UNLP CA (Argentina) Universidad Nacional de La Plata Was created as a national university in 1905 Is the 3rd largest.

Slides:



Advertisements
Similar presentations
1 APNIC Resource Certification Service Project Routing SIG 7 Sep 2005 APNIC20, Hanoi, Vietnam George Michaelson.
Advertisements

Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Yuan, Tein Horng Academia Sinica Computing Centre 13 June 2003.
CNIC Grid CA/SDG CA Self Audit Kejun (Kevin) Dong Computer Network Information Center (CNIC) Chinese Academy of Sciences APGridPMA F2F.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
E-infrastructure shared between Europe and Latin America Dova, M.T., Grunfeld, C., Monticelli, F., Tripiana, M., Veiga, A. IFLP (CONICET-UNLP)
16.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
1 REUNA Certificate Authority Juan Carlos Martínez REUNA Chile Rio de Janeiro,27/03/2006, F2F meeting, TAGPMA.
Open Science Grid Use of PKI: Wishing it was easy A brief and incomplete introduction. Doug Olson, LBNL PKI Workshop, NIST 5 April 2006.
APNIC Trial of Certification of IP Addresses and ASes RIPE 52 Plenary George Michaelson Geoff Huston.
9/20/2000www.cren.net1 Root Key Cutting and Ceremony at MIT 11/17/99.
Wolfgang Schneider NSI: A Client-Server-Model for PKI Services.
Lecture 12 Electronic Business (MGT-485). Recap – Lecture 11 E-Commerce Security Environment Security Threats in E-commerce Technology Solutions.
OpenVPN OpenVPN: an open source, cross platform client/server, PKI based VPN.
Digital Certificates Made Easy Sam Lutgring Director of Informational Technology Services Calhoun Intermediate School District.
UNAMgrid CA Juan Carlos Guel UNAM, México. Alejandro Núñez UNAM, México. Israel Becerril UNAM, México. DGSCA UNAM 31/08/06.
NECTEC-GOC CA APGrid PMA face-to-face meeting. October, Sornthep Vannarat National Electronics and Computer Technology Center, Thailand.
National Institute of Advanced Industrial Science and Technology Self-audit report of AIST GRID CA Yoshio Tanaka Information.
DataGrid WP6 CA meeting, CERN, 12 December 2002 IISAS Certification Authority Jan Astalos Department of Parallel and Distributed Computing Institute of.
March 27, 2006TAGPMA - Rio de Janeiro1 Short Lived Credential Services Profile Tony J. Genovese The Americas Grid PMA DOEGridsATF/ESnet/LBNL.
National Institute of Advanced Industrial Science and Technology Brief status report of AIST GRID CA APGridPMA Singapore September 16 Yoshio.
© 2006 Cisco Systems, Inc. All rights reserved. Network Security 2 Module 5 – Configure Site-to-Site VPNs Using Digital Certificates.
Module 9: Fundamentals of Securing Network Communication.
NECTEC-GOC CA Self Audit 7 th APGrid PMA Face-to-Face meeting March 8 th, 2010 Large-Scale Simulation Research Laboratory Sornthep Vannarat Large-Scale.
Module 9: Designing Public Key Infrastructure in Windows Server 2008.
IHEP Grid CA Status Report Gongxing Sun F2F Meeting 20 Apr Computing Centre, IHEP,CAS,China.
IHEP Grid CA Status Report Wei F2F Meeting 8 Mar Computing Centre, IHEP,CAS,China.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Profile for Portal-based Credential Services (POCS) Yoshio Tanaka International Grid Trust Federation APGrid PMA AIST.
UNAMgrid Alejandro Núñez Sandoval Rio de Janeiro, Brazil, 03/27/06 F2F meeting, TAGPMA.
KISTI Grid CA Status Report Korea Institute of Science and Technology Information Sangwan Kim Jae-Hyuck Kwan
Sam Morrison APAC CA – APGridPMA - ISGC2010 APAC CA Self Audit and status update Sam Morrison ARCS.
Academia Sinica Grid Computing Certification Authority (ASGCCA)
Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre.
IST E-infrastructure shared between Europe and Latin America ULAGrid Certification Authority Vanessa Hamar Universidad de Los.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien April 20, th APGridPMA in Taipei.
E-science grid facility for Europe and Latin America Task TSA1.3 - Authentication Services and Policies Acheivements Jacques Alves da Silva.
Security fundamentals Topic 5 Using a Public Key Infrastructure.
Grid Canada Certificate Authority Darcy Quesnel
Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre.
1 APNIC Trial of Certification of IP Addresses and ASes RIPE October 2005 Geoff Huston.
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
APGrid PMA face-to-face meeting, 9/16/2008 PRAGMA-UCSD CA Team Pacific Rim Application and Grid Middleware Assembly
0 NAREGI CA Status Report APGrid F2F meeting in Singapore June 4, 2007 Rumiko Masuko.
8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK
MICS Authentication Profile Maintenance & Update Presented for review and discussion to the TAGPMA On 1May09 by Marg Murray.
FP6−2004−Infrastructures−6-SSA E-infrastructure shared between Europe and Latin America The Latin American Catch-all Grid Certification.
Egypt Certification Authority Dr. Ayman Bahaa-Eldin EUN Director 8 May th EuGridPMA meeting, Germany.
Baltic Grid Certification Authority 15th EUGridPMA, January 28th 2009, Nicosia1 Self-audit Hardi Teder EENet.
Trusted Organizations In the grid world one single CA usually covers a predefined geographic region or administrative domain: – Organization – Country.
TR-GRID CA Self-Auditing Results and Status Update EUGridPMA Meeting September 12-14, 2011 Marrakesh Feyza Eryol, Onur Temizsoylu TUBITAK-ULAKBIM
HKU Computer Centre Grid Certificate Authority Status Update Lilian Chan IT Services, The University of Hong Kong APGrid.
FP6−2004−Infrastructures−6-SSA [ Empowering e Science across the Mediterranean ] Rome, Tutorial for Certification Authority Managers,
18 th EUGridPMA, Dublin / SRCE CA Self Audit SRCE CA Self Audit Emir Imamagić SRCE Croatia.
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
NECTEC-GOC CA A Brief Status Report 13 th APGrid PMA Face-to-Face meeting March 24 th, 2014 Large-Scale Simulation Research Laboratory Information Communications.
Feyza Eryol TÜBİTAK ULAKBİM TR-GRID CA SELF-AUDIT & UPDATES.
UGRID CA Self-audit report Sergii Stirenko 21 st EUGRIDPMA Meeting Utrecht 24 January 2011.
Armenian e-Science Foundation Certification Authority Ara A. Grigoryan 1,2, Artem Harutyunyan 1,2,3, Arsen Hayrapetyan 1,2,4 1 Armenian e-Science Foundation;
TNGrid CA 24 th EUGridPMA meeting Ljubljana, Slovenia, January, 2012 Heithem ABBES Mohamed JEMNI
IRAN-GRID CA Self Audit IRAN-GRID CA Self Audit Report Shahin Rouhani IRAN-GRID Tehran Iran Shahin Rouhani Grid Computation Group IPM, Tehran, Iran May.
UGRID CA Sergii Stirenko, Oleg Alienin
کاربرد گواهی الکترونیکی در سیستمهای کاربردی (امضای دیجیتال)
APNIC Trial of Certification of IP Addresses and ASes
APNIC Trial of Certification of IP Addresses and ASes
MaGrid CA Self audit and update
Emir Imamagić University Computing Centre (Srce)
KISTI CA Report Status & Self-Audit
BG.ACAD CA Self-audit report 2018
Presentation transcript:

UNLP CA (Argentina) Universidad Nacional de La Plata Was created as a national university in 1905 Is the 3rd largest university in Argentina More than enrolled students More than 140 degree programs More than 200 postgraduate programs Produces about 20% of the academic research in Argentina

UNLP CA (Argentina) C entro S uperior para el P rocesamiento de la I nformación Provides research network for UNLP 1991 (via BITNET) April 1994 connection to Internet –Class B: x.x. –Domain unlp.edu.ar –Autonomous Systems Number: 5692 Since 2004 connected to Academic Research Networks Ampath & CLARA (viaRETINA) –prefijo IPv6: 2001:1318:A001:: /64

UNLP CA (Argentina) Ce.S.P.I Provides Network Monitoring & management: –More than 3000 computers with public IP –Tools used: Mtrg Nagios Netflow Ipaudit Administrative information systems –Payroll & human resources –Students system –Statistics

UNLP CA (Argentina) pkUNLPGrid CA Following RFC 3647 OID pending in IANA since 12/jan/06 –To be requested from IGTF CP/CPS ver 0.91 (20/03/06) First checked by: Jorge Gomes (LIP) Reviewers:Tony J. Genovese & Alan Sill

UNLP CA (Argentina) Persons involved with the computer network infrastructure for the project Coordinating the CA for UNLP: Javier Díaz, Miguel Luengo Policies, procedures & auditing: Viviana Ambrosi, Lia Molinari PKI infraestructure for de CA: Paula Venosa, Viviana Ambrosi, Einar Lanfranco Network administration (also working in an academic IRT): Miguel Luengo, Nicolas Macia, Andres Barbieri, Alejandro Veiga, Matias Zabaljauregui. RA administration: Maria del Carmen Lago, Teresa Di Pietro, Fernanda Aday

UNLP CA (Argentina) UNLP is working in cooperation with the ONTI, the agency of the federal government of Argentina that coordinated used of information system and technology. –Security standars for the information systems. –Arcert which is the only CERT in Argentina. –pki.gov.ar which is the federal agency that promotes the use of digital signature in the government. –Providing digital signature support for the information systems provided by SIU to the Universities.

UNLP CA (Argentina) Initially only one RA related to UNLP The information to contact initial RA is in the site: The concept is one RA per University or Academic institution equivale CA RA Inst. 1Inst. 2Inst. 3Inst. 4

UNLP CA (Argentina) Name Forms: PKUNLPGRID CA prefers that organizations use domain component naming. Issuer: DC=ar, DC=UNLPgrid, CN=UNLPGridCA Subject: DC=ar, DC=UNLPgrid, O=string, CN=name.surname DC=ar, DC=UNLPgrid, O=string, CN=FQDN

UNLP CA (Argentina) Types of names For people the name and surname or a text directly derived from their name CN=JavierDiaz For Server the server fully qualified domain name (FQDN).IP address are nor accepted CN=pkigrid.unlp.edu.ar For Services the name of the service, the character '/' and the FQDN of the server. CN=ldap/ pkigrid.unlp.edu.ar

UNLP CA (Argentina) Lifetime of certificates CA key size 2048 bits, Initial 10 years lifetime. EE key size 1024 bits, Certificates valid for 13 months (one year + one month). CRL issued every 30 days (at least 7 day befores de expiration of the previous CRL or upon demand)

UNLP CA (Argentina) Guidelines CA offline CA online site supports : Certificates signed by the UNLPCA CRLs CP/CPS technical contacts of the CA RA contact pointer to the TAGPMA & IGTF

UNLP CA (Argentina) Tools used –CA offline: running Linux Debian stable, stored in a safe; OpenCA versión (latest release), OpenSSL versión using etokens-PRO de 32 K for holding private key of CA operators keep in a separate safe (with procedures for accessing the etoken and the passphrase) –CA online site In the Datacenter of the UNLP with access control, etc Behind a FW based on OpenBSD Traffic analyzer (on separate port SPAN using SNORT with a correlation tool such as: ossim/sguil/prelude