EUGridPMA 41 and IGTF All-Hands Meeting

Slides:



Advertisements
Similar presentations
National Institute of Advanced Industrial Science and Technology Asia Pacific Grid PMA Yoshio Tanaka APGrid PMA, Chair Grid Technology Research Center,
Advertisements

2 nd APGrid PMA F2F Meeting Osaka University Convention Center October 15 09: :20 # Participants: 26.
Updates of the APGrid PMA Catania March 3, 2009 Yoshio Tanaka APGridPMA Chair, AIST, Japan.
International Grid Trust Federation Session GGF 20 Manchester, UK Wednesday, May CAOPS-WG session #2.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
4 th APGrid PMA F2F Meeting Academia Sinica, Taipei, Taiwan April 8, 2008 Agendahttp:// Call for note takers!
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Policy Issues for Identity Management (and other attributes) EGI Technical.
FIM-related activities and issues being discussed in Japan 1.GEO Grid Yoshio Tanaka (AIST) 2.HPCI, GakuNin Eisaku Sakane, Kento Aida (NII)
Updates of APGrid PMA 22 June, Members (15 + 1) 15 Accredited CAs AIST (JP) APAC (AU) ASGC (TW) CNIC (CN), SDG IGCA (IN) IHEP (CN) KEK (JP) KISTI.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
User Certificate Application: ASGCCA. Agenda Introduction ASGCCA User Responsibilities Certificate application form RA verify identity of users User generate.
TAGPMA & the Bridge WG (Scott Rea – Dartmouth College) Internet2 Member Meeting, Dec 2006 PKI Activities and Applications Update - Chicago, IL.
International Grid Trust Federation Session GGF 20 Manchester, UK Wednesday, May CAOPS-WG session #2.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien April 20, th APGridPMA in Taipei.
National Institute of Advanced Industrial Science and Technology Updates of the APGrid PMA Yoshio Tanaka APGrid PMA, Chair Grid Technology Research Center,
NRENs, Grids and Integrated AAI In Search For the Utopian Solution Christos Kanellopoulos AUTH/GRNET October 17 th, 2005 skanct at physics.auth.gr 2nd.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Opening Remarks and Updates of the APGrid PMA 5 th APGridPMA September 16, 2008 Yoshio Tanaka APGridPMA Chair, AIST, Japan.
Community PKIs Initiatives Updates TF-EMC2 Meeting Loughborough, UK 6-7 May, 2009 Licia Florio, TERENA
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Update of APGridPMA APGridPMA Meeting Academia Sinica, Taiwan 22 March,
APGridPMA Update Eric Yen APGridPMA August, 2014.
Summary of Poznan EUGridPMA32 September EUGridPMA Poznan 2014 meeting – 2 David Groep – Welcome back at PSNC.
Disaster Mitigation Competence Centre Project Meeting Coordinator: Simon Lin July 7, 2015.
A Study of Certification Authority Integration Model in a PKI Trust Federation on Distributed Infrastructures for Academic Research Eisaku SAKANE, Takeshi.
Co-ordination & Harmonisation of Advanced e-Infrastructures for Research and Education Data Sharing Research Infrastructures Grant Agreement n
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
Update of APGridPMA Eric Yen 25 th EUGridPMA & IGTF All Hands Meeting KIT, Germany 7 May, 2012.
Feyza Eryol TÜBİTAK ULAKBİM TR-GRID CA SELF-AUDIT & UPDATES.
APGridPMA Update Eric Yen 35 th Amsterdam, NL September 7, 2015.
Updates of APGrid PMA 18 th EUGridPMA Meeting 18 th EUGridPMA Meeting 18 January, 2010 Eric Yen ASGCCA Taiwan.
29 th EUGridPMA meeting, September 2013, Bucharest AEGIS Certification Authority Dušan Radovanović University of Belgrade Computer Centre.
IHEP Grid CA Status Report F2F Meeting 17 Mar Computing Centre, IHEP,CAS,China.
The Federal E-Authentication Initiative David Temoshok Director, Identity Policy GSA Office of Governmentwide Policy February 12, 2004 The E-Authentication.
Self-Audit & Status Report for KEK GRID CA Hiroyuki Matsunaga KEK (High Energy Accelerator Research Organization), Computing Research Center APGridPMA.
International Grid Trust Federation Session GGF 19 Chapel Hill, NC, USA Thursday, Feb CAOPS-WG session #1.
Bob Jones EGEE Technical Director
Jens Jensen EU Grid PMA, Berlin Jan 2015
Disaster Mitigation Competence Centre Project Meeting
EGI Updates Check-in Matthew Viljoen – EGI Foundation
AARC Update What’s been happening in AARC which matters for GÉANT
Road Manager Module National Heavy Vehicle Regulator
AEGIS Certification Authority
Classic X.509 AP updates (v4.1)
Disaster Mitigation Competence Centre Project Meeting
Updates of the APGrid PMA
Grids & PKI: TAGPMA & Bridges (Scott Rea – Dartmouth College) Internet2 Member Meeting, Dec 2006 PKI Implementers Workshop - Chicago, IL.
Christos Kanellopoulos
CheckIn: the AAI platform for EGI
Disaster Mitigation Competence Centre Project Meeting
Organized by governmental sector (National Institute of information )
2018 Safety Group 1 – 5 Year Program Timeline Guide
2017 Safety Group 1 – 5 Year Program Timeline Guide
Updated (VO) Community Security Policies
EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.
APAN update & update Yasuichi Kitamura APAN Board member Steering Committee member.
UK e-Science CA and JCS Migration Status
MaGrid CA Self audit and update
Road Manager Module National Heavy Vehicle Regulator
AAI in EGI Status and Evolution
2016 Safety Group 1 – 5 Year Program Timeline Guide
IGTF All-Hands Meeting
MyIFAM CA Self-Audit Report APGridPMA F2F Meeting 1/4/2019
Program of IGTF All-Hands Meeting on 1 April 2019
HKU Grid Certificate Authority (HKU Grid CA) CP/CPS Reviewer’s Comments Bill Yau
KISTI CA Report Status & Self-Audit
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

EUGridPMA 41 and IGTF All-Hands Meeting APGridPMA Update Eric Yen ASGCCA, Taiwan EUGridPMA 41 and IGTF All-Hands Meeting Manchester, UK 25 September 2017

General Status Chair and Vice Chair (2016-2017): Will be elected in next APGridPMA F2F Meeting, Oct. 2017 Chair: Eric Yen (ASGCCA, Taiwan) Vice Chair: Kento Aida(HPCI CA, Japan), Eisaku Sakane (HPCI CA, Japan) Routine Gathering Spring: Together with ISGC in Taiwan Fall: Collocated with e-Science or Networking events Virtual meeting will be arranged upon request or whenever there is any issue in-between F2F meetings Self Auditing Report: Once a year for each CA Regional Catch-All CA: ASGCCA, now supporting users through local RAs in PH, TH, ID, IN, MN, LK

CA ccTLD Self Audit #valid Cert IPv6 Remarks AIST CA JP APAC CA AU Withdrawn from Nov. 2013 APAC CA AU Services ended in Dec 31, 2012 ASGC CA TW Aug. 2016 141, 257, 8 Y Regional Catch-All CA; x.509 based SSO in AS AusCert New national certificate services of AU (+NZ, FJ, PG) CNIC CA CN Aug. 2015 21 SDG CA 2 HKU CA 4, 25, 1 HPCI CA Mar. 2017 296, 188 MICS; OCSP enabled; SSO IGCA IN 2013 134, 23 IHEP CA 2014 53, 46, 16 KEK CA 138, 159 Support robot Cert and OCSP is Ready KISTI CA KR 37, 32, 3 Renewed and back to service from June 2017 MYIFAM MY Aug. 2014 16, 45 National Fed IdM and Fed CA are ongoing; Eduroam, Shib NCHC CA Withdrawn from Feb. 2015 NECTEC CA TH March, 2014 4, 13 Decommissioned from Jan 2017 NAREGI CA NAREGI CA 2.4, ended EEC issuance from Dec. 2014 PRAGMA-UCSD US Withdrawn from July 2014 11 Production CAs in 7 countries v6 plan and CRL status

From Previous Meetings (March 2017) KISTI Grid CA is back in operation since July 2017 GridCA Webserver Updated: MYIFAM (done), HKU (done) CA Operation MICS CA Audit Checklist: NII (HPCI CA, JP) draft is reviewed based on IGTF LoA and PKI technology Remote Identity Vetting Model Review: evaluation of experiments based on practices highlighted at EUGridPMA wiki will be reported at the APGridPMA meeting in Oct. 2017 (HPCICA and ASGCCA) New version NAREGI-CA will be released in late 2017 Enforcement of RA management IPv6 CRL Distribution Point: hope to be available by Aug. of 2017 IPv4 Only: KISTI Reorganising APGridPMA Website (in progress, conducted by Eisaku san) Improve the monitoring and warning services of CAs Changes of CA Managers: CNIC, iHEP, MyIFAM, KISTI Doc GFD169 for self-audit guidelines is outdated and does not address newer assurance profiles such as MICS. NII draft was presented at last APGridPMA meeting and IGTF AHM. RA has to be included in the assurance chain and the links of RA in APGridPMA is not strong enough as I know. We’d like to focus this topic more in the next meeting in Oct. including the RPS template and the practices of APGridPMA CAs, to enhance the consistency and on boarding RA processes.

Extensively Support and Integrate with Wider Applications/User Communities Integration with existing institutional SSO, identity federation and Cloud Services Enhance application and system security Will work with Identity & Access Management (IAM) working group of APAN Policy and technical issues working with REFEDS and eduGAIN on Training, Dissemination, and Engagement in Asia Pacific Region (in APAN meetings, twice a year, specifically) leveraging IGTF and EduGAIN bridge and SAML protocol We plan to have some case studies and requirements from user communities could be reported and discussed in future APGridPMA meetings

Case Study Test bed building Online CA Policy, Technology & Operation Single Sign-On (PKI, LDAP, Access Mgnt) & VO Membership Medical Imaging Protein Analysis Drug Discovery HEP: AMS, KAGRA Tsunami, Storm Surge, Weather Simulation Multispectral Imaging Soundscape Analysis DL/AI Applications Science Gateway (Web UI, Web Terminal or CLI) Federated Identity Management Test bed building Online CA Policy, Technology & Operation User Types: staffs from partner institutes (w/, w/o) eduGain or IGTF CA e-Science Infrastructure & Distributed Cloud Platform over Integrated Resources in Partner Institutes or Commercial Clouds (e.g., DiCOS)

Requirements Role of CA for Certificate-free User Applications Relationship with eduGAIN and Sirtfi and others Extensive usages of certificates from IGTF CA, e.g, website signing, digital signature of emails, etc. A single, fully IGTF accredited online CA; Federated access via eduGAIN; Hidden personal user certificates; Easy integration with Science Gateways; Scalable trust model (certs are powerful!)

Future Meetings 19th APGridPMA Face-to-Face Meeting: March 6th 2017 20th APGridPMA F2F Meeting: 15 Oct. 2017, collocated with HEPiX at KEK in 16-20 Oct. 2017 21st APGridPMA F2F Meeting: together with ISGC 2018 on 19 March 2018 22nd APGridPMA F2F Meeting: Call for Host Option 1: 46th APAN Meeting, August 20-24, 2018, Auckland (NZ)