Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre.

Slides:



Advertisements
Similar presentations
INFN CA1 active since July manager: –Roberto Cecchini types of certificates released: –personal –server –object signing.
Advertisements

Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
APGrid PMA Face-to-Face Meeting NCHC CA Weicheng Huang National Center for High-performance Computing April 8, 2008.
User Certificate Application Guide Mason Hsiung. Visit start to request your user certificatehttp://ca.grid.sinica.edu.tw.
Grid Computing, B. Wilkinson, 20045a.1 Security Continued.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Yuan, Tein Horng Academia Sinica Computing Centre 13 June 2003.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien.
1 ASGCCA Self-Audit Report APGridPMA Jinny Chien March
CNIC Grid CA/SDG CA Self Audit Kejun (Kevin) Dong Computer Network Information Center (CNIC) Chinese Academy of Sciences APGridPMA F2F.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
Identity Standards (Federal Bridge Certification Authority – Certificate Lifecycle) Oct,
DESIGNING A PUBLIC KEY INFRASTRUCTURE
1 REUNA Certificate Authority Juan Carlos Martínez REUNA Chile Rio de Janeiro,27/03/2006, F2F meeting, TAGPMA.
National Institute of Advanced Industrial Science and Technology Auditing, auditing template and experiences on being audited Yoshio Tanaka
Summer School Certificates Diego Romano & Gilda Team.
HEBCA – Higher Education Bridge Certification Authority Presented by Scott Rea and Mark Franklin, Fed/Ed Meeting, 12/14/2005.
Computing Research Center, High Energy Accelerator Organization (KEK) KEK Grid CA Go Iwai The 2 nd APGrid PMA Meeting at Osaka Univ.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien F2F Meeting 8 th March 2010.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
UNAMgrid CA Juan Carlos Guel UNAM, México. Alejandro Núñez UNAM, México. Israel Becerril UNAM, México. DGSCA UNAM 31/08/06.
NECTEC-GOC CA APGrid PMA face-to-face meeting. October, Sornthep Vannarat National Electronics and Computer Technology Center, Thailand.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
National Institute of Advanced Industrial Science and Technology Self-audit report of AIST GRID CA Yoshio Tanaka Information.
Chapter 9: Using and Managing Keys Security+ Guide to Network Security Fundamentals Second Edition.
DataGrid WP6 CA meeting, CERN, 12 December 2002 IISAS Certification Authority Jan Astalos Department of Parallel and Distributed Computing Institute of.
SECURITY MANAGEMENT Key Management in the case of public-key cryptosystems, we assumed that a sender of a message had the public key of the receiver at.
March 27, 2006TAGPMA - Rio de Janeiro1 Short Lived Credential Services Profile Tony J. Genovese The Americas Grid PMA DOEGridsATF/ESnet/LBNL.
National Institute of Advanced Industrial Science and Technology Brief status report of AIST GRID CA APGridPMA Singapore September 16 Yoshio.
NECTEC-GOC CA Self Audit 7 th APGrid PMA Face-to-Face meeting March 8 th, 2010 Large-Scale Simulation Research Laboratory Sornthep Vannarat Large-Scale.
Windows 2000 Certificate Authority By Saunders Roesser.
IHEP Grid CA Status Report Gongxing Sun F2F Meeting 20 Apr Computing Centre, IHEP,CAS,China.
IHEP Grid CA Status Report Wei F2F Meeting 8 Mar Computing Centre, IHEP,CAS,China.
KFKI CA József Kadlecsik KFKI RMKI
User Certificate Application: ASGCCA. Agenda Introduction ASGCCA User Responsibilities Certificate application form RA verify identity of users User generate.
Profile for Portal-based Credential Services (POCS) Yoshio Tanaka International Grid Trust Federation APGrid PMA AIST.
UNAMgrid Alejandro Núñez Sandoval Rio de Janeiro, Brazil, 03/27/06 F2F meeting, TAGPMA.
Sam Morrison APAC CA – APGridPMA - ISGC2010 APAC CA Self Audit and status update Sam Morrison ARCS.
Academia Sinica Grid Computing Certification Authority (ASGCCA)
KISTI Grid CA Operation KISTI Supercomputing Center Sangwan Kim, Soonwook Hwang CA Operators Contact: Jan. 8, 2007.
Who’s watching your network The Certificate Authority In a Public Key Infrastructure, the CA component is responsible for issuing certificates. A certificate.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien April 20, th APGridPMA in Taipei.
Security fundamentals Topic 5 Using a Public Key Infrastructure.
Grid Canada Certificate Authority Darcy Quesnel
Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre.
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
APGrid PMA face-to-face meeting, 9/16/2008 PRAGMA-UCSD CA Team Pacific Rim Application and Grid Middleware Assembly
0 NAREGI CA Status Report APGrid F2F meeting in Singapore June 4, 2007 Rumiko Masuko.
8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK
MICS Authentication Profile Maintenance & Update Presented for review and discussion to the TAGPMA On 1May09 by Marg Murray.
Egypt Certification Authority Dr. Ayman Bahaa-Eldin EUN Director 8 May th EuGridPMA meeting, Germany.
Baltic Grid Certification Authority 15th EUGridPMA, January 28th 2009, Nicosia1 Self-audit Hardi Teder EENet.
Trusted Organizations In the grid world one single CA usually covers a predefined geographic region or administrative domain: – Organization – Country.
TR-GRID CA Self-Auditing Results and Status Update EUGridPMA Meeting September 12-14, 2011 Marrakesh Feyza Eryol, Onur Temizsoylu TUBITAK-ULAKBIM
HKU Computer Centre Grid Certificate Authority Status Update Lilian Chan IT Services, The University of Hong Kong APGrid.
FP6−2004−Infrastructures−6-SSA [ Empowering e Science across the Mediterranean ] Rome, Tutorial for Certification Authority Managers,
18 th EUGridPMA, Dublin / SRCE CA Self Audit SRCE CA Self Audit Emir Imamagić SRCE Croatia.
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
UGRID CA Self-audit report Sergii Stirenko 21 st EUGRIDPMA Meeting Utrecht 24 January 2011.
HellasGrid CA self Audit. In general We do operations well Our policy documents need work (mostly to make the text clearer in a few sections) 2.
Armenian e-Science Foundation Certification Authority Ara A. Grigoryan 1,2, Artem Harutyunyan 1,2,3, Arsen Hayrapetyan 1,2,4 1 Armenian e-Science Foundation;
CAISO Public Key Infrastructure: Supporting Secure ICCP Leslie DeAnda Senior Information Security Analyst, Information Security, CAISO EMS Users Group.
TNGrid CA 24 th EUGridPMA meeting Ljubljana, Slovenia, January, 2012 Heithem ABBES Mohamed JEMNI
MD-Grid CA Valentin Pocotilenco RENAM Association
IRAN-GRID CA Self Audit IRAN-GRID CA Self Audit Report Shahin Rouhani IRAN-GRID Tehran Iran Shahin Rouhani Grid Computation Group IPM, Tehran, Iran May.
جايگاه گواهی ديجيتالی در ايران
MaGrid CA Self audit and update
NATIONAL CENTRE FOR PHYSICS PK-Grid-CA
Bill Yau HKU Grid Certificate Authority (HKU Grid CA) Self Audit & Status Report Bill Yau
MyIFAM CA Self-Audit Report APGridPMA F2F Meeting 1/4/2019
Presentation transcript:

Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre

Outline Introduction Procedural Security Physical Security Technical Security Contact Information Related Information

Introduction The ASGCCA locates at Academia Sinica Computing Centre in Taiwan and has been running since July It is managed by Academia Sinica Computing Centre It provides X.509 certificate to support the secure environment in grid computing.

Procedural Security End Entity and Certificate Type Identification and Authentication Certificate Request Certificate Revocation Records Archival

End Entity and Certificate Type End Entities: –Academia Sinica employees –Research collaborators Certificate Type –Person Certificate C=TW, O=AS, OU=CC, CN=Yuan Tein Horng / –Host Certificate C=TW, O=AS, OU=CC, CN=beta.wsl.sinica.edu.tw –Service Certificate C=TW, O=AS, OU=CC, CN=FTP/beta.wsl.sinica.edu.tw

Identification and Authentication Person certificate: –Subscriber must be already registered at the Academia Sinica Grid Computing Directory Service (ASGCDS) as a Academia Sinica employee or collaborator. –RA staff will check account registered on ASGCDS and contact subscriber personally. Host or service certificate: –Requests must be signed with a valid personal ASGCCA certificate –RA will check the FQDN of the host before issuing certificate

Certificate Request subscriberRACA ASGCDS Subscriber registers on ASGCDS 2.Subscriber requests certificate 3.RA checks the Subscriber’s identity on ASGCDS 4.RA contacts and confirms subscriber’s identity personally 5. RA send certificate request to CA by signed 6. CA issues certificate 7. RA sends notice to subscriber and subscriber picks up new certificate

Certificate Revocation Circumstances for Revocation –The entity’s private key is lost or suspected to be compromised. –The information in the entity's certificate is suspected to be inaccurate. –The entity terminate services. –The entity violated its obligations.

Certificate Revocation (cont.) Procedure for Revocation Request –Sending an , signed by subscriber’s valid ASGCCA certificate. RA will then contact subscriber by phone for confirmation. –In the other cases, authentication is performed with the same procedure used to authenticate the identity of person.

Records Archival RA must record and archive –All requests (application form) –All confirmations CA must record and archive –All requests for certificates –All issued certificates –All requests for revocation –All issued CRLs –Login/Logout/Reboot of the issuing machine All archive data is restored in optical storage media The retention period for archives is three years

Physical Security The CA issuing machine is –dedicated machine –not connect to any network –located in a secure environment only accessible by CA administrator –private key and pass phrase are restored in optical storage media and locked in a safe

Technical Security Key Generation Key Restriction Certificate Restriction CRL Policy

Key Generation Private key is generated by browsers on the users’ machine. CA and RA will never generate the private key for users. CA and RA have no access to the users’ private key.

Key Restriction Key Length –ASGCCA private key is 2048 bits –Person private key must have at least 1024 bits –Host private key must has at least 1024 bits –Service private key must has at least 1024 bits Pass phrase –The pass phrase of CA’s private key is at least 15 characters –The pass phrase of end entity’s private key is at minimum 8 characters. –Protecting the pass phrase from others

Certificate Restriction Certificate Lifetime –Lifetime of ASGCCA certificate is 5 years –Lifetime of person certificate is one year –Lifetime of host certificate is one year –Lifetime of service certificates is one year User certificate should not be shared.

CRL Policy The lifetime of CRL is 30 days CRL is updated immediately after every revocation CRL is reissued 7 days before expiration even if there have been no revocations

Contact Information Yuan, Tein Horng Phone: Fax: Mail Box: Nankang PO BOX 1-8 Taipei, Taiwan 115 Address: 128, Sec. 2, Academic Rd., Nankang 115, Taipei, Taiwan

Related Information Homepage – CP/CPS –Follows the RFC 2527 structure – ASGCCA certificate – CRL –

The End