NAREGI CA Updates Kento Aida NAREGI CA/NII Kento Aida, National Institute of Informatics APGrid PMA meeting 04/20/2008
Current Status operation with CP/CPS 4.0 (since Sep/2008) #user certificates = 12 #host certificates = 110 LRA operation #sites with the LRA operator(s) = 11 9 computing centers (universities), IMS, NII minor revision in CP/CPS Kento Aida, National Institute of Informatics 2
Certificate Issue Kento Aida, National Institute of Informatics F2F interview cert. request NAREGI CA system Computer Center A NII User LRA operator LRA admin. cert. request NAREGI Portal UMS acct+passwd+ license ID cert. UMS cert. 3
Minor Revision of CP/CPS CP/CPS Routine Re-key When a certificate has expired, its validity date must not be extended. A new certificate must be issued again with a new public key, or rekeyed, according to resubmission of an enrollment request in section 4.1 “Application, assessment and issue of certificates”. End-entity certificates may be rekeyed for less than 5 years without the procedure defined in "User Identity Authentication" User certificate validity period : As described in Section 3.2, renewing of a certificate is not allowed. Re- keying of a certificate is not allowed if the certificate is valid. In order to renewal a certificate, the subscriber must request a new certificate following the procedures described in Section 4.1. End-entity certificates may be rekeyed for less than 5 years without the procedure defined in "User Identity Authentication". Kento Aida, National Institute of Informatics 4
Organization NAREGI CA Security Officer:Kento Aida CA operator:Eisaku Sakane RA operator:Masaru Kawai Log administrator:Emiko Kaburaki help desk:Eisaku Sakane, Kazuyuki Yamada, Takashi Iida, Masaru Kawai NII LRA LRA administrator:Takashi Iida/Kazuyuki Yamada LRA operators:>20 Kento Aida, National Institute of Informatics 5
NAREGI-CA Mailing List NAREGI-CA (current version 2.2.4) NAREGI-CA is a CA server and command shell program running on UNIX. The package consists of a variety of utility commands including key generation and certification issuance, verification, and storage. mailing list a mailing list for CA administrators/operators using the NAREGI-CA software and software developers for CA operations Contact or for joining the mailing list. Kento Aida, National Institute of Informatics 6
Thank you. Kento Aida, National Institute of Informatics