4 th APGrid PMA F2F Meeting Academia Sinica, Taipei, Taiwan April 8, 2008 Agendahttp://www.apgridpma.org/meetings/index.html Call for note takers!

Slides:



Advertisements
Similar presentations
National Institute of Advanced Industrial Science and Technology Asia Pacific Grid PMA Yoshio Tanaka APGrid PMA, Chair Grid Technology Research Center,
Advertisements

Resource/data WG Summary Yoshio Tanaka Mason Katz.
2 nd APGrid PMA F2F Meeting Osaka University Convention Center October 15 09: :20 # Participants: 26.
Resource WG Report. Projects Applications EOL Ninf-G Climate model GridBlast GOC Gangla / SCMSWeb => Uniform Database Goodness Status map (e.g. IVDGL)
Usage of PGP in TACAR 19th OGF Meeting Chapel Hill, USA February 1, 2007 Licia Florio Project Development Officer
Updates of the APGrid PMA Catania March 3, 2009 Yoshio Tanaka APGridPMA Chair, AIST, Japan.
International Grid Trust Federation Session GGF 20 Manchester, UK Wednesday, May CAOPS-WG session #2.
Grid Computing in Higher Education (Scott Rea) EDUCAUSE PKI Deployment Forum Madison, WI - April 15, 2008.
National Institute of Advanced Industrial Science and Technology Proposals for auditing Yoshio Tanaka Grid Technology Research.
National Institute of Advanced Industrial Science and Technology Status and plans of the APGrid PMA Yoshio Tanaka Grid Technology.
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
2 nd APGrid PMA F2F Meeting Osaka University Convention Center October 15 Wireless LAN SSID: PRAGMA11 Wep key: PRAGMA11JAPAN.
National Institute of Advanced Industrial Science and Technology Auditing, auditing template and experiences on being audited Yoshio Tanaka
NRENs supporting Grids using current Grid technology TERENA NREN-GRID Workshop Amsterdam Milan Sova CESNET.
CILogon OSG CA Mine Altunay Jim Basney TAGPMA Meeting Pittsburgh May 27, 2015.
NECTEC-GOC CA APGrid PMA face-to-face meeting. October, Sornthep Vannarat National Electronics and Computer Technology Center, Thailand.
Updates of APGrid PMA 22 June, Members (15 + 1) 15 Accredited CAs AIST (JP) APAC (AU) ASGC (TW) CNIC (CN), SDG IGCA (IN) IHEP (CN) KEK (JP) KISTI.
National Institute of Advanced Industrial Science and Technology Self-audit report of AIST GRID CA Yoshio Tanaka Information.
The CA Distribution Process David Groep, July 2007.
National Institute of Advanced Industrial Science and Technology Updates of the APGrid PMA Yoshio Tanaka Grid Technology Research.
March 27, 2006TAGPMA - Rio de Janeiro1 Short Lived Credential Services Profile Tony J. Genovese The Americas Grid PMA DOEGridsATF/ESnet/LBNL.
JSPG: User-level Accounting Data Policy David Kelsey, CCLRC/RAL, UK LCG GDB Meeting, Rome, 5 April 2006.
5 th APGrid PMA Meeting An Update from the TAGPMA Vinod Rebello Taipei, Taiwan 20th April 2009 The Americas Grid Policy Management Authority.
CAOPS-IGTF Session An Update from the TAGPMA Vinod Rebello given by Scott Rea OGF 25, Catania, Italy March 2, 2009 The Americas Grid Policy Management.
TERENA TF-EMC2 Workshop David Groep,
Updates from the EUGridPMA David Groep, July 16 st, 2007.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
Profile for Portal-based Credential Services (POCS) Yoshio Tanaka International Grid Trust Federation APGrid PMA AIST.
Sam Morrison APAC CA – APGridPMA - ISGC2010 APAC CA Self Audit and status update Sam Morrison ARCS.
TAGPMA & the Bridge WG (Scott Rea – Dartmouth College) Internet2 Member Meeting, Dec 2006 PKI Activities and Applications Update - Chicago, IL.
ESnet RAF and eduroam ™ Tony J. Genovese ATF Team ESnet/Lawrence Berkeley National Laboratory.
National Institute of Advanced Industrial Science and Technology APGrid PMA: Stauts Yoshio Tanaka Grid Technology Research Center,
National Institute of Advanced Industrial Science and Technology Some topics from the OGF20 and the EUGrid PMA F2F Meeting Yoshio Tanaka Grid Technology.
SC2008 (11/19/2008) Resources Group Pacific Rim Application and Grid Middleware Assembly Reports.
International Grid Trust Federation Session GGF 20 Manchester, UK Wednesday, May CAOPS-WG session #2.
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
Distribution Repository Structure David Groep,
National Institute of Advanced Industrial Science and Technology Updates of the APGrid PMA Yoshio Tanaka APGrid PMA, Chair Grid Technology Research Center,
National Institute of Advanced Industrial Science and Technology GGF12 Workshop on Operational Security for the Grid Cross-site authentication and access.
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
Opening Remarks and Updates of the APGrid PMA 5 th APGridPMA September 16, 2008 Yoshio Tanaka APGridPMA Chair, AIST, Japan.
APGrid PMA face-to-face meeting, 9/16/2008 PRAGMA-UCSD CA Team Pacific Rim Application and Grid Middleware Assembly
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
Community PKIs Initiatives Updates TF-EMC2 Meeting Loughborough, UK 6-7 May, 2009 Licia Florio, TERENA
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
0 NAREGI CA Status Report APGrid F2F meeting in Singapore June 4, 2007 Rumiko Masuko.
TACAR Updates version David Groep, NIKHEF. 9 th EUGridPMA ‘RAL’ meeting – Jan David Groep – TACAR Aims  Trusted and.
FP6−2004−Infrastructures−6-SSA E-infrastructure shared between Europe and Latin America The Latin American Catch-all Grid Certification.
Update of APGridPMA APGridPMA Meeting Academia Sinica, Taiwan 22 March,
APGridPMA Update Eric Yen APGridPMA August, 2014.
FP6−2004−Infrastructures−6-SSA [ Empowering e Science across the Mediterranean ] Rome, Tutorial for Certification Authority Managers,
Summary of Poznan EUGridPMA32 September EUGridPMA Poznan 2014 meeting – 2 David Groep – Welcome back at PSNC.
Security Bob Cowles
A Study of Certification Authority Integration Model in a PKI Trust Federation on Distributed Infrastructures for Academic Research Eisaku SAKANE, Takeshi.
18 th EUGridPMA, Dublin / SRCE CA Self Audit SRCE CA Self Audit Emir Imamagić SRCE Croatia.
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
Update of APGridPMA Eric Yen 25 th EUGridPMA & IGTF All Hands Meeting KIT, Germany 7 May, 2012.
14 th EUGridPMA Meeting Update from TAGPMA Jim Basney Lisbon, Portugual October 6-8, 2008 The Americas Grid Policy Management Authority.
The Americas Grid Policy Management Authority TAGPMA Update Derek Simmel 27 th EUGridPMA Meeting Rome, Italy January 14-16, 2013.
APGridPMA Update Eric Yen 35 th Amsterdam, NL September 7, 2015.
UGRID CA Self-audit report Sergii Stirenko 21 st EUGRIDPMA Meeting Utrecht 24 January 2011.
News from EUGridPMA EGI OMB, 22 Jan 2013 David Kelsey (STFC) Using notes from David Groep 22/01/20131EUGridPMA News.
Updates of APGrid PMA 18 th EUGridPMA Meeting 18 th EUGridPMA Meeting 18 January, 2010 Eric Yen ASGCCA Taiwan.
Updates from the EUGridPMA David Groep, Oct 17 st, 2007.
29 th EUGridPMA meeting, September 2013, Bucharest AEGIS Certification Authority Dušan Radovanović University of Belgrade Computer Centre.
International Grid Trust Federation Session GGF 19 Chapel Hill, NC, USA Thursday, Feb CAOPS-WG session #1.
Classic X.509 AP updates (v4.1)
Updates of the APGrid PMA
Grids & PKI: TAGPMA & Bridges (Scott Rea – Dartmouth College) Internet2 Member Meeting, Dec 2006 PKI Implementers Workshop - Chicago, IL.
HellasGrid CA & euGridPMA
Presentation transcript:

4 th APGrid PMA F2F Meeting Academia Sinica, Taipei, Taiwan April 8, 2008 Agendahttp:// Call for note takers!

Updates of the APGrid PMA and recap of the IGTF Yoshio Tanaka Chair,APGrid PMA / AIST

Asia Pacific Grid PMA General Policy Management Authority in Asia Pacific Not specific for ApGrid, Not specific for PRAGMA … Launched on June 1 st, 2004 Defines minimum CA requirements Based on IGTF Classic AP maintained by EUGridPMA APGrid PMA approved that we accept two levels of CA: Experimental-level CA Alternative of the Globus CA Can be trusted within A-P communities Production-level CA Strict management is necessary Expected to be trusted by international communitiesMeetings Regular VTC (every 3~4 months) F2F meeting (once or twice a year)

Members (13 + 4) 9 Accredited CAs In operation AIST (Japan) APAC (Australia) ASGCC (Taiwan) CNIC (China) IHEP (China) KEK (Japan) KISTI (Korea) NAREGI (Japan) NECTEC (Thailand) 3 CAs under review NGO (Singapore) PRAGMA (USA) NCHC (Taiwan)Planning ThaiGrid (Thailand) CDAC (India) General membership Osaka U. (Japan) U. Hong Kong (China) U. Hyderabad (India) USM (Malaysia)

Scope of the APGrid PMA Manage the PMA membership Define charter and minimum CA requirements Publish related documents Maintain and revise the documents Accredit authorities with respect to the minimum CA requirements Coordinate auditing and re-certification of accredited authorities Monitor member CA signing namespaces Operate a secure collection point for information about accredited CAs Be primarily concerned with Grid communities in Asia Pacific, and their external partners

APGrid PMA responsibilities CP/CPS Responsible for supporting and auditing the development and maintenance of the CP/CPS for CAs in Asia Pacific. Other documents Charter Minimum CA requirements Authentication Profiles

APGrid PMA responsibilities (cont ’ d) Accreditation Accredit authorities according to the procedure defined in the charter.Audit APGrid PMA is doing external auditingOperation Every CA must be responsible for its operation. The PMA is NOT an operation unit but a policy management authority.Obligation All PMA members are understood to represent the best interest of their national/regional communities and expected active participation to activities of the PMA.

General Architecture of the IGTF Member PMAs are responsible for accrediting authorities The IGTF maintains a set of authentication profiles (APs) that specify the policy and technical requirements for a class of identity assertions and assertion providers. Each AP is assigned by the IGTF to a specific member PMA. Classic AP (EUGrid PMA) Short Lived Credential Services (SLCS) AP (TAGPMA) Member Integrated Credential Services (MICS) AP (TAGPMA)

General Architecture of the IGTF (cont ’ d) Proposed changes to an AP will be circulated to all chairs of the IGTF member PMAs. All of the PMA chairs, after approval by their PMA, are required to endorse the proposed changes before the modified AP will come into effect. Authorities accredited by a PMA are always subject to the policies and practices of a specific AP as decided by the accrediting PMA. Any changes to the policy and practices of a authority after accreditation will void the accreditation unless the changes have been approved by the accrediting PMA prior to their taking effect.

Requirements for accredited authorities Maintain at least one contact mechanism which must allow for un-moderated access to report problems and faults regarding the authority by the relying parties and genral public. This point of contact shall be made known to the accrediting PMA and the IGTF for subsequent re-publishing. Must disclose to the accrediting PMA and to the general public its documented policies and practices.

Implementation of the federation Each PMA maintains information of all accredited CAs. Root certificate CRL Distribution Point Point of contact Signing policy file Point to the CP/CPS Information of the all PMA is packed into a single tarball/RPM and distributed as an IGTF CA distribution No hierarchies. All accredited CAs are included in a flat structure Once you will be accredited by the APGrid PMA, you will be an IGTF- accredited CA IGTF CA distribution is released in every few weeks David Groep will notify all member CAs the plan of the new release to ask reports of any updates. Distribution frequency is flexible. The information is stored in the CVS repository maintained by the EUGrid PMA Yoshio, Mason, and Darcy have accounts on the CVS server If you have modified CA cert, etc., please let me know. IGTF CA distribution is available from the EUGrid PMA web site and the APGrid PMA web site. APGrid PMA is planning to mirror the CVS server as wel.

Chair’s role A Point of Contact for the PMA Running the PMA meetings Ensuring that all voting is recorded and published Leads discussions Contributes to the IGTF Attend meetings of EUGridPMA and TAGPMA Attend OGF Best effort basis Maintains the IGTF CA Distribution Commit/delete/update files of APGridPMA- accredited CA Maintains web site Maintains ML

Businesses Chair election Next F2F meeting September 2008, Singapore How to protect the ML from SPAMS TACAR and PGP/Thawte key signing

7 th TAGPMA Face-to-Face Meeting TACAR Registration and Accreditation Vinod Rebello and Mike helm NERSC, Oakland, CA, USA April 2 – 4, 2008 The Americas Grid Policy Management Authority

15 7th TAGPMA F2F, April 2008Vinod Rebello – TACAR The TERENA Academic CA Repository (TACAR) offers a trusted and centralized place where root CA certificates can be stored and safely downloaded. The only requirement to be part of TACAR is that the applying CA operates for the research and academic community IGTF and TAGPMA approved third party repository

16 7th TAGPMA F2F, April 2008Vinod Rebello – Joining TACAR Read Policy – currently version CA Manager should fill in the Letter of Registration (Annex I) –Contain info on the CA, Root certificate, location of CP/CPS and its PDF fingerprint The Letter of Accreditation needs to be signed by the head of the institution to which the CA is affiliated. Letters which are being provided for the first time must be validated via a face-to-face meeting between the representative(s) of the applying CA and a TACAR representative

17 7th TAGPMA F2F, April 2008Vinod Rebello – Required files Letters to be presented on paper (two copies of each) and in electronic (PDF) form on CD Also on CD –The detached PGP signatures of the two letters –PDF version of the CP/CPS –Root Certificate in PEM format –And their respective detached PGP signatures –Also the PGP Key

18 7th TAGPMA F2F, April 2008Vinod Rebello – Trusted Introducer If you cant meet with Licia Fiorio in person then talk to Mike Helm Yoshio Tanaka The TI is basically the TERENA RA. The TI will deliver all material collected to TERENA by using signed for the electronic information and postal mail or face-to-face meeting for the paper material.