June 2002 Status report


Goals this month

  1. Set up new Remote RMs - testing
  2. LDAP publishing Directory - Online
  3. Review Hardware Security Modules - FIPS 140
  4. PMA guidelines effort
  5. Equipment status
  6. iVDGL added as new RA
  7. European Data Grid CA managers meeting
  8. Certificate service Statistics as of 6/20

Achievements

Develop configurations for new Remote Registration Manager

Dhiva has set up a Remote RM on the development system Amber. And continues the testing/evaluating the interaction with the Certificate manager (CM). This work is rolled up in to the RPMs that are used to distribute this software. This type of configuration allows us to limit the interactions (i.e. Certificate Requests) between RAs. There is a limitation though, in that the RA via the RM does not have full access to the CM feature set.  But this is not a major limitation, because the RA could always be able to go to the CM for access to its features.  The normal work flow of request/authorization can be done on the RM..  

LDAP directory to publish, subscriber certificates, CRLs, etc

We have brought on line the publishing directory of the DOEGrids service.  Dhiva has install a http gateway that allows web based access. You can reach it at: http://ldap.doesciencegrid.org/ds/search. You can also reach it via an LDAP client at ldap.doesciencegrid.org on the standard port 389. You can use the Web access to get to all the public certificates of the registered users.  This is a handy way of getting the public certificate for encrypting a message for an individual.

Hardware Security Modules

Mike Helm and Dhiva has been extensively evaluating this produces from: Rainbow, Chrysalis and Ncipher. The HSM has now become a requirement for the project. To meet the security requirement of EDG, we need to have one.  EDG requires the CA to be off line, but because of the size of our certificate service, this would be to costly. We proposed the use of HSM as a means to achieve a level of security that would be acceptable to them.  This is a long an detailed process, but should be finished by the October milestone. 

 PMA guidelines effort

Mike has volunteered to author a Grid Forum document on PMA guidelines.  He will start with our document and work with the GridCP working group to produce a document for the community.  This will be beneficial to both our project and the community. 

Equipment status

The security Racks have arrived and are waiting installation in the ESnet Data Center.  We expect this work, which requires LBL plant engineering, to be finished in September.  This will allow us to meet the October milestone.  

iVDGL added as new RA

Scott Koranda: skoranda@gravity.phys.uwm.edu has been vetted as a new Registration Authority representing the VO iVDGL. International Virtual Data Grid Laboratory has been added to our growing community:   

European Data Grid CA managers Meeting Prague

Several new CAs are joining the the EDG CA manager, that are originating in the CrossGrid programme. CrossGrid is an EU project, coordinated by the Poznan HPC Centre in Poland, with partners from several other EU states and associated states. Information is available from <http://www.eu-crossgrid.org/>.  This will effectively increase the number of CA that we will trust from the original 11 to 18.  Countries being added Slovakia, Cyprus, Germany, Greece, Poland, Portugal and Spain. A full copy of the meeting minutes can be found at:

http://www.dutchgrid.nl/DataGrid/ca-group/CA-coordination-20020627.txt

Presented status of our project and received comments on our architecture.  The EDG CA managers require that the CA be off line and that all Certificate signing Requests be handled by a human. This would not meet our operational needs.  Mike Helm presented an architecture based on using Hardware Security Modules (FIPS 140). He was able to secure a reasonable concession with this architecture.

Certificate service Statistics as of 6/20

  1. ~ 40 – 80 Certs per month issued
  2. Total Certificates issued: 258
  3. Certificates revoked:   29
  4. People Certificates 101
  5. Services Certificates 100
  6. Host (internal usage)   12
  7. Requests in Queue:    5

System design

Current ESnet Data Center design:

Schedule

Item

Date

Comments

Install Hosts

Oct, 23

3 Systems have been racked

Root CA

November, 30

 

No significant work in December

 

Travel, vacation and laboratory seasonal closer.

RA for PPDG and NFC

January 15, 2002

Done 

Order equipment, servers etc.

February 8, 2002

Done - This is for the secure build out of the PKI in Room 2275.

RA for PNNL

February 15, 2002

Done  

Beta PPDG, NFC & PNNL certificates

February 15, 2002

Done

Hire developer

March 1, 2002

Done

Add a RM and Directory server to development environment March 15, 2002 Done

EDG participation

April 1, 2002

Done  

Deploy separate CM and RM services April 10, 2002 Done - these are evaluation services and will be deployed as the community requires
New UI for service April 15, 2002 Done - New UI based on V2 CP requirements. Under eval by PMA, will be deployed as appropriate.
RPM for RM April 22, 2002 First version is done - working with NERSC to finalize details of process.
Deploy LDAP service April 29, 2002 Done - this service is in eval and will be deployed as appropriate. The service is now available on the website
Version 2.0 of CP/CPS April 30, 2002 Done - Written needs PMA approval

Start adding new RAs as appropriate.

May 15, 2002

Pending iVDGL approval and inclusion

CP/CPS – sign off

June 1, 2002

Done PMA approved 2.0 May 3

Issue EDG acceptable Certificates for Test Bed 2

July 1, 2002

Done - this requires EDG now to use it.

New naming structure August 1, 2002 Need PMA to approve new naming and DIT.
Roll out plan for version 2 architecture August 1, 2002 We need to maintain current PKI1 and deploy PKI2 to the community
Advance email notifications August 15, 2002 Add additional information to the email request notifications
Add additional information to the Directory listings of certificates September 1, 2002 Add information from the CSR to the directory listing of certificate.
     
Secure Racks Sep 15, 2002 The Racks have arrived and are being installed. This will take some time, as it requires Plant engineer to approve and do the electrical...

General release of service

October 15, 2002

System support staff take over daily operation

Problems

No significant issues open.