8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK

Slides:



Advertisements
Similar presentations
24-May-01D.P.Kelsey, GridPP WG E: Security1 GridPP Work Group E Security Development David Kelsey CLRC/RAL, UK
Advertisements

Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
Chapter 14 – Authentication Applications
11-Dec-01D.P.Kelsey, Authentication1 Authentication 11 Dec 2001 David Kelsey CLRC/RAL, UK
Academia Sinica Grid Computing Certification Authority (ASGCCA) Yuan, Tein Horng Academia Sinica Computing Centre 13 June 2003.
1 ASGCCA Self-Audit Report APGridPMA Jinny Chien March
Cryptography and Network Security Third Edition by William Stallings Lecture slides by Lawrie Brown.
CSCE 715: Network Systems Security Chin-Tser Huang University of South Carolina.
Geneva, Switzerland, 2 June 2014 Introduction to public-key infrastructure (PKI) Erik Andersen, Q.11 Rapporteur, ITU-T Study Group 17 ITU Workshop.
Andrew McNab - EDG Access Control - 14 Jan 2003 EU DataGrid security with GSI and Globus Andrew McNab University of Manchester
5-Sep-02D.P.Kelsey, Security Summary, Budapest1 WP6/7 Security Summary Budapest 5 Sep 2002 David Kelsey CLRC/RAL, UK
Public Key Infrastructure (PKI) Providing secure communications and authentication over an open network.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
16.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
1 REUNA Certificate Authority Juan Carlos Martínez REUNA Chile Rio de Janeiro,27/03/2006, F2F meeting, TAGPMA.
National Institute of Advanced Industrial Science and Technology Auditing, auditing template and experiences on being audited Yoshio Tanaka
Authentication Policy David Kelsey CCLRC/RAL 15 April 2004, Dublin
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
Security Mechanisms The European DataGrid Project Team
9/20/2000www.cren.net1 Root Key Cutting and Ceremony at MIT 11/17/99.
NECTEC-GOC CA APGrid PMA face-to-face meeting. October, Sornthep Vannarat National Electronics and Computer Technology Center, Thailand.
NENA Development Conference | October 2014 | Orlando, Florida Security Certificates Between i3 ESInet’s and FE’s Nate Wilcox Emergicom, LLC Brian Rosen.
13-May-03D.P.Kelsey, WP8 CA and VO organistion1 CA’s and Experiment (VO) Organisation WP8 Meeting EDG Barcelona, 13 May 2003 David Kelsey CCLRC/RAL, UK.
12-May-03D.P.Kelsey, SCG Online Authentication1 Online Authentication SCG Meeting EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
Configuring Directory Certificate Services Lesson 13.
DataGrid WP6 CA meeting, CERN, 12 December 2002 IISAS Certification Authority Jan Astalos Department of Parallel and Distributed Computing Institute of.
9-May-02D.P.Kelsey, Security Plans, GridPP41 Security: Plans 9 May 2002 GridPP4 meeting, Manchester David Kelsey CLRC/RAL, UK
Summary from CA coordination and Security working group meeting WP4 workshop
March 27, 2006TAGPMA - Rio de Janeiro1 Short Lived Credential Services Profile Tony J. Genovese The Americas Grid PMA DOEGridsATF/ESnet/LBNL.
NECTEC-GOC CA Self Audit 7 th APGrid PMA Face-to-Face meeting March 8 th, 2010 Large-Scale Simulation Research Laboratory Sornthep Vannarat Large-Scale.
10-Jun-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 10 June 2003 David Kelsey CCLRC/RAL, UK
IHEP Grid CA Status Report Wei F2F Meeting 8 Mar Computing Centre, IHEP,CAS,China.
Public Key Infrastructure (X509 PKI) Presented by : Ali Fanian
Profile for Portal-based Credential Services (POCS) Yoshio Tanaka International Grid Trust Federation APGrid PMA AIST.
3-Nov-00D.P.Kelsey, HEPiX, JLAB1 Certificates for DataGRID David Kelsey CLRC/RAL, UK
10-May-01D.P.Kelsey, Security Workshop Summary1 DataGrid Security Workshop 29/30 March 2001 SUMMARY David Kelsey CLRC/RAL, UK
Sam Morrison APAC CA – APGridPMA - ISGC2010 APAC CA Self Audit and status update Sam Morrison ARCS.
HEPSYSMAN UCL, 26 Nov 2002Jens G Jensen, CLRC/RAL UK e-Science Certification Authority Status and Deployment.
Academia Sinica Grid Computing Certification Authority (ASGCCA)
Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre.
3-Jul-02D.P.Kelsey, Security1 Security meetings Report to EDG PTB 3 Jul 2002 David Kelsey CLRC/RAL, UK
Security Mechanisms The European DataGrid Project Team
Who’s watching your network The Certificate Authority In a Public Key Infrastructure, the CA component is responsible for issuing certificates. A certificate.
23-Oct-02D.P.Kelsey, Grid Security, HEPiX, FNAL1 LCG/EDG Security - update and plans HEPiX/HEPNT - FNAL 23 Oct 2002 David Kelsey CLRC/RAL, UK
Security fundamentals Topic 5 Using a Public Key Infrastructure.
Grid Canada Certificate Authority Darcy Quesnel
Academia Sinica Grid Computing Certification Authority (ASGCCA) Academia Sinica Computing Centre.
2-Sep-02D.P.Kelsey, WP6 CA, Budapest1 WP6 CA report Budapest 2 Sep 2002 David Kelsey CLRC/RAL, UK
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
11-Dec-00D.P.Kelsey, Certificates, WP6 meeting, Milan1 Certificates for DataGrid Testbed0 David Kelsey CLRC/RAL, UK
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
12-Jun-03D.P.Kelsey, CA meeting1 CA meeting Minimum Requirements CERN, 12 June 2003 David Kelsey CCLRC/RAL, UK
MICS Authentication Profile Maintenance & Update Presented for review and discussion to the TAGPMA On 1May09 by Marg Murray.
10-May-01D.P.Kelsey, WP6 Security1 Certificates/Authorisation for DataGrid Testbeds David Kelsey CLRC/RAL, UK
7-May-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Issues and Planning or Report from the Security Group CERN, 8 May 2003 David Kelsey CCLRC/RAL, UK.
11-May-01D.P.Kelsey, Security Update1 GRID Security Update David Kelsey CLRC/RAL, UK
Baltic Grid Certification Authority 15th EUGridPMA, January 28th 2009, Nicosia1 Self-audit Hardi Teder EENet.
Trusted Organizations In the grid world one single CA usually covers a predefined geographic region or administrative domain: – Organization – Country.
TR-GRID CA Self-Auditing Results and Status Update EUGridPMA Meeting September 12-14, 2011 Marrakesh Feyza Eryol, Onur Temizsoylu TUBITAK-ULAKBIM
18 th EUGridPMA, Dublin / SRCE CA Self Audit SRCE CA Self Audit Emir Imamagić SRCE Croatia.
GRID-FR French CA Alice de Bignicourt.
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
UGRID CA Self-audit report Sergii Stirenko 21 st EUGRIDPMA Meeting Utrecht 24 January 2011.
HellasGrid CA self Audit. In general We do operations well Our policy documents need work (mostly to make the text clearer in a few sections) 2.
Armenian e-Science Foundation Certification Authority Ara A. Grigoryan 1,2, Artem Harutyunyan 1,2,3, Arsen Hayrapetyan 1,2,4 1 Armenian e-Science Foundation;
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
7-Mar-01D.P.Kelsey, User access, WP6, Amsterdam1 WP6: GRID mapfiles and Users access policy David Kelsey CLRC/RAL, UK
David Kelsey CLRC/RAL, UK
Cryptography and Network Security
Presentation transcript:

8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK

8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam2 Members of WP6 CA group Luca dell AgnelloINFN, Italy Roberto AlfieriINFN, Italy Jean-Luc ArchimbaudCNRS, France Roberto CecchiniINFN, Italy Jorge GomesLIP, Portugal David GroepNIKHEF, NL Denise HeagertyCERN Dave Kelsey(Chair)RAL, UK Daniel KourilCesnet, Czech Rep. Rafael MarcoSpain Pietro Paolo MartucciCERN Andrew SansumRAL, UK

8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam3 Meetings 4/5 December 2000, CERN 2 March 2001, CERN Next meeting: 5 June 2001, CERN

8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam4 CA status National CA already in operation for DataGrid Testbed0 –CERN –Czech Republic –France –Italy –Netherlands –Portugal –Spain –UK Successful tests of globus job submission between CA domains Sites not represented?

8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam5 Certificates for users/hosts All testbed users should obtain a certificate from their own national CA. Same for host certificates See WP6 web page – Countries not yet running a CA –Implement one or –Find an existing CA willing to issue certificates Globus certificates are still OK for Testbed0 but should be avoided if possible –Will be removed in Testbed 1

8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam6 Configuration of systems See WP6 web We will provide configuration advice for globus –To configure complete list of trusted CA’s –To configure the certificate request mechanism –To maintain grid mapfile But no automatic updates Local site is free to accept trusted CA’s or not. –We will check CPS of each CA to define “trust”

8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam7 CA Policies CP (Certificate Policy) –Applicability of the certificate to a particular community and/or class of application CPS (Certification Practice Statement) –Practices used in issuing certificates INFN and NIKHEF have prepared a CP/CPS Others working on this –To be completed by mid-April Review of all CP and CPS by small group before Testbed 1

8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam8 Minimum CP/CPS Discussed a minimum set of requirements for a CP and CPS –Also being discussed in GGF Security WG Registration Authority (RA) –An acceptable procedure for confirming the identity of the requestor and the right to ask for a certificate –The RA should be the appropriate person to make decisions on the right to ask for a certificate and must follow the CP –requests for machine certificates must be signed by personal certificates or verified by other appropriate means Communication between RA and CA –Either by signed or some other acceptable method

8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam9 Minimum CPS (2) Certification Authority (CA) –The issuing machine must be: a dedicated machine located in a secure environment Not connected to any network be managed in an appropriately secure way by a trained person –the CA private key (and copies) should be locked in a safe or other secure place must be encrypted with a pass phrase having at least 15 characters the pass phrase must only be known by the Certificate issuer(s)

8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam10 Minimum CPS (3) minimum length of user private keys must be 1024 min length of CA private key must be 2048 lifetime of personal certificates should be no longer than one year. question: how many farm nodes will require host certs? And how long should these certs live? Revocation – see later Users must generate their own private key and must keep this private and secure Publishing of user public keys is not required.

8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam11 Minimum CPS (4) Recording - audit trail –RAs must record and archive all requests all confirmations –CAs must record and archive all requests for certs all issued certs all requests for revocation all issued CRLs login/logout/reboot of the issuing machine

8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam12 Naming To date, different choices have been made –No proof of uniqueness Longer term, do we want a hierarchical namespace? (o=hep?) Coordination with Info services LDAP namespace? This needs further study

8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam13 Revocation lost or compromised private key person left organisation Can be requested by either the user or the RA Every CA must generate and maintain a CRL –The lifetime of the CRL should be no more than 30 days. –This must be updated immediately after every revocation and at least before the expiry of the lifetime. All clients must update their local copies of CRL's at least once per day.

8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam14 General Security group PTB asked me to join the ATF for security –See my talk on Friday 9 th March –I propose to create a general security group WP6 security reps plus reps from other WP’s plus … How do we handle authorisation in DataGrid? Strong recommendation not to mix authentication and authorisation –Industry trends PMI (privilege management infrastructure) –X.509V3 extension fields should only carry authorisation information that is stable and constant over time –“Attribute Certificates” – PKIX IETF working group –CAS from Globus looks very interesting

8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam15 Future Plans Complete WP6 web pages with CA details and configuration advice (by Easter) CA’s to complete CP and CPS (by Easter) Small group to review all CP/CPS (before Testbed 1) More work under the general security group –Authorisation –Mapfiles –etc