Presentation is loading. Please wait.

Presentation is loading. Please wait.

BG.ACAD CA Self-audit report 2018

Similar presentations


Presentation on theme: "BG.ACAD CA Self-audit report 2018"— Presentation transcript:

1 BG.ACAD CA http://ca.acad.bg Self-audit report 2018
Vladimir Dimitrov IICT-BAS ( 44th EUGridPMA Meeting Toulouse, Sep 2018 (9 slides)

2 44th EUGridPMA Meeting, Toulouse, 24-26 Sep 2018
BG.ACAD CA Overview (1) BG.ACAD CA is member since Serves academic community in Bulgaria Located in Sofia, IICT-BAS Implementation, simple: Online CA based on Scientific Linux 6.9 and Apache. Offline Signing machine with recent FreeBSD, OpenSSL and some own developed scripts. Issued 1021 certificates since 2007: Personal: 507 Hosts: Services (robot): 1 Revoked certificates: 21 Currently valid certificates (total): 65 bot 44th EUGridPMA Meeting, Toulouse, Sep 2018

3 44th EUGridPMA Meeting, Toulouse, 24-26 Sep 2018
BG.ACAD CA Overview (2) Current CP/CPS revision: 1.2, OID: TACAR member since Jan 2013 Since 5 May 2014 all new EE certificates are hashed with SHA-256. The last SHA-1 certificate expired in Jan 2015. CRL is hashed with SHA-256. In 2016 the root certificate was extended to 2027, also hashed with SHA-256, same private key. The Online CA machine has full IPv6 support. CA staff members: 3 RAs: 10 people from 3 cities and 9 institutions in Bulgaria. 44th EUGridPMA Meeting, Toulouse, Sep 2018

4 44th EUGridPMA Meeting, Toulouse, 24-26 Sep 2018
Self-audit The previous self-audit was presented during the 32nd meeting in Poznan, Sep and was approved in 36th meeting, Bratislava, Jan 2016. The current Self-audit was done in accordance with the Guidelines for auditing Grid CAs version 1.1, 2010 and OGF GFD.169 document. Audit dates: Sep 2018 Reviewers: TBD Summary: A: 66 Good. B: 0 Recommendation (minor change) C: 0 Recommendation (major change) D: 0 Advice (must change) X: 0 Could not evaluate (N/A) 44th EUGridPMA Meeting, Toulouse, Sep 2018

5 44th EUGridPMA Meeting, Toulouse, 24-26 Sep 2018
Pre-examination CP/CPS – yes, in repository Relevant IGTF Authentication Profile(s) - yes Manuals for subscribers – yes, in repository Operational manuals – yes, available for the CA members CA Repository (e.g. Web site) - yes , CA Certificate – yes, in repository CRL – yes, in repository End entity certificates – yes, in repository HSM manual – N/A, offline signing machine. Any other document described as published in the repository in the CP/CPS – yes, EE statement, user guide. Any other document available for the auditors: EE declarations and evidences for user employment – yes, on papers. 44th EUGridPMA Meeting, Toulouse, Sep 2018

6 44th EUGridPMA Meeting, Toulouse, 24-26 Sep 2018
Main examination (1) CA room for Online CA machine: located in IICT-BAS, in the main NOC of Bulgarian NREN (BREN). Restricted access, CCTV, fire alarm system. CA room for Offline CA signing machine: located in IICT-BAS inside the main academic HPC and data center. Access with personal RFID cards and keys, CCTV, 24/7 surveillance, fire alarm system. The removable hard disks of the machine are locked in a dedicated safe box. HSM – not present. Backup media of the CA private key – Yes. Burned on a CD-R and locked in a dedicated safe box on another floor in IICT-BAS. Offline media (sealed envelope) which contains a pass phrase of the CA private key – Yes. In the same safe box as above. But we haven’t another dedicated safe box for now. 44th EUGridPMA Meeting, Toulouse, Sep 2018

7 44th EUGridPMA Meeting, Toulouse, 24-26 Sep 2018
Main examination (2) Media storage of archived logs and other documents and their place – Yes, the logs of offline CA are included in the full backups on 2 flash cards in a dedicated safe box. End entity certificates (if not available for the pre-examination), including issuance activities – Yes, in the repository. Logs of the CA/RA servers – No, there are no such servers. Logs of the CA repository (e.g. Web server) - Yes, on the server and included in the regular backups on a dedicated separated storage array. Records of operation of the CA private key (including accesses to the HSM) – Yes. Access log to the CA room – Yes. In the central security system. Based on the personal RFID cards usage. Any other documents (e.g. daily report of the CA operators) – No. 44th EUGridPMA Meeting, Toulouse, Sep 2018

8 44th EUGridPMA Meeting, Toulouse, 24-26 Sep 2018
Auditing Checklist There are 66 A scores (all good). Some difficulties when using the proposed Excel file for RFC This file: So I read the relevant texts and decided if we did them. 44th EUGridPMA Meeting, Toulouse, Sep 2018

9 44th EUGridPMA Meeting, Toulouse, 24-26 Sep 2018
Additional changes Perhaps chapter 9.4 will need to be slightly modified according to GDPR. But long time ago it was very Jesuitical written and should not have a problem now. End of Self-Audit Questions? Vladimir Dimitrov, 44th EUGridPMA Meeting, Toulouse, Sep 2018


Download ppt "BG.ACAD CA Self-audit report 2018"

Similar presentations


Ads by Google