Self-Audit & Status Report for KEK GRID CA Hiroyuki Matsunaga KEK (High Energy Accelerator Research Organization), Computing Research Center APGridPMA.

Slides:



Advertisements
Similar presentations
Classic X.509 secured profile version 4.2 Proposed Changes David Groep, Apr 20 th, 2009.
Advertisements

Academia Sinica Grid Computing Certification Authority (ASGCCA) Yuan, Tein Horng Academia Sinica Computing Centre 13 June 2003.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien.
1 ASGCCA Self-Audit Report APGridPMA Jinny Chien March
CNIC Grid CA/SDG CA Self Audit Kejun (Kevin) Dong Computer Network Information Center (CNIC) Chinese Academy of Sciences APGridPMA F2F.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
1 REUNA Certificate Authority Juan Carlos Martínez REUNA Chile Rio de Janeiro,27/03/2006, F2F meeting, TAGPMA.
National Institute of Advanced Industrial Science and Technology Auditing, auditing template and experiences on being audited Yoshio Tanaka
Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien F2F Meeting 8 th March 2010.
NECTEC-GOC CA APGrid PMA face-to-face meeting. October, Sornthep Vannarat National Electronics and Computer Technology Center, Thailand.
KISTI Grid CA Status Report KISTI Supercomputing Center Sangwan Kim APGridPMA Meeting Mar 8, 2010 Academia Sinica, Taipei, Taiwan.
National Institute of Advanced Industrial Science and Technology Self-audit report of AIST GRID CA Yoshio Tanaka Information.
NAREGI CA Updates Kento Aida NAREGI CA/NII Kento Aida, National Institute of Informatics APGrid PMA meeting 04/20/2008.
DataGrid WP6 CA meeting, CERN, 12 December 2002 IISAS Certification Authority Jan Astalos Department of Parallel and Distributed Computing Institute of.
March 27, 2006TAGPMA - Rio de Janeiro1 Short Lived Credential Services Profile Tony J. Genovese The Americas Grid PMA DOEGridsATF/ESnet/LBNL.
National Institute of Advanced Industrial Science and Technology Brief status report of AIST GRID CA APGridPMA Singapore September 16 Yoshio.
NECTEC-GOC CA Self Audit 7 th APGrid PMA Face-to-Face meeting March 8 th, 2010 Large-Scale Simulation Research Laboratory Sornthep Vannarat Large-Scale.
IHEP Grid CA Status Report Gongxing Sun F2F Meeting 20 Apr Computing Centre, IHEP,CAS,China.
IHEP Grid CA Status Report Wei F2F Meeting 8 Mar Computing Centre, IHEP,CAS,China.
Profile for Portal-based Credential Services (POCS) Yoshio Tanaka International Grid Trust Federation APGrid PMA AIST.
Sam Morrison APAC CA – APGridPMA - ISGC2010 APAC CA Self Audit and status update Sam Morrison ARCS.
Academia Sinica Grid Computing Certification Authority (ASGCCA)
Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre.
European Grid Policy Management Authority. Event - 2/total Speaker Name – Coverage of the EUGridPMA Green: Countries with an accredited.
National Institute of Advanced Industrial Science and Technology Some topics from the OGF20 and the EUGrid PMA F2F Meeting Yoshio Tanaka Grid Technology.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien April 20, th APGridPMA in Taipei.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre.
KEK GRID CA updates Takashi Sasaki Computing Research Center KEK.
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
0 NAREGI CA Status Report APGrid F2F meeting in Singapore June 4, 2007 Rumiko Masuko.
KEK GRID CA Takashi Sasaki Computing Research Center KEK.
MICS Authentication Profile Maintenance & Update Presented for review and discussion to the TAGPMA On 1May09 by Marg Murray.
Update of APGridPMA APGridPMA Meeting Academia Sinica, Taiwan 22 March,
NIIF CA Status Update and Self-Audit Results 15 th EUGridPMA meeting Nicosia Tamás Máray NIIF Institute.
APGridPMA Update Eric Yen APGridPMA August, 2014.
Baltic Grid Certification Authority 15th EUGridPMA, January 28th 2009, Nicosia1 Self-audit Hardi Teder EENet.
TR-GRID CA Self-Auditing Results and Status Update EUGridPMA Meeting September 12-14, 2011 Marrakesh Feyza Eryol, Onur Temizsoylu TUBITAK-ULAKBIM
BG.ACAD CA HTTP :// CA. ACAD. BG S ELF - AUDIT REPORT 2014 Vladimir Dimitrov IICT-BAS ( 32 nd EUGridPMA Meeting Poznan, 8-10.
18 th EUGridPMA, Dublin / SRCE CA Self Audit SRCE CA Self Audit Emir Imamagić SRCE Croatia.
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
NECTEC-GOC CA A Brief Status Report 13 th APGrid PMA Face-to-Face meeting March 24 th, 2014 Large-Scale Simulation Research Laboratory Information Communications.
Feyza Eryol TÜBİTAK ULAKBİM TR-GRID CA SELF-AUDIT & UPDATES.
UGRID CA Self-audit report Sergii Stirenko 21 st EUGRIDPMA Meeting Utrecht 24 January 2011.
HellasGrid CA self Audit. In general We do operations well Our policy documents need work (mostly to make the text clearer in a few sections) 2.
Updates of APGrid PMA 18 th EUGridPMA Meeting 18 th EUGridPMA Meeting 18 January, 2010 Eric Yen ASGCCA Taiwan.
29 th EUGridPMA meeting, September 2013, Bucharest AEGIS Certification Authority Dušan Radovanović University of Belgrade Computer Centre.
IHEP Grid CA Status Report F2F Meeting 17 Mar Computing Centre, IHEP,CAS,China.
TNGrid CA 24 th EUGridPMA meeting Ljubljana, Slovenia, January, 2012 Heithem ABBES Mohamed JEMNI
Soapbox (S-Series) Certificate Validation Jens Jensen, STFC.
PKGrid CA Self-Audit 2012 Adeel-ur-Rehman Mansoor Sheikh.
IRAN-GRID CA Self Audit IRAN-GRID CA Self Audit Report Shahin Rouhani IRAN-GRID Tehran Iran Shahin Rouhani Grid Computation Group IPM, Tehran, Iran May.
Jens Jensen EU Grid PMA, Berlin Jan 2015
To the ETS – Accounts Setup and Preferences Online Training Course
AEGIS Certification Authority
Updates of the APGrid PMA
UGRID CA Sergii Stirenko, Oleg Alienin
Guidelines for auditing Grid CAs
Organized by governmental sector (National Institute of information )
UK e-Science CA and JCS Migration Status
MaGrid CA Self audit and update
NATIONAL CENTRE FOR PHYSICS PK-Grid-CA
To the ETS – Accounts Setup and Preferences Online Training Course
Emir Imamagić University Computing Centre (Srce)
Bill Yau HKU Grid Certificate Authority (HKU Grid CA) Self Audit & Status Report Bill Yau
MyIFAM CA Self-Audit Report APGridPMA F2F Meeting 1/4/2019
HKU Grid Certificate Authority (HKU Grid CA) CP/CPS Reviewer’s Comments Bill Yau
KISTI CA Report Status & Self-Audit
BG.ACAD CA Self-audit report 2018
OCSP Requirements GGF13.
Presentation transcript:

Self-Audit & Status Report for KEK GRID CA Hiroyuki Matsunaga KEK (High Energy Accelerator Research Organization), Computing Research Center APGridPMA F2F Sapporo, 17 Oct

2 March 11 14:46: Earthquake. March 11 15:10: UPS battery ran out, power down. March 15 11:00: Started checking CA/RA systems. ■ No physical damage to CA/RA observed. March 15 15:00: CA/RA functions restored. ■ No downtime since then. Recovery of the whole computing system took several months. ■ Due to severe limitation to the power consumption. ■ Still foresee power shortage this winter (and next summer). Prof. Sasaki canceled the last F2F meeting at Taipei. Ranging from I/O bound to CPU bound The faster the network the higher the I/O rate The lower the network latency the higher the I/O rate The more disks the higher the I/O rate The more RAM the more can be cached The more CPUs the faster the processing After the Earthquake

3 Staff User administrator: ■ H.M. since July ■ Prof. Takashi Sasaki stepped down. Security officer: ■ Yoshimi Iida CA operator: ■ Minoru Nakaya, Yukinori Yokoshima RA operator: ■ 2 people Help Desk: ■ 4

Self-Audit Following “Guidelines for auditing Grid CAs version 1.0” (GFD 169) ■ Also using “Authentication Profile for Classic X.509 CAs version 4.2” and other relevant materials Performed in January 2010 ■ The last external audit was done in April 2007 Sasaki-san already presented the results in a video/phone meeting last year ■ Reiterate it in this F2F meeting 4

Summary of Audit Results Results ■ Score B: 2 ■ Score C: 1 ■ Score D: 1 ■ N/A: 2 Comments on the above items will be shown in the next slides. 5

Score B (Minor Change) CA-(5) ■ Whenever there is a change in the CP/CPS the OID of the document MUST change. ■ OID was not changed for minor corrections. CA-(34) ■ The EE certificate MUST have a maximum lifetime of 1 year plus 1 month. ■ Extended a lifetime from 365 days to 1 year plus 1 month. 6

Score C (Major Change) CA-(7) ■ CP/CPS documents SHOULD be structured as defined in RFC ■ Still in RFC Will be modified in the future, most likely in

Score D (Must Change) CA-(16) ■ The on-line CA architecture MUST provide for a log of issued certificates and revocations. The log SHOULD be tamper- protected. ■ Due to limitation of the hardware (nCipher HSM), the log is not tamper-protected. ■ HSM will be replaced when migrating to the new system. 8

N/A CA-(2) ■ There SHOULD be a single CA per country, region, or international organization. RA-(5) ■ RA MUST validate the association of the certificate signing request. ■ CA software does instead. 9

Status CP/CPS: ■ 2.1.1: Extend the certificate’s validity period ■ 2.1.2: Minor update on Certificate and CRL Profile Annual Identity Check ■ Performed in July and August 2011 ■ After the end of JFY 2010, but delayed due to disaster recovery ■ Based on self-declaration by users ■ Disabled 83 user accounts ■ Revoked 13 user certificates 10

11 Issued Certificates (as of 1 st Oct.) Users ■ Total: 279 ■ Valid: 157 User certificates ■ Total: 1096 ■ Valid: 125 Host certificates ■ Total: 1759 ■ Valid: 230

12 System Replacement Lease term of the current system ends in February 2012 Will migrate to the new system in coming winter ■ Started preparatory work for the migration ■ Continue to use NAREGI CA Tool ■ Software will be updated ■ New HSM will be used ■ System downtime expected twice during the migration ■ CA/RA will move to the new hardware in December ■ The whole computing system will migrate in February