7. septembar 2007 A E G I S Academic and Educational Grid Initiative of Serbia 2007 Annual Assembly AEGIS Certification Authority and Applications Branko.

Slides:



Advertisements
Similar presentations
APGrid PMA Face-to-Face Meeting NCHC CA Weicheng Huang National Center for High-performance Computing April 8, 2008.
Advertisements

Academia Sinica Grid Computing Certification Authority (ASGCCA) Yuan, Tein Horng Academia Sinica Computing Centre 13 June 2003.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien.
1 ASGCCA Self-Audit Report APGridPMA Jinny Chien March
CNIC Grid CA/SDG CA Self Audit Kejun (Kevin) Dong Computer Network Information Center (CNIC) Chinese Academy of Sciences APGridPMA F2F.
Identity Standards (Federal Bridge Certification Authority – Certificate Lifecycle) Oct,
DESIGNING A PUBLIC KEY INFRASTRUCTURE
1 REUNA Certificate Authority Juan Carlos Martínez REUNA Chile Rio de Janeiro,27/03/2006, F2F meeting, TAGPMA.
National Institute of Advanced Industrial Science and Technology Auditing, auditing template and experiences on being audited Yoshio Tanaka
Computing Research Center, High Energy Accelerator Organization (KEK) KEK Grid CA Go Iwai The 2 nd APGrid PMA Meeting at Osaka Univ.
SEE-GRID-2 The SEE-GRID-2 initiative is co-funded by the European Commission under the FP6 Research Infrastructures contract no
Paralelno i distribuirano računarstvo – primena u praksi Beograd jun Grid - korisnicki pristup i razvoj aplikacija Branko Marović RCUB.
NECTEC-GOC CA APGrid PMA face-to-face meeting. October, Sornthep Vannarat National Electronics and Computer Technology Center, Thailand.
SEE-GRID-SCI The SEE-GRID-SCI initiative is co-funded by the European Commission under the FP7 Research Infrastructures contract no.
National Institute of Advanced Industrial Science and Technology Self-audit report of AIST GRID CA Yoshio Tanaka Information.
FP6−2004−Infrastructures−6-SSA E-infrastructure shared between Europe and Latin America The Brazilian Grid Certification Authority.
Configuring Directory Certificate Services Lesson 13.
DataGrid WP6 CA meeting, CERN, 12 December 2002 IISAS Certification Authority Jan Astalos Department of Parallel and Distributed Computing Institute of.
March 27, 2006TAGPMA - Rio de Janeiro1 Short Lived Credential Services Profile Tony J. Genovese The Americas Grid PMA DOEGridsATF/ESnet/LBNL.
National Institute of Advanced Industrial Science and Technology Brief status report of AIST GRID CA APGridPMA Singapore September 16 Yoshio.
NECTEC-GOC CA Self Audit 7 th APGrid PMA Face-to-Face meeting March 8 th, 2010 Large-Scale Simulation Research Laboratory Sornthep Vannarat Large-Scale.
IHEP Grid CA Status Report Gongxing Sun F2F Meeting 20 Apr Computing Centre, IHEP,CAS,China.
IHEP Grid CA Status Report Wei F2F Meeting 8 Mar Computing Centre, IHEP,CAS,China.
KFKI CA József Kadlecsik KFKI RMKI
User Certificate Application: ASGCCA. Agenda Introduction ASGCCA User Responsibilities Certificate application form RA verify identity of users User generate.
IHEP Grid CA Status Report Gongxing Sun 5 th F2F Meeting 16 Sep Computer Center, IHEP,CAS,China.
Profile for Portal-based Credential Services (POCS) Yoshio Tanaka International Grid Trust Federation APGrid PMA AIST.
UNAMgrid Alejandro Núñez Sandoval Rio de Janeiro, Brazil, 03/27/06 F2F meeting, TAGPMA.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Next steps with EGEE EGEE training community.
Sam Morrison APAC CA – APGridPMA - ISGC2010 APAC CA Self Audit and status update Sam Morrison ARCS.
Academia Sinica Grid Computing Certification Authority (ASGCCA)
Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre.
INFSO-RI Enabling Grids for E-sciencE EGEE Induction Grid training for users, Institute of Physics Belgrade, Serbia Sep. 19, 2008.
Grid Canada Certificate Authority Darcy Quesnel
Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre.
Prof: doc.dr. Samir Lemeš student: Samir Hrnjić. System restore je komponenta Microsoftovih operativnih sistema Windows Serveri ne podržavaju opciju System.
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
APGrid PMA face-to-face meeting, 9/16/2008 PRAGMA-UCSD CA Team Pacific Rim Application and Grid Middleware Assembly
8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK
MICS Authentication Profile Maintenance & Update Presented for review and discussion to the TAGPMA On 1May09 by Marg Murray.
EGI-InSPIRE RI Grid Training for Power Users EGI-InSPIRE N G I A E G I S Grid Training for Power Users Institute of Physics Belgrade.
Egypt Certification Authority Dr. Ayman Bahaa-Eldin EUN Director 8 May th EuGridPMA meeting, Germany.
Baltic Grid Certification Authority 15th EUGridPMA, January 28th 2009, Nicosia1 Self-audit Hardi Teder EENet.
TR-GRID CA Self-Auditing Results and Status Update EUGridPMA Meeting September 12-14, 2011 Marrakesh Feyza Eryol, Onur Temizsoylu TUBITAK-ULAKBIM
HKU Computer Centre Grid Certificate Authority Status Update Lilian Chan IT Services, The University of Hong Kong APGrid.
FP6−2004−Infrastructures−6-SSA [ Empowering e Science across the Mediterranean ] Rome, Tutorial for Certification Authority Managers,
BG.ACAD CA HTTP :// CA. ACAD. BG S ELF - AUDIT REPORT 2014 Vladimir Dimitrov IICT-BAS ( 32 nd EUGridPMA Meeting Poznan, 8-10.
QuoVadis accreditation with EuGridPMA Alessandro Usai
18 th EUGridPMA, Dublin / SRCE CA Self Audit SRCE CA Self Audit Emir Imamagić SRCE Croatia.
GRID-FR French CA Alice de Bignicourt.
Co-ordination & Harmonisation of Advanced e-Infrastructures for Research and Education Data Sharing Research Infrastructures Grant Agreement n
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
NECTEC-GOC CA A Brief Status Report 13 th APGrid PMA Face-to-Face meeting March 24 th, 2014 Large-Scale Simulation Research Laboratory Information Communications.
UGRID CA Self-audit report Sergii Stirenko 21 st EUGRIDPMA Meeting Utrecht 24 January 2011.
HellasGrid CA self Audit. In general We do operations well Our policy documents need work (mostly to make the text clearer in a few sections) 2.
Armenian e-Science Foundation Certification Authority Ara A. Grigoryan 1,2, Artem Harutyunyan 1,2,3, Arsen Hayrapetyan 1,2,4 1 Armenian e-Science Foundation;
29 th EUGridPMA meeting, September 2013, Bucharest AEGIS Certification Authority Dušan Radovanović University of Belgrade Computer Centre.
TNGrid CA 24 th EUGridPMA meeting Ljubljana, Slovenia, January, 2012 Heithem ABBES Mohamed JEMNI
H I A S T HIAST GRID CA 21 th EUGridPMA meeting Utrecht, January, 2011 Ghassan SABA Houssam ABED
IRAN-GRID Certificate Authority 13 th EUgridPMA Meeting Copenhagen May 2008 Majid Arabgol Hessamdding Arfaei Shahin Rouhani
MD-Grid CA Valentin Pocotilenco RENAM Association
AEGIS Certification Authority
UGRID CA Sergii Stirenko, Oleg Alienin
جايگاه گواهی ديجيتالی در ايران
MaGrid CA Self audit and update
NATIONAL CENTRE FOR PHYSICS PK-Grid-CA
Bill Yau HKU Grid Certificate Authority (HKU Grid CA) Self Audit & Status Report Bill Yau
MyIFAM CA Self-Audit Report APGridPMA F2F Meeting 1/4/2019
KISTI CA Report Status & Self-Audit
BG.ACAD CA Self-audit report 2018
Presentation transcript:

7. septembar 2007 A E G I S Academic and Educational Grid Initiative of Serbia 2007 Annual Assembly AEGIS Certification Authority and Applications Branko Marović RCUB

A E G I S 7. Septembar AEGIS 2007 Annual Assembly AEGIS Certification Authority Primljen u EUGridPMA na skupu u Istanbulu AEGIS CA Certificate Policy and Certification Practice Statement

A E G I S 7. Septembar AEGIS 2007 Annual Assembly AEGIS Certification Authority Names  Issuer: C=RS, O=AEGIS, CN=AEGIS-CA  Subject: C=RS, O=AEGIS, OU=XXX, CN=Subject-name  Country: Must be “RS”  Organization: Must be “AEGIS”  OrganizationUnit: Must be the name of the subject's institute  CommonName: First name and last name of the subject for user certificates, DNS FQDN for server or service certificates End Entity Certificates  Maximum lifetime: 1 year  Key length: at least 1024 bits Person requesting a certificate  Presentation in person of valid official identification document Server/Host/Service certificate  Can be only requested by the administrator of the particular host  The administrator must already have a valid AEGIS certificate

A E G I S 7. Septembar AEGIS 2007 Annual Assembly Izdavanje prvog sertifikata Videti instrukcije na Formirati PKCS#10 zahtev – najlakše je na nekom od AEGIS UI računara Poslati zahtev i lične podatke (ime i prezime, , institucija, adresa) preko AEGIS CA web interfejsa ili na Generiše se slučajni 10-ocifreni broj i šalje automatski odgovor gde se korisnik obaveštava  Da je vreme procesiranja sertifikata 3 radna dana  Da je potrebno da se lično pojavi u kancelariji AEGIS CA ili RA radi potvrde identiteta  O adresi i brojevima telefona AEGIS CA/RA  O procesu autentifikacije korisnikovog -a: generisani broj se deli na dva dela. U odgovoru se nalazi prvih 5 cifara, dok drugih 5 korisnik dobija kada se pojavi radi autentifikacije. Korisnik dolazi kod AEGIS CA ili RA sa validnim dokumentom za ličnu identifikaciju i dokazom veze sa institucijom navedenom u zahtevu. Šalje 10 cifara sa prijavljene adrese na AEGIS CA/RA Na ovako potvrđenu adresu se dostavlja potpisan sertifikat  Korisnik se obaveštava da treba da u roku od 5 dana pošalje potpisan dobijenim sertifikatom kojim prihvata svoj novi sertifikat i CP/CPS dokumenat Korisnik svoj sertifikat može koristiti za pristup Grid-u, za potpisivanje e- mail-ova, autentifikaciju preko Web-a i enkripciju podataka. Može sertifikat koristiti kroz AEGIS i SEE-GRID VOMS server

A E G I S 7. Septembar AEGIS 2007 Annual Assembly Izdavanje narednih sertifikata Zahtevi za re-key sertifikata koji su potpisani važećim sertifikatom izdatim od CA akreditovanim od EUGridPMA će biti potpisani bez prethodne procedure jer je identitet korisnika već utvrđen. Korišćeni sertifikat i zahtev treba da se odnose na istu osobu, i instituciju. CA/RA i dalje mora da proveri da li osoba ima vezu sa institucijom navedenom u zahtevu – dovoljno je da je e- mail institucionalni.

A E G I S 7. Septembar AEGIS 2007 Annual Assembly Generisanje sertifikata i sigurnost Sertifikati se generišu na izolovanom računaru, u kancelariji sa ograničenim pristupom. Koriste se lozinke od bar 15 karaktera. CA manager i CA operater jedini znaju root password. Na računaru je instaliran CentOS operativni sistem sa minimumom servisa - apliciraju se sve security zakrpe. Koristi se CSP softver. Računar ima CD-RW uređaj i USB konektore za backup. Hard disk se stavlja u HDD rack, čuva se na sigurnoj lokaciji. Vrši se backup na CD-ROM i USB flash-u koji se takođe čuvaju sigurnoj lokaciji. Postojaće i off-site backup. Na CA sajtu će biti omogućena isključivo pretraga (ne i listanje) izdatih sertifikata. Čuva se lista generisanih sertifikata. Kada se sertifikat povuče, obnavlja se CRL, koja se odmah objavljuje na CA sajtu. CRL se takodje obnavlja na svakih 30 dana, bez obzira da li je bilo povučenih sertifikata.

A E G I S 7. Septembar AEGIS 2007 Annual Assembly Certificate Revocation Certificate Revocation List  Minimum/maximum lifetime: 7/30 days  CRL is updated immediately after every certificate revocation  CRL is issued at least 7 days before expiration Circumstances for revocation  Subscriber has ceased to be a member of, or associated with AEGIS related institution, program or activity  Subscriber key is lost or suspected to be compromised  Information in certificate is suspected to be inaccurate  Subscriber violated his/her obligations  Subscriber does not need the certificate any more

A E G I S 7. Septembar AEGIS 2007 Annual Assembly Events Recorded events  Certification requests  Issued certificates  Requests for revocation  Issued CRL’s  Login/logout/reboot of the signing machine Archived events  Certification requests  Issued certificates  Requests for revocation  Issued CRL’s  All messages of correspondence between RA and CA

A E G I S 7. Septembar AEGIS 2007 Annual Assembly Kontakt University of Belgrade Computer Center Kumanovska bb Beograd Serbia Phone: , Fax: Dušan Radovanović

A E G I S 7. Septembar AEGIS 2007 Annual Assembly SEE-GRID-2 Application Selection ARC (Application Review Committee) Large number of potential applications For the reason of scalability, it was decided that only a subset of the applications will be supported Candidate application developers fill online Continuous Grid Application Questionnaire submitting data on their applications  Application ranking criteria developed jointly trough discussion within the consortium WP4 partners from all countries. 32 applications in total were submitted initially. 23 were assessed with the questionnaire.

A E G I S 7. Septembar AEGIS 2007 Annual Assembly Application Lifecycle

A E G I S 7. Septembar AEGIS 2007 Annual Assembly SEE-GRID2 Applications

A E G I S 7. Septembar AEGIS 2007 Annual Assembly SEE-GRID2 Applications

A E G I S 7. Septembar AEGIS 2007 Annual Assembly Developer Resources Grid environment is constantly evolving, but  Useful features persist  New are constantly being added  Bugs are being fixed  Gained knowledge remains relevant, must be updated  Applications can be easily migrated to new/updated APIs gLite User Guide  SEE-GRID Gridification Guide  SEEGRID Wiki  gLite documentation 

A E G I S 7. Septembar AEGIS 2007 Annual Assembly Application Gridification Guide Relevant topics for application developers identified trough online questionnaire system Some investigation areas identified as well – candidates for future GG topics Gridification guide will provide information on these topics GG collaboration medium – Wiki  see.org/index.php/SG_Gridification_Guide

A E G I S 7. Septembar AEGIS 2007 Annual Assembly SEE-GRID-2 Application Support Application support group (ASG) – experienced developers & admins  National level application support  SEE-GRID - global level application support Work in close collaboration with WP5 (training) and WP3 (software requirements, maintenance of performance)

A E G I S 7. Septembar AEGIS 2007 Annual Assembly Šta je Web za podatke, to će Grid biti za računarske resurse! Grid: naredni korak u evoluciji Interneta. Pristup računarima će postati usluga poput struje, telefona ili vode.