IRAN-GRID CA Self Audit IRAN-GRID CA Self Audit Report Shahin Rouhani IRAN-GRID Tehran Iran Shahin Rouhani Grid Computation Group IPM, Tehran, Iran May.

Slides:



Advertisements
Similar presentations
Academia Sinica Grid Computing Certification Authority (ASGCCA) Yuan, Tein Horng Academia Sinica Computing Centre 13 June 2003.
Advertisements

Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien.
1 ASGCCA Self-Audit Report APGridPMA Jinny Chien March
CNIC Grid CA/SDG CA Self Audit Kejun (Kevin) Dong Computer Network Information Center (CNIC) Chinese Academy of Sciences APGridPMA F2F.
ESOS COMPLIANCE PROCESS 26 FEBRUARY REGULATORY APPROACH.
1 REUNA Certificate Authority Juan Carlos Martínez REUNA Chile Rio de Janeiro,27/03/2006, F2F meeting, TAGPMA.
National Institute of Advanced Industrial Science and Technology Auditing, auditing template and experiences on being audited Yoshio Tanaka
HEBCA – Higher Education Bridge Certification Authority Presented by Scott Rea and Mark Franklin, Fed/Ed Meeting, 12/14/2005.
9/20/2000www.cren.net1 Root Key Cutting and Ceremony at MIT 11/17/99.
UNAMgrid CA Juan Carlos Guel UNAM, México. Alejandro Núñez UNAM, México. Israel Becerril UNAM, México. DGSCA UNAM 31/08/06.
Tweaking the Certificate Lifecycle for the UK eScience CA John Kewley NGS Support Centre Manager & Service Manager for the UK e-Science CA
NECTEC-GOC CA APGrid PMA face-to-face meeting. October, Sornthep Vannarat National Electronics and Computer Technology Center, Thailand.
National Institute of Advanced Industrial Science and Technology Self-audit report of AIST GRID CA Yoshio Tanaka Information.
DataGrid WP6 CA meeting, CERN, 12 December 2002 IISAS Certification Authority Jan Astalos Department of Parallel and Distributed Computing Institute of.
JSPG: User-level Accounting Data Policy David Kelsey, CCLRC/RAL, UK LCG GDB Meeting, Rome, 5 April 2006.
NECTEC-GOC CA Self Audit 7 th APGrid PMA Face-to-Face meeting March 8 th, 2010 Large-Scale Simulation Research Laboratory Sornthep Vannarat Large-Scale.
IHEP Grid CA Status Report Gongxing Sun F2F Meeting 20 Apr Computing Centre, IHEP,CAS,China.
IHEP Grid CA Status Report Wei F2F Meeting 8 Mar Computing Centre, IHEP,CAS,China.
IHEP Grid CA Status Report Gongxing Sun 5 th F2F Meeting 16 Sep Computer Center, IHEP,CAS,China.
Profile for Portal-based Credential Services (POCS) Yoshio Tanaka International Grid Trust Federation APGrid PMA AIST.
UNAMgrid Alejandro Núñez Sandoval Rio de Janeiro, Brazil, 03/27/06 F2F meeting, TAGPMA.
KISTI Grid CA Status Report Korea Institute of Science and Technology Information Sangwan Kim Jae-Hyuck Kwan
Sam Morrison APAC CA – APGridPMA - ISGC2010 APAC CA Self Audit and status update Sam Morrison ARCS.
Academia Sinica Grid Computing Certification Authority (ASGCCA)
Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien.
National Institute of Advanced Industrial Science and Technology Some topics from the OGF20 and the EUGrid PMA F2F Meeting Yoshio Tanaka Grid Technology.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien April 20, th APGridPMA in Taipei.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre.
Lessons Learned from disaster recovery Jinny Chien April 20, th APGridPMA in Taipei.
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
APGrid PMA face-to-face meeting, 9/16/2008 PRAGMA-UCSD CA Team Pacific Rim Application and Grid Middleware Assembly
0 NAREGI CA Status Report APGrid F2F meeting in Singapore June 4, 2007 Rumiko Masuko.
NIIF CA Status Update and Self-Audit Results 15 th EUGridPMA meeting Nicosia Tamás Máray NIIF Institute.
Baltic Grid Certification Authority 15th EUGridPMA, January 28th 2009, Nicosia1 Self-audit Hardi Teder EENet.
TR-GRID CA Self-Auditing Results and Status Update EUGridPMA Meeting September 12-14, 2011 Marrakesh Feyza Eryol, Onur Temizsoylu TUBITAK-ULAKBIM
HKU Computer Centre Grid Certificate Authority Status Update Lilian Chan IT Services, The University of Hong Kong APGrid.
FP6−2004−Infrastructures−6-SSA [ Empowering e Science across the Mediterranean ] Rome, Tutorial for Certification Authority Managers,
BG.ACAD CA HTTP :// CA. ACAD. BG S ELF - AUDIT REPORT 2014 Vladimir Dimitrov IICT-BAS ( 32 nd EUGridPMA Meeting Poznan, 8-10.
18 th EUGridPMA, Dublin / SRCE CA Self Audit SRCE CA Self Audit Emir Imamagić SRCE Croatia.
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
NECTEC-GOC CA A Brief Status Report 13 th APGrid PMA Face-to-Face meeting March 24 th, 2014 Large-Scale Simulation Research Laboratory Information Communications.
Feyza Eryol TÜBİTAK ULAKBİM TR-GRID CA SELF-AUDIT & UPDATES.
UGRID CA Self-audit report Sergii Stirenko 21 st EUGRIDPMA Meeting Utrecht 24 January 2011.
HellasGrid CA self Audit. In general We do operations well Our policy documents need work (mostly to make the text clearer in a few sections) 2.
Armenian e-Science Foundation Certification Authority Ara A. Grigoryan 1,2, Artem Harutyunyan 1,2,3, Arsen Hayrapetyan 1,2,4 1 Armenian e-Science Foundation;
29 th EUGridPMA meeting, September 2013, Bucharest AEGIS Certification Authority Dušan Radovanović University of Belgrade Computer Centre.
IHEP Grid CA Status Report F2F Meeting 17 Mar Computing Centre, IHEP,CAS,China.
TNGrid CA 24 th EUGridPMA meeting Ljubljana, Slovenia, January, 2012 Heithem ABBES Mohamed JEMNI
IRAN-GRID Certificate Authority 13 th EUgridPMA Meeting Copenhagen May 2008 Majid Arabgol Hessamdding Arfaei Shahin Rouhani
Self-Audit & Status Report for KEK GRID CA Hiroyuki Matsunaga KEK (High Energy Accelerator Research Organization), Computing Research Center APGridPMA.
PKGrid CA Self-Audit 2012 Adeel-ur-Rehman Mansoor Sheikh.
Jens Jensen EU Grid PMA, Berlin Jan 2015
J Jensen, STFC Chief Soapbox Officer 23 May 2017
AEGIS Certification Authority
UGRID CA Sergii Stirenko, Oleg Alienin
SUBMITTING REQUESTS FOR PROPOSAL ELECTRONICALLY
Guidelines for auditing Grid CAs
NAREGI-CA Development of NAREGI-CA NAREGI-CA Software CP/CPS Audit
HellasGrid CA & euGridPMA
Tweaking the Certificate Lifecycle for the UK eScience CA
MaGrid CA Self audit and update
NATIONAL CENTRE FOR PHYSICS PK-Grid-CA
BCS Template Presentation February 22, 2018
Emir Imamagić University Computing Centre (Srce)
Bill Yau HKU Grid Certificate Authority (HKU Grid CA) Self Audit & Status Report Bill Yau
MyIFAM CA Self-Audit Report APGridPMA F2F Meeting 1/4/2019
HKU Grid Certificate Authority (HKU Grid CA) CP/CPS Reviewer’s Comments Bill Yau
KISTI CA Report Status & Self-Audit
BG.ACAD CA Self-audit report 2018
Presentation transcript:

IRAN-GRID CA Self Audit IRAN-GRID CA Self Audit Report Shahin Rouhani IRAN-GRID Tehran Iran Shahin Rouhani Grid Computation Group IPM, Tehran, Iran May 2014

IRAN-GRID CA Self Audit Overview IRAN-GRID CA Self Audit Conclusions

IRAN-GRID CA Self Audit IRAN-GRID CA

IRAN-GRID CA Self Audit Established in May 2008 Certificates for the Iranian academic and research community Public web site: Address Institute for Research in Fundamental Sciences (IPM), Niavaran square., Niavaran Bldg. Tehran, Iran, P. O. Box Tel: Fax:

IRAN-GRID CA Self Audit Organization CA & IRAN-GRID –Two staff members:  Shahin Rouhani,  Heydar Saadatmand Javan

IRAN-GRID CA Self Audit System Architecture OpenCA (to be upgraded) Online interface (RA) –Used for certificate requests –Used by RA for request confirmations –Deployed on institute’s main web server Offline (CA) –Laptop and backup media kept in safe accessible to CA staff only –Data transfer achieved by USB –Data backup performed after each operation

IRAN-GRID CA Self Audit Certificates Total: 20 issued certificates –Host: 10 –User: 10 Revoked: –user 11 –Host 2

IRAN-GRID CA Self Audit CP/CPS Update April 2010 Upgraded to RFC 3647

IRAN-GRID CA Self Audit SHA2 Upgrade Planned for June 2014

IRAN-GRID CA Self Audit Self audit

IRAN-GRID CA Self Audit Versions Guidelines for auditing Grid CAs version 1.0, by Y Tanaka, M Viljoen, S Rea –February 17, –Slight change: award marks instead of letters according to: D = 0 Advice (must change) C = 1 Recommendation (major change) B = 2 Recommendation (minor change) A = 3 Good X not available to check –This method provides a total numerical score IRAN-GRID CA CP/CPS Version 2.0(approved) –13 April 2010 –Available on

IRAN-GRID CA Self Audit Summary 1. Pre-examination –Operational Manuals for RA-CA staff were non existent. CA obliged to prepare manuals within two months 2. Main Examination –Total number of items: 70 –Total score: 207/210 ~ 98% Marks: –0: None –1: None –2: 3 items –3: 67 items –X: None

IRAN-GRID CA Self Audit Certification authority

IRAN-GRID CA Self Audit CP/CPS The CP/CPS documents should be structured as defined in RFC IRAN-GRID CA has upgraded to RFC 3647.

IRAN-GRID CA Self Audit CA System The secure environment must be documented and approved by the PMA, and that document or an approved audit thereof must be available to the PMA. This environment has only been audited by management 0f IPM- Grid. Last audit was in 2010, 2012 Audit was missed.

IRAN-GRID CA Self Audit Certificate Revocation List Every CA must issue a new CRL at least 7 days before expiration. Although it has never reached 0 days but sometimes at less than 7 days.

IRAN-GRID CA Self Audit Publication and repository responsibilities The repository must be run at least on a best-effort basis, with an intended availability of 24x7. With the exception of some downtime, this has been achieved. Downtimes happened mainly due to operator negligence in the server room.

IRAN-GRID CA Self Audit Registration authority

IRAN-GRID CA Self Audit Records and archival The CA is responsible for maintaining an archive of these records in an auditable form. Records were kept in a mixture of digital and paper. It was recommended that a complete parallel digital and paper format should be kept.

IRAN-GRID CA Self Audit Conclusion Our next Audit in 2016 Proposed changes and recommendations will be done during 2014; Upgrade OpenCA to 1.5.1; Upgrade to SHA2.

IRAN-GRID CA Self Audit Thank You!