Presentation is loading. Please wait.

Presentation is loading. Please wait.

APGrid PMA face-to-face meeting, 9/16/2008 PRAGMA-UCSD CA Team Pacific Rim Application and Grid Middleware Assembly

Similar presentations


Presentation on theme: "APGrid PMA face-to-face meeting, 9/16/2008 PRAGMA-UCSD CA Team Pacific Rim Application and Grid Middleware Assembly"— Presentation transcript:

1 APGrid PMA face-to-face meeting, 9/16/2008 PRAGMA-UCSD CA Team http://www.pragma-grid.net/ca Pacific Rim Application and Grid Middleware Assembly http://www.pragma-grid.net http://goc.pragma-grid.net PRAGMA-UCSD CA Status Update

2 APGrid PMA face-to-face meeting, 9/16/2008 Overview Since The Last APGrid Meeting Certificates Issued Operations Changes

3 APGrid PMA face-to-face meeting, 9/16/2008 Since The Last APGrid Meeting 4/7/08 - Accredited in APGrid Taipei meeting 4/20/08 - Yoshio informed us a resolution in APGrid Taipei meeting about best practice pertaining Issuer and Subject names 4/24/08~6/24/08 – Worked with NAREGI-CA team for a new version of CA software and setup new CA with “Issuer: DC=NET, DC=PRAGMA-GRID, CN=PRAGMA-UCSD CA” 6/25/08~6/26/08 - Updated CP/CPS, user guides and internal documentations to reflect the change in Issuer and Subject name –http://goc.pragma-grid.net/ca/ca-certs/http://goc.pragma-grid.net/ca/ca-certs/ –http://goc.pragma-grid.net/ca/cp-cps/http://goc.pragma-grid.net/ca/cp-cps/ –goc.pragma-grid.net/ca/internal/PRAGMA-UCSD-CA-operation.doc (require login) –http://goc.pragma-grid.net/secure/pragma-ucsd-ca-client.tar.gzhttp://goc.pragma-grid.net/secure/pragma-ucsd-ca-client.tar.gz –https://goc.pragma-grid.net/secure/pragma-ucsd-ca-client-user- guide.dochttps://goc.pragma-grid.net/secure/pragma-ucsd-ca-client-user- guide.doc 6/27/08 – Start operation 7/28/08 – Included in IGTF distribution 1.23

4 APGrid PMA face-to-face meeting, 9/16/2008 Certificates Issued 10 host certificates are issued for PRAGMA grid servers and clusters at SDSC No user certificate have been issued so far All 6 certificates (3 hosts and 3 users) used for testing during PRAGMA-UCSD CA server setup have been revoked

5 APGrid PMA face-to-face meeting, 9/16/2008 Operations CRL updates have been done every 3 weeks –One failure of retrieval due to the web server 1 day outage Backup has been performed according to CP/CPS and operation manual User/host certificate requests and issuances have been done following the procedures and rules set in CP/CPS

6 APGrid PMA face-to-face meeting, 9/16/2008 No Change In Personnel CA – Cindy Zheng, Mason Katz (UCSD) RA – Mason Katz, Anoop Rajendra (UCSD) PMA – Yoshio Tanaka (AIST) Security Officer – Phil Papadopoulos (UCSD) pragma-ucsd-ca@sdsc.edu reaches no more and no less than these 5 peoplepragma-ucsd-ca@sdsc.edu

7 APGrid PMA face-to-face meeting, 9/16/2008 No Change In Equipment CA server is dedicated and off-line RA server is dedicated and on-line CA software is naregi-wp5-nas-070112

8 APGrid PMA face-to-face meeting, 9/16/2008 One Change In Physical Security

9 APGrid PMA face-to-face meeting, 9/16/2008 No Change In CA Key and Passphrase CA key length 2048 bits (6.1.5) CP-CPS 6.4 describes CA key protection –Pass phrase >= 15 characters. –Only known by CA and RA. –In 2 sealed envelopes in 2 separate locked drawers in Cindy (CA) and Mason (RA)’s office. Only Cindy and Mason have the keys to the drawers. –The sealed envelops are kept separated from the backed up private key.

10 APGrid PMA face-to-face meeting, 9/16/2008 No Change In Private Key Backup On offline media – USB drives Kept in a locked cabinet Only Anoop (RA) has the key

11 APGrid PMA face-to-face meeting, 9/16/2008 No Change In Web Repository Policies Public accessible http://goc.pragma-grid.net/ca http://goc.pragma-grid.net/ca –CA root certificates –Certificates issued –CRL –CP/CPS –Contact info Grant APGrid PMA and IGTF unlimited re- distribution Internal only –Operation manuals –Canned emails –Forms –Check list –CA profiles Only CA staff and auditors allowed access

12 APGrid PMA face-to-face meeting, 9/16/2008 Special Thanks to Naregi-CA developer, Takuto Okuno For upgrade Naregi-CA software which enabled us to implement the best practice set by APGrid PMA


Download ppt "APGrid PMA face-to-face meeting, 9/16/2008 PRAGMA-UCSD CA Team Pacific Rim Application and Grid Middleware Assembly"

Similar presentations


Ads by Google