KEK GRID CA updates Takashi Sasaki Computing Research Center KEK.

Slides:



Advertisements
Similar presentations
Digital Certificate Installation & User Guide For Class-3 Certificates.
Advertisements

Digital Certificate Installation & User Guide For Class-2 Certificates.
Installation & User Guide
Digital Certificate Installation & User Guide For Class-2 Certificates.
Digital Certificate Installation & User Guide For Class-2 Certificates.
Grid Computing, B. Wilkinson, 20045a.1 Security Continued.
SECURE SITES. A SECURE CONNECTION TERMS Secure Sockets Layer (SSL) An older Internet protocol that allows for data transmission between server and client.
CNIC Grid CA/SDG CA Self Audit Kejun (Kevin) Dong Computer Network Information Center (CNIC) Chinese Academy of Sciences APGridPMA F2F.
Lecture 23 Internet Authentication Applications
Environmental Council of States Network Authentication and Authorization Services The Shared Security Component February 28, 2005.
Public Key Infrastructure (PKI) Providing secure communications and authentication over an open network.
PKI Activities at Virginia January 2004 CSG Meeting Jim Jokl.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
Dartmouth PKI Deployment Robert Brentrup PKI Summit July 14, 2004.
Summer School Certificates Diego Romano & Gilda Team.
Use of Kerberos-Issued Certificates at Fermilab Kerberos  PKI Translation Matt Crawford & Dane Skow Fermilab.
Virginia Tech Overview of Tech Secure Enterprise Technology Initiatives e-Provisioning Group Frank Galligan Fed/Ed.
Digital Certificate Installation & User Guide For Class - 2 Certificates.
Wolfgang Schneider NSI: A Client-Server-Model for PKI Services.
Security Directions - Release 6 and beyond SearchDomino.com Webcast Patricia Booth Security and Directory Product Management 9/25/02.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien F2F Meeting 8 th March 2010.
Securing Microsoft® Exchange Server 2010
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
UNAMgrid CA Juan Carlos Guel UNAM, México. Alejandro Núñez UNAM, México. Israel Becerril UNAM, México. DGSCA UNAM 31/08/06.
 Academic   Administrative ◦ Departments  Desktop Services  Networking & Telecommunications  Computer Center ◦ Office of Computer and Information.
NECTEC-GOC CA APGrid PMA face-to-face meeting. October, Sornthep Vannarat National Electronics and Computer Technology Center, Thailand.
Lecture 23 Internet Authentication Applications modified from slides of Lawrie Brown.
National Institute of Advanced Industrial Science and Technology Self-audit report of AIST GRID CA Yoshio Tanaka Information.
NAREGI CA Updates Kento Aida NAREGI CA/NII Kento Aida, National Institute of Informatics APGrid PMA meeting 04/20/2008.
Computer Security: Principles and Practice First Edition by William Stallings and Lawrie Brown Lecture slides by Lawrie Brown Chapter 22 – Internet Authentication.
Chapter 23 Internet Authentication Applications Kerberos Overview Initially developed at MIT Software utility available in both the public domain and.
DataGrid WP6 CA meeting, CERN, 12 December 2002 IISAS Certification Authority Jan Astalos Department of Parallel and Distributed Computing Institute of.
National Institute of Advanced Industrial Science and Technology Brief status report of AIST GRID CA APGridPMA Singapore September 16 Yoshio.
Module 9: Fundamentals of Securing Network Communication.
NECTEC-GOC CA Self Audit 7 th APGrid PMA Face-to-Face meeting March 8 th, 2010 Large-Scale Simulation Research Laboratory Sornthep Vannarat Large-Scale.
Introduction of NAREGI-CA National Institute of Informatics JAPAN Toshiyuki Kataoka, July 19, 2006 APAN Grid-Middleware Workshop, Singapore.
The Distribution Online Vending Pilot Project Demo Testing Certificate Management Kennedy P Subramoney 23 July 2004.
IHEP Grid CA Status Report Gongxing Sun 5 th F2F Meeting 16 Sep Computer Center, IHEP,CAS,China.
Profile for Portal-based Credential Services (POCS) Yoshio Tanaka International Grid Trust Federation APGrid PMA AIST.
Sam Morrison APAC CA – APGridPMA - ISGC2010 APAC CA Self Audit and status update Sam Morrison ARCS.
HEPSYSMAN UCL, 26 Nov 2002Jens G Jensen, CLRC/RAL UK e-Science Certification Authority Status and Deployment.
Academia Sinica Grid Computing Certification Authority (ASGCCA)
KISTI Grid CA Operation KISTI Supercomputing Center Sangwan Kim, Soonwook Hwang CA Operators Contact: Jan. 8, 2007.
The Intranet.
Who’s watching your network The Certificate Authority In a Public Key Infrastructure, the CA component is responsible for issuing certificates. A certificate.
Fermilab CA Infrastructure EDG CA Managers Mtg June 13, 2003.
Grid technology Security issues Andrey Nifatov A hacker.
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
0 NAREGI CA Status Report APGrid F2F meeting in Singapore June 4, 2007 Rumiko Masuko.
KEK GRID CA Takashi Sasaki Computing Research Center KEK.
8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK
MICS Authentication Profile Maintenance & Update Presented for review and discussion to the TAGPMA On 1May09 by Marg Murray.
Gilda certificates. Certification Authority
HKU Computer Centre Grid Certificate Authority Status Update Lilian Chan IT Services, The University of Hong Kong APGrid.
18 th EUGridPMA, Dublin / SRCE CA Self Audit SRCE CA Self Audit Emir Imamagić SRCE Croatia.
GRID-FR French CA Alice de Bignicourt.
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
UGRID CA Self-audit report Sergii Stirenko 21 st EUGRIDPMA Meeting Utrecht 24 January 2011.
HellasGrid CA self Audit. In general We do operations well Our policy documents need work (mostly to make the text clearer in a few sections) 2.
29 th EUGridPMA meeting, September 2013, Bucharest AEGIS Certification Authority Dušan Radovanović University of Belgrade Computer Centre.
Digital Certificates Presented by: Matt Weaver. What is a digital certificate? Trusted ID cards in electronic format that bind to a public key; ex. Drivers.
Self-Audit & Status Report for KEK GRID CA Hiroyuki Matsunaga KEK (High Energy Accelerator Research Organization), Computing Research Center APGridPMA.
SFS-HTTP: Securing the Web with Self-Certifying URLs
AEGIS Certification Authority
Configuring and Troubleshooting Routing and Remote Access
Installation & User Guide
Secure Enterprise Technology Initiatives e-Provisioning Group
Installation & User Guide
Managing Services with VMM and App Controller
Bill Yau HKU Grid Certificate Authority (HKU Grid CA) Self Audit & Status Report Bill Yau
Presentation transcript:

KEK GRID CA updates Takashi Sasaki Computing Research Center KEK

Operation statistics Issued certificates –User: Valid: 90 Invalid: 304 –Host: Valid; 220 Invalid 591 Total number of users: 169 –Disabled: 15 –Inactive: 64 userhost

Hardware replacement and operation changes We have upgraded the CA hardware as reported earlier Operation procedure and role assignments are also going to be changed –We soon update our CP/CPS according to this change

RA Server CA Server User Administrator CA Operator Security Officer Help Desk Certificate User Host Administrator Old CA System - administrates all tasks on the CA system including the CA private key -maintains the CA system -creates users ids and distribute them - accepts user enrollment - examines user information and approve the use -a user using a certificate issued by KEK GRID CA -an administrator of a host using a certificate issued by KEK GRID CA

Organization Diagram from CP/CPS Private Key Management Accept CSR, revocation, registration and user registration Host Administrator Certificate User

RA Server CA Server User Administrator CA Operator Security Officer Help Desk Certificate User Host Administrator RA Operator New delegate the operation to create users ids and distribute them, from CA Operator to RA Operator CA System

CA Operation Role Assignment Before March –Security Officer Yoshimi Iida Kohki Ishikawa –User Administrator Takashi Sasaki –CA Operator Yukinori Yokoshima Minoru Nakaya After April –Security Officer Yoshimi Iida Manabu Matsui –User Administrator Takashi Sasaki –CA Operator Yukinori Yokoshima Minoru Nakaya –RA Operator Katsumi Kikuchi Masato Wada

Operation Diagram

RA ServerCA Server User Administrator CA Operator Security Officer Certificate User Host Administrator RA Operator New User Registration CA System 2. Interview 1.. Application with Photo ID 1.. Application with Photo ID 5. Return User ID and Initial Password 5. Return User ID and Initial Password 6. Return User ID and Initial Password to End User 6. Return User ID and Initial Password to End User 3. Register User 4. Get Initial Password 7. Change Password Reject, If needed

RA ServerCA Server User Administrator CA Operator Security Officer Certificate User Host Administrator RA Operator After User Registration CA System 1. Request Operation 2. System Response Once registered, Certificate User and Host Administrator can access directly RA to request CA services. They can perform following activities: -User Profile Self Management -Password Chang -Request User Certificate -Request Host Certificate -Request Certificate Revocation Once registered, Certificate User and Host Administrator can access directly RA to request CA services. They can perform following activities: -User Profile Self Management -Password Chang -Request User Certificate -Request Host Certificate -Request Certificate Revocation

RA CA Client HSM Internet F/W DMZ 1.All users should download NAREGI-CA package from RA Web, and install into their machines. 2.Users can create private key and certificates signing request (CSR) on their client machine using client toolkit or Web browser extension (Internet Explorer only ) 3.Users send CSR to RA server 4.RA server identify and verify users, and then accept users’ CSR. 5.RA forward CSR to CA 6.CA signs and publish new certificate with its private key, protected by HSM 7.CA return signed certificate to RA. 8.RA returns published signed certificate to user. KEK GRID CA System Certificate Request Procedure * KEK GRID CA bases on NAREGI-CA software * *All network connection encrypted with SSL (Informational) Not Changed

RA ServerCA Server User Administrator CA Operator Security Officer Certificate User Host Administrator RA Operator User Support and How to handle irregular Request CA System Help Desk 1. Request or Question 3. Sharing Information 2. Forward Question 4. Perform Response

External audit Hopefully, end of May or June Volunteers needed –Anyone, please!