Presentation is loading. Please wait.

Presentation is loading. Please wait.

David Kelsey CLRC/RAL, UK

Similar presentations


Presentation on theme: "David Kelsey CLRC/RAL, UK"— Presentation transcript:

1 David Kelsey CLRC/RAL, UK d.p.kelsey@rl.ac.uk
WP6 CA Mgrs meeting 5 Mar 2002 David Kelsey CLRC/RAL, UK 5-Mar-02 D.P.Kelsey, WP6 CA Mgrs

2 Meetings WP6 Certificate Authorities Group
Defining procedures for Authentication/Trust Dec 2000, March, June, August, Dec 2001 and 5 March 2002 Agenda 5 Mar 02 Roundtable update Features/Acceptance Matrix GGF CP/CPS Authentication with other Grid projects (USA, CrossGrid) WP6 procedures Next meeting – June 2002 5-Mar-02 D.P.Kelsey, WP6 CA Mgrs

3 EDG CA’s roundtable Already in TB1
CERN, Czech Rep, France, Ireland, Italy, Netherlands, Nordic, Portugal, Russia, Spain, UK Several working on OpenCA as the implementation Should/will share expertise here Discussion about re-issue of expired certs (users and CA) Long jobs which live beyond life of cert? CA publishing issued certs in LDAP (For VO Authorisation) Some do, some don’t, some don’t want to Other Grid projects USA (LBL/ESnet DOE Science Grid) Karlsruhe (Germany, CrossGrid) 5-Mar-02 D.P.Kelsey, WP6 CA Mgrs

4 Features/Acceptance Matrix
Defined Minimum requirements for EDG CA (Jun01) N * N matrix to show status of “acceptance” Matrix still rather sparse right now! But Features matrix is in better shape Every CA checks that it “trusts” all others Brian Coghlan working on developing and automating the process Investigate using Grid info services Once we have N*N matrix may collapse to single row Using a modified set of min requirements “CA Managers” measure of “trust” 5-Mar-02 D.P.Kelsey, WP6 CA Mgrs

5 Inter-Grid authentication
USA DOE CA now in operation We reviewed their procedures in Dec 2000 Passed EDG criteria Add to Acceptance matrix Approved as a “trusted” CA First test USA – UK reported recently Karlsruhe (CrossGrid and Germany) CA in early operation with draft CP/CPS WP6 CA group will check this soon 5-Mar-02 D.P.Kelsey, WP6 CA Mgrs

6 Scaling Issues Now: 11 CA’s + 2 new
Potentially 7 more CrossGrid countries to come! But no overlap – one per country Can a semi-automated Acceptance matrix cope? OK for now so we should continue this way In the longer term, this will become more difficult! Must remember that authorisation should check user identity carefully we don’t want 2 heavy weight systems Investigate requirements for future Authentication Re-look at Root or Bridge CA Or GGF will solve the problem? 5-Mar-02 D.P.Kelsey, WP6 CA Mgrs

7 GGF CP/CPS Security Area GridCP working group
Discussed in GGF4 Toronto Aiming to help solve “Trust” problem Discussing CP/CPS, Audit, PMA, … Aim to finalise the CP models in GGF5 Edinburgh Our acceptance matrix methods may be useful 5-Mar-02 D.P.Kelsey, WP6 CA Mgrs

8 WP6 CA procedures “Catch all” CA for DataGrid -> CNRS (agreed)
For those without a CA (CEA, ESA, CSSI etc) But requested revised CP to state how RA works User training/documentation (many repeated cert requests!) Cal Loomis requests/suggestions Stability Subscription service for CRL’s Notification of updates Registry of trusted CA’s (GRID service) Subscription service for CA info We will investigate OCSP, OGSA – notification 5-Mar-02 D.P.Kelsey, WP6 CA Mgrs


Download ppt "David Kelsey CLRC/RAL, UK"

Similar presentations


Ads by Google