January 2002 Status report


Goals this month

  1. Set up offline and online CAs
  2. Issue test certificates
  3. Update CP/CPS
  4. Specify Hardware for CAs and Remote managers
  5. Establish PMA

Achievements

We have also begun setting up our Policy Management Authority, who will be responsible for the management of the DOESG PKI. The list of PMA members will include all Registration Authority agents.  Currently we have: Mike Helm (ESnet), Von Welch (Globus), Tony Genovese (ESnet), Mary Thompson (FNC), Doug Olsen (PPDG), John Volmer (ANL), William Johnson (DOESG PI), Jim Leighton (ESnet PI) and Keith Jackson (DOESG). 

During January we were able to set up our off line and online CAs, plus one development CA.  This architecture was designed to serve our initial low volume customers.  During our initial roll out a new requirement to handle a large volume of certificate requests was identified.  We have made an emergency order for additional servers and reengineering the architecture to handle this. We have begun issuing certificates to our RA agents - Doug Olsen was the first for PPDG. He has been able to issue some end entity certificates for his community.  

Input from the community has been incorporated in the CP/CPS.  Version 1.2 is out for review. 

The service is scaling up slowly as the community requirements are shaken out and our RA agents get their sea legs.  The service may have to redo its root service to meet these changing requirements.  This could be disruptive if we have to re-issue certificates, but all efforts are being done to allow the architecture to change.

We have now deployed Registration Authorities at LBNL for PPDG, FNC and DOESG. PNNL is scheduled to bring up their RA in the February timeframe - but they may move this date further out.  We have also identified RAs for ANL and NERSC. ANL and NERSC are scheduled to roll out their service in the next few months. We still need to identify an RA for ORNL 

We have now specified the Hardware and Software for use in the service.  Orders for the new Hardware will be done the week of February 11th.  The schedule for the project:  

Schedule

Item

Date

Comments

Install Hosts

Oct, 23

3 Systems have been racked

Root CA

November, 30

 

No significant work in December

 

Travel, vacation and laboratory seasonal closer.

RA for PPDG and NFC

January 15, 2002

 

Order equipment, servers etc.

February 8, 2002

This is for the secure build out of the PKI in Room 2275.

RA for PNNL

February 15, 2002

 

Beta PPDG, NFC & PNNL certificates

February 15, 2002

 

Hire developer

March 1, 2002

 

CA repository online

March 1, 2002

 

EDG participation

April 1, 2002

 

Start adding new RAs

May 15, 2002

New RAs will be added to schedule. This is dependent on the Secure servers being finished and configured.

CP/CPS – sign off

June 1, 2002

PMA has been set up and approves CP/CPS

Migrate Beta CA/RAs systems to match final CP.

July 15, 2002

 

Issue EDG acceptable Certificates for Test Bed 2

July 1, 2002

 

General release of service

October 1, 2002

System support staff take over daily operation

Problems

Procurement is not an exact science and it is hard to get fixed dates.  Also, configuration and racking of our servers may be delayed to meet priorities of ESnet operations. The dates in the above schedule reflects some time allowances.