A history of the CACG, EUGridPMA, and the IGTF
(and some next steps)
First APGridPMA Face-to-Face Meeting Beijing
David Groep, 2005-11-29
A history of the CACG, EUGridPMA, and the IGTF (and some next - - PowerPoint PPT Presentation
A history of the CACG, EUGridPMA, and the IGTF (and some next steps) First APGridPMA Face-to-Face Meeting Beijing David Groep, 2005-11-29 A brief history From the CACG to EUGridPMA to IGTF The EU DataGrid CACG The EUGridPMA:
David Groep, 2005-11-29
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 2 David Groep – davidg@eugridpma.org
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 3 David Groep – davidg@eugridpma.org
The EU DataGrid in 2000 needed a PKI for the test bed
PKI
was not convenient to support with existing software
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 4 David Groep – davidg@eugridpma.org
First CA coordination meeting for the DataGrid project
First version of the minimum requirements
5 CAs: France (CNRS), Portugal (LIP), Netherlands (NIKHEF), CERN, Italy (INFN), UK (UK eScience)
Extension to other projects: EU-CrossGrid
…
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 5 David Groep – davidg@eugridpma.org
Minimum requirements for RA - Testbed 1
for a certificate e.g. by personal contact or some other rigorous method The RA should be the appropriate person to make decisions on the right to ask for a certificate and must follow the CP. Communication between RA and CA
known person Minimum requirements for CA - Testbed 1
a dedicated machine located in a secure environment be managed in an appropriately secure way by a trained person the private key (and copies) should be locked in a safe or other secure place the private keu must be encrypted with a pass phrase having at least 15 characters the pass phrase must only be known by the Certificate issuer(s) not be connected to any network minimum length of user private keys must be 1024 min length of CA private key must be 2048 requests for machine certificates must be signed by personal certificates or verified by
...
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 6 David Groep – davidg@eugridpma.org
for other mechanisms) – goal is a single common identity for every person
shape the minimum requirements
to (re) evaluate members on entry & periodically
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 7 David Groep – davidg@eugridpma.org
GRIDPMA.org
16 countries, 19 organizations
AIST, Japan; SDSC, USA; KISTI, Korea; Bll, Singapore; Kasetsart Univ., Thailand; CAS, China
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 8 David Groep – davidg@eugridpma.org
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 9 David Groep – davidg@eugridpma.org
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 10 David Groep – davidg@eugridpma.org
The European Policy Management Authority for Grid Authentication in e-Science (hereafter called EUGridPMA) is a body
providers
end-entities in inter-organisational access to distributed resources. As its main activity the EUGridPMA
for use with Grid authentication middleware. The EUGridPMA itself does not provide identity assertions, but instead asserts that - within the scope of this charter – the certificates issued by the Accredited Authorities meet or exceed the relevant guidelines.
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 11 David Groep – davidg@eugridpma.org
(CESNET, ESnet, Belnet, NIIF, EEnet, SWITCH, DFN, … )
(UK eScience, VL-e, CNRS, … )
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 12 David Groep – davidg@eugridpma.org
Other Accredited CAs:
* Migrated to APGridPMA per Oct 5th, 2005
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 13 David Groep – davidg@eugridpma.org
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 14 David Groep – davidg@eugridpma.org
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 15 David Groep – davidg@eugridpma.org
5 10 15 20 25 30 35
accredited CAs
Mar-01 Jun-01 Sep-01 Dec-01 Mar-02 Jun-02 Sep-02 Dec-02 Mar-03 Jun-03 Sep-03 Dec-03 Mar-04 Jun-04 Sep-04 Dec-04
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 16 David Groep – davidg@eugridpma.org
TAGPMA APGridPMA
The America’s Grid PMA Asia-Pacific Grid PMA European Grid PMA
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 17 David Groep – davidg@eugridpma.org
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 18 David Groep – davidg@eugridpma.org
(.us)
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 19 David Groep – davidg@eugridpma.org
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 20 David Groep – davidg@eugridpma.org
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 21 David Groep – davidg@eugridpma.org
Characteristics Relying Party requests
approximate parity in CAs
issue unique names
about CAs which you accredit
(list courtesy of the Open Science Grid)
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 22 David Groep – davidg@eugridpma.org
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 23 David Groep – davidg@eugridpma.org
via a network of Registration Authorities
hardware
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 24 David Groep – davidg@eugridpma.org
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 25 David Groep – davidg@eugridpma.org
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 26 David Groep – davidg@eugridpma.org
classic, SLCS, experimental*, …
including a ‘meta’ package with dependencies per profile
install’
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 27 David Groep – davidg@eugridpma.org
A trusted repository which contains verified root-CA certificates The certificates to be collected are those directly managed by the member NRENs, or belonging either to a National Academic PKI in the TERENA member countries (NPKIs), or to non-profit research projects directly involving the academic community.
(and not exclusively for grid use)
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 28 David Groep – davidg@eugridpma.org
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 29 David Groep – davidg@eugridpma.org
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 30 David Groep – davidg@eugridpma.org
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 31 David Groep – davidg@eugridpma.org
e-IRG: e-Infrastructure Reflection Group Roadmap for i2010:
Towards an integrated AAI for academia in Europe and beyond
conjunction with the TACAR CA Repository and it expresses its satisfaction for a European initiative that serves e-Science Grid
TACAR to continue their valuable work […] (Dublin, 2004)
academia and research institutes that ensures mutual recognition
(The Hague, 2005)
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 32 David Groep – davidg@eugridpma.org
(includes authorization as well, and even software discussions)
HAKA, FEIDE/Moria
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 33 David Groep – davidg@eugridpma.org
In no particular order …
Discussion on the Wiki, e.g.
https://grid.ie/eugridpma/wiki/Annotated_Classic_AP
First APGridPMA Face-to-Face Meeting Beijing – Nov 2005 - 34 David Groep – davidg@eugridpma.org
Graphic by David O’Callaghan, Poznan 2005