National Institute of Advanced Industrial Science and Technology Auditing, auditing template and experiences on being audited Yoshio Tanaka

Slides:



Advertisements
Similar presentations
Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
Advertisements

Grid Computing, B. Wilkinson, 20045a.1 Security Continued.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Yuan, Tein Horng Academia Sinica Computing Centre 13 June 2003.
CNIC Grid CA/SDG CA Self Audit Kejun (Kevin) Dong Computer Network Information Center (CNIC) Chinese Academy of Sciences APGridPMA F2F.
1 WebTrust for Certification Authorities (CAs) Overview October 2011 WebTrust for Certification Authorities (CAs) Overview October 2011 Presentation based.
Identity Standards (Federal Bridge Certification Authority – Certificate Lifecycle) Oct,
National Institute of Advanced Industrial Science and Technology Proposals for auditing Yoshio Tanaka Grid Technology Research.
4 th APGrid PMA F2F Meeting Academia Sinica, Taipei, Taiwan April 8, 2008 Agendahttp:// Call for note takers!
Public Key Infrastructure (PKI) Providing secure communications and authentication over an open network.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
Federation of Campus PKI and Grid PKI for Academic GOC Management Conformable to APGrid PMA National Institute of Informatics, JAPAN Toshiyuki Kataoka,
Resource PKI: Certificate Policy & Certification Practice Statement Dr. Stephen Kent Chief Scientist - Information Security.
1 REUNA Certificate Authority Juan Carlos Martínez REUNA Chile Rio de Janeiro,27/03/2006, F2F meeting, TAGPMA.
NRENs supporting Grids using current Grid technology TERENA NREN-GRID Workshop Amsterdam Milan Sova CESNET.
Chapter 11: Active Directory Certificate Services
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
CSE 4482, 2009 Session 21 Personal Information Protection and Electronic Documents Act Payment Card Industry standard Web Trust Sys Trust.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Configuring Active Directory Certificate Services Lesson 13.
Deploying a Certification Authority for Networks Security Prof. Dr. VICTOR-VALERIU PATRICIU Cdor.Prof. Dr. AUREL SERB Computer Engineering Department Military.
Computing Research Center, High Energy Accelerator Organization (KEK) KEK Grid CA Go Iwai The 2 nd APGrid PMA Meeting at Osaka Univ.
Service Organization Control (SOC) Reporting Options and Information
David L. Wasley Office of the President University of California Higher Ed PKI Certificate Policy David L. Wasley University of California I2 Middleware.
NECTEC-GOC CA APGrid PMA face-to-face meeting. October, Sornthep Vannarat National Electronics and Computer Technology Center, Thailand.
WebTrust SM/TM Principles and Criteria for Certification Authorities CA Trust Jeff
National Institute of Advanced Industrial Science and Technology Self-audit report of AIST GRID CA Yoshio Tanaka Information.
+1 (801) Standards for Registration Practices Statements IGTF Considerations.
Chapter 9: Using and Managing Keys Security+ Guide to Network Security Fundamentals Second Edition.
Configuring Directory Certificate Services Lesson 13.
DataGrid WP6 CA meeting, CERN, 12 December 2002 IISAS Certification Authority Jan Astalos Department of Parallel and Distributed Computing Institute of.
March 27, 2006TAGPMA - Rio de Janeiro1 Short Lived Credential Services Profile Tony J. Genovese The Americas Grid PMA DOEGridsATF/ESnet/LBNL.
National Institute of Advanced Industrial Science and Technology Brief status report of AIST GRID CA APGridPMA Singapore September 16 Yoshio.
HEPKI-PAG Policy Activities Group David L. Wasley University of California.
NECTEC-GOC CA Self Audit 7 th APGrid PMA Face-to-Face meeting March 8 th, 2010 Large-Scale Simulation Research Laboratory Sornthep Vannarat Large-Scale.
Introduction of NAREGI-CA National Institute of Informatics JAPAN Toshiyuki Kataoka, July 19, 2006 APAN Grid-Middleware Workshop, Singapore.
Maintaining Network Health. Active Directory Certificate Services Public Key Infrastructure (PKI) Provides assurance that you are communicating with the.
IHEP Grid CA Status Report Gongxing Sun F2F Meeting 20 Apr Computing Centre, IHEP,CAS,China.
IHEP Grid CA Status Report Wei F2F Meeting 8 Mar Computing Centre, IHEP,CAS,China.
Public Key Infrastructure (X509 PKI) Presented by : Ali Fanian
DIGITAL SIGNATURE. GOOD OLD DAYS VS. NOW GOOD OLD DAYS FILE WHATEVER YOU WANT – PUT ‘NA’ OR ‘-’ OR SCRATCH OUT FILE BACK DATED, FILE BLANK FORMS, FILE.
Profile for Portal-based Credential Services (POCS) Yoshio Tanaka International Grid Trust Federation APGrid PMA AIST.
Academia Sinica Grid Computing Certification Authority (ASGCCA)
Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre.
Who’s watching your network The Certificate Authority In a Public Key Infrastructure, the CA component is responsible for issuing certificates. A certificate.
1 Topic# 7 – Auditing with Technology Readings, Chapter 10 A – COMPUTERIZED AUDIT TOOLS –Electronic Spreadsheets –Automated Working Papers –Generalized.
“Trust me …” Policy and Practices in PKI David L. Wasley Fall 2006 PKI Workshop.
National Institute of Advanced Industrial Science and Technology Updates of the APGrid PMA Yoshio Tanaka APGrid PMA, Chair Grid Technology Research Center,
Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre.
National Institute of Advanced Industrial Science and Technology GGF12 Workshop on Operational Security for the Grid Cross-site authentication and access.
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
APGrid PMA face-to-face meeting, 9/16/2008 PRAGMA-UCSD CA Team Pacific Rim Application and Grid Middleware Assembly
0 NAREGI CA Status Report APGrid F2F meeting in Singapore June 4, 2007 Rumiko Masuko.
8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK
MICS Authentication Profile Maintenance & Update Presented for review and discussion to the TAGPMA On 1May09 by Marg Murray.
TR-GRID CA Self-Auditing Results and Status Update EUGridPMA Meeting September 12-14, 2011 Marrakesh Feyza Eryol, Onur Temizsoylu TUBITAK-ULAKBIM
HKU Computer Centre Grid Certificate Authority Status Update Lilian Chan IT Services, The University of Hong Kong APGrid.
BG.ACAD CA HTTP :// CA. ACAD. BG S ELF - AUDIT REPORT 2014 Vladimir Dimitrov IICT-BAS ( 32 nd EUGridPMA Meeting Poznan, 8-10.
1 US Higher Education Root CA (USHER) Update Fed/Ed Meeting December 14, 2005 Jim Jokl University of Virginia.
18 th EUGridPMA, Dublin / SRCE CA Self Audit SRCE CA Self Audit Emir Imamagić SRCE Croatia.
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
UGRID CA Self-audit report Sergii Stirenko 21 st EUGRIDPMA Meeting Utrecht 24 January 2011.
HellasGrid CA self Audit. In general We do operations well Our policy documents need work (mostly to make the text clearer in a few sections) 2.
IRAN-GRID CA Self Audit IRAN-GRID CA Self Audit Report Shahin Rouhani IRAN-GRID Tehran Iran Shahin Rouhani Grid Computation Group IPM, Tehran, Iran May.
Alternative Governance Models for PKI
Guidelines for auditing Grid CAs
جايگاه گواهی ديجيتالی در ايران
MaGrid CA Self audit and update
Bill Yau HKU Grid Certificate Authority (HKU Grid CA) Self Audit & Status Report Bill Yau
KISTI CA Report Status & Self-Audit
BG.ACAD CA Self-audit report 2018
Presentation transcript:

National Institute of Advanced Industrial Science and Technology Auditing, auditing template and experiences on being audited Yoshio Tanaka NAREGI, APGrid PMA, Grid Technology Research Center, AIST, Japan

Proposed audit items NAREGI PKI WG has subjectively selected criteria for auditing Grid CAs. based on AICPA/CICA WebTrust SM/TM Program for Certification Authority minimum CA requirements of APGrid PMA and EUGrid PMA Web Trust WebTrust is a seal awarded to web sites that consistently adhere to certain business standards established by the Canadian Institute of Chartered Accountants (CICA.ca) and the American Institute of Certified Public Accountants (AICPA).CICA.caAICPA In the program, “ Web Trust Principles and Criteria for Certification Authorities ” lists criteria for CAs. may too much for Grid CAs.

Criteria in the WebTrust SM/TM Principle 1: CA Business Practices Disclosure The certification authority discloses its key and certificate life cycle management business and information privacy practices and provides its services in accordance with its disclosed practices Principle 2: Service Integrity The certification authority maintains effective controls to provide reasonable assurance that: Subscriber information was properly authenticated (for the registration activities performed by ABC-CA) and The integrity of keys and certificates it manages is established and protected throughout their life cycles.

Criteria in the WebTrust SM/TM (cont ’ d) Principle 3: CA Environmental Controls The certification authority maintains effective controls to provide reasonable assurance that: Subscriber and relying party information is restricted to authorized individuals and protected from uses not specified in the CA's business practices disclosure; The continuity of key and certificate life cycle management operations is maintained; and CA systems development, maintenance, and operation are properly authorized and performed to maintain CA systems integrity.

Audit checklist Simply pickup items from WebTrust SM/TM criteria based on minimum CA requirements. The number of criteria: WebTrust SM/TM Check List Principle Principle Principle Others4

Experiences on being audited AIST GRID CA was audited by NAREGI CA according to the proposed criteria for audit. Term of auditing Preliminary examination: Feb. 21 ~ Mar. 28 Main examination: Mar. 29Auditors Three auditors from NEC/NAREGI. Chief auditor is an expert of auditingProcedure Examination of documents Interview to Security Officers, CA operators, and User Administrators Inspection of the CA server room, CA system (including HSM), and a safe box

Subjects of auditing NoSubjects Documents1AIST GRID PKI Service Certificate Policy and Certificate Practices Statements 2Certificate and CRL Profile 3AIST GRID CA Enrollment Procedure Document 4Operation Manual Logs 5CA Server Log (login/logout/reboot) 6RA Server Log (login/logout/reboot) 7Repository Server Log (login/logout/reboot) 8Access log of the CA server room CA server room9Inspection of the CA server room and related devices Certificates10Self signed certificate, fingerprint 11End entity certificates (Globus Server/Client, Unicore Server/Client, LDAP server) 12CRL

Schedule Interview and log check Principle 1: 13:30 ~ 14:20 Principle 2: 14:20 ~ 15:10 Principle 3: 15:10 ~ 16:00 Inspection of CA server, etc. 16:15 ~ 17:00

Sample interviewed issues Principle 1 How does an end entity know that his certificate has been issued? How does an end entity know that his certificate has been revoked? Principle 2 Who operates the CA system? Who knows the pass phrase for CA private key? Who can access to the backup media of CA private key? Who has a key of a safe box? How do you confirm the uniqueness of subject name? How do you generate a CRL if you receive multiple revocation requests at the same time?

Sample interviewed issues (cont ’ d) Principle 3 Who revises the CP/CPS? and Who authorizes the revision of CP/CPS? In which case do you assign a new OID to the CP/CPS? How do you inform end entities that the CP/CPS has been revised? How do you control access to the CA room? What kind of information do you archive?Others How does RA communicate with CA?

Sample inspected issues Principle 2 HSM A safe box Revocation function of the CA system Backup media of archive Issued certificates Principle 3 CA room

Summary of auditing Number of criteria By document check By Interview By Inspection Principle Principle Principle Others4410

Summary of auditing (cont ’ d) Most interviewed issues should be described in CP/CPS. Basically, CP/CPS is the only way for giving end entities the information about the CA. Advised issues Some issues must be described in CP/CPS Procedures for revising CP/CPS who does? who authorizes? how to inform end entities. Access control to the CA room, CA system other small issues Not all issued CRLs were archived violate minimum CA requirements AIST GRID CA will archive all issued CRLs. CA room is not dedicate for CA operation The room was shared by other system engineers for cluster management. We have made the CA room to be dedicated to the CA operation.

Summary of audit (cont ’ d, last) The focuses of auditors How the CA private key is kept secure Issuing certificates must not be done by a single person. how to implement multi-person control Enough records/logs must be archived so that we can trace anything if illegal accident would happen. Server logs (login/logout/reboot) Access logs to the CA room Date, name, purpose, etc. Describe CP/CPS as rich as possible Purpose of auditing Not the audit itself but to improve CA operation!