e-Infrastructures  the LHC Computing Grid turned into a production system  TERENA TF-AACE had established TACAR This called for a pan-European coordinated effort  Encompassing all three e-Infrastructure projects  To be recognized as a European coordination body  With support from the new e-Infrastructure Reflection Group  Fostered by the Irish EU Presidency in 2004 History

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – … we published and moved on to …  Best practices of the CACG documented in the paper by David O’Callaghan et al.  Lecture Notes in Computer Science 3470 pp History

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – The European Policy Management Authority for Grid Authentication in e-Science (hereafter called EUGridPMA) is a body to establish requirements and best practices for grid identity providers to enable a common trust domain applicable to authentication of end-entities in inter-organisational access to distributed resources. As its main activity the EUGridPMA coordinates a Public Key Infrastructure (PKI) for use with Grid authentication middleware. The EUGridPMA itself does not provide identity assertions, but instead asserts that - within the scope of this charter – the certificates issued by the Accredited Authorities meet or exceed the relevant guidelines. The EUGridPMA “constitution”

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – EUGridPMA Membership EUGridPMA membership for (classic) CAs:  A single Certification Authority (CA)  per country,  large region (e.g. the Nordic Countries), or  international treaty organization.  The goal is to serve the largest possible community with a small number of stable CAs  operated as a long-term commitment Many CAs are operated by the (national) NREN (CESNET, ESnet, Belnet, NIIF, EEnet, SWITCH, DFN, … ) or by the e-Science programme/Science Foundation (UK eScience, VL-e, CNRS, … )

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Coverage of the EUGridPMA Green: Countries with an accredited CA  23 of 25 EU member states (all except LU, MT)  + AM, CH, IL, IS, NO, PK, RU, TR, “SEE-catch-all” Other Accredited CAs:  DoEGrids (.us)  GridCanada (.ca)  CERN  ASGCC (.tw)*  IHEP (.cn)* * Migrated to APGridPMA per Oct 5 th, 2005

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – The Catch-All CAs Project-centric “catch all” Authorities  For those left out of the rain in EGEE  CNRS “catch-all” (Sophie Nicoud)  coverage for all EGEE partners  For the South-East European Region  regional catch-all CA  For LCG world-wide  DoeGrids CA (Tony Genovese & Mike Helm, ESnet)  Registration Authorities through Ian Neilson

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – New CAs: the Accreditation Process Accreditation Guidelines for EUGridPMA Key elements:  Codification of procedures in a CP(S) for each CA  de facto lots of copy/paste, except for vetting sections  Peer-review process for evaluation  comments welcomed from all PMA members  two assigned referees  In-person appearance during the review meeting  Accreditation model for other PMAs typically embedded in their charter …  Peer-auditing and periodic re-evaluation are needed

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Growth of the CACG & EUGridPMA History

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Solution to Extending Trust: IGTF – the International Grid Trust Federation TAGPMA APGridPMA  common, global best practices for trust establishment  better manageability and coordination of the PMAs The America’s Grid PMA Asia-Pacific Grid PMA European Grid PMA

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – APGridPMA  13 members from the Asia-Pacific Region, chaired by Yoshio Tanaka (AIST)  Launched June 1 st, 2004  4 ‘production-quality’ CAs  Pioneered ‘experimental’ profile AIST (.jp) APAC (.au) BMG (.sg) CMSD (.in) HKU CS SRG (.hk) KISTI (.kr) NCHC (.tw) NPACI (.us) Osaka U. (.jp) SDG (.cn) USM (.my) IHEP Beijing (.cn) ASGCC (.tw)

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – TAGPMA  10 members to date, chaired by Darcy Quesnel (Canarie)  Launched June 28th, 2005  Pioneered new “SLCGS” (Kerberos CA & al.) Canarie (.ca) OSG (.us) TERAGRID (.us) Texas H.E. Grid (.us) DOEGrids (.us) SDSC (.us) FNAL (.us) Dartmouth (.us) Umich (.us) Brazil (.br)

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Timeline  March 2005: IGTF Draft Federation Document GGF13  July 27 th : APGridPMA approved version 0.7  September 28 th : EUGridPMA approval version 0.9  October 5 th : TAGPMA approved version 1.0  October 5 th : formal foundation of the IGTF

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Common Guidelines across the IGTF

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Relying Party issues to be addressed Characteristics Relying Party requests 1. standard accreditation profiles sufficient to assure approximate parity in CAs 2. monitor [] signing namespaces for name overlaps and issue unique names 3. a forum [to] participate and raise issues 4. [operation of] a secure collection point for information about CAs which you accredit 5. common practices where possible (list courtesy of the Open Science Grid)

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Guidelines: common elements  Coordinated namespace  Subject names refer to a unique entity (person, host)  Basis for authorization decisions  Common Naming  One-stop shopping for all trust anchors in the federation  Trusted, redundant, download sources  Concerns and ‘incident’ handling  Guaranteed point of contact  Forum to raise issues and concerns  Requirement for documentation of processes  Detailed policy and practice statement  Open to auditing by federation peers

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Guidelines: secured X.509 CAs  Long-lived identity assertions  Identity vetting procedures  Based on (national) photo ID’s  Face-to-face verification of applicants via a network of Registration Authorities  Periodic renewal (once every year)  Secure operation  off-line signing key or special (FIPS or better) hardware  Response to incidents  Timely revocation of compromised certificates  Version 4.0 synchronised with Federation Document  The Annotated Minimum Requirements on the Wiki

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Guidelines: short-lived credential service  Issue short-lived credentials (for grid: proxies) based on another site-local authentication system  e.g. Kerberos CA based on existing administration  Same common guidelines apply  documented policies and processes  a reliable identity vetting mechanism  accreditation of the credential issuer with a PMA  Same X.509 format, but no user-held secrets  New profile by TAGPMA in the Americas

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Guidelines: ‘Active Certificate Stores’ ?? Do we need one for ACS’s, for can we re-use the SLCS?  Secure key/cert storage for end-users  Backed by a “traditional” CA  Releases short-lived tokens (RFC3820 “proxy” certs)  User key data protected by “other” (possibly UHO) mechanisms  ACS hosted by a trusted party (e.g. by the CA, the NREN, or an e-Science OpCenter)  Profile yet to be written (Jens Jensen, Tony?, …)

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Common Naming: the Distribution  Periodic, monthly, distribution of all trust anchors  Common for the entire IGTF  Includes all trust anchors for all profiles classic, SLCS, experimental*, …  Does not distinguished between accrediting PMAs  Wide variety of formats  RedHat Package Management (RPM) system including a ‘meta’ package with dependencies per profile  ‘tar’ archives per CA, ordered per profile  Installation bundle suitable for ‘./configure && make install ’  New formats (like JKS) on request  Chairs can update the common back-end repository

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – TACAR A trusted repository which contains verified root-CA certificates The certificates to be collected are those directly managed by the member NRENs, or belonging either to a National Academic PKI in the TERENA member countries (NPKIs), or to non-profit research projects directly involving the academic community.  Authoritative source for validation of trust anchors  independent web administration makes for stronger trust  TACAR certificate itself published in paper/journals  over 20 CA root certificates (and not exclusively for grid use)

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Access to the Distribution Repository  Web site  Should be mirrored by all PMAs  Each PMA can/should sign the RPMs with their own PGP key  Validation of content via TACAR (where possible)

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – EUGridPMA and TACAR

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Relationships: IGTF, PMAs, TACAR and GGF

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Developments in Europe: Along the e-IRG Roadmap e-IRG: e-Infrastructure Reflection Group Roadmap for i2010:  commitment to the federated approach  vision of an integrated AA infrastructure for eEurope Towards an integrated AAI for academia in Europe and beyond  The e-IRG notes the timely operation of the EUGridPMA in conjunction with the TACAR CA Repository and it expresses its satisfaction for a European initiative that serves e-Science Grid projects. […] The e-IRG strongly encourages the EUGridPMA / TACAR to continue their valuable work […] (Dublin, 2004)  The e-IRG encourages work towards a common federation for academia and research institutes that ensures mutual recognition of the strength and validity of their authorization assertions. (The Hague, 2005)

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Recent developments in this direction  From the policy side  Push for global interoperability  From TERENA  NRENs-GRID workshop series  TF-EMC2 / TF-Mobility  TACAR extensions?  REFEDS: Research and Education Federations (includes authorization as well, and even software discussions)  IGTF, eduroam, A-Select, PAPI, SWITCH-AAI, InCommon, HAKA, FEIDE/Moria 

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – Current Fuzzy Issues in the EUGridPMA In no particular order …  Real Names in the certificate subject?  commonName vs. pseudonym  Relying parties like the “warm and fuzzy feeling of trust”  One-statement certificate policies - implementation  CSR delivery and linking with identity vetting trail  Steady move to the use of HSMs for CAs  USB hardware token delivery has started as well  What’s the future interoperability/software support? And cost?  OCSP re-/transponder network, how to run it?  Setup together with certiVer and with discussions in GGF  Format and distribution  CA monitoring and availability … Discussion on the Wiki, e.g.

First APGridPMA Face-to-Face Meeting Beijing – Nov David Groep – EUGridPMA IGTF Graphic by David O’Callaghan, Poznan 2005