Overview of DFN`s Certificate Services - Regular, Grid and short-lived -



Similar documents
The InCommon Certificate Service FAQ This document subject to change as elements of the program are refined.

Reading an sent with Voltage Secur . Using the Voltage Secur Zero Download Messenger (ZDM)

Digital Certificates (Public Key Infrastructure) Reshma Afshar Indiana State University

VPN: Virtual Private Network Setup Instructions

Securing ArcGIS Server Services: First Steps

Campus VPN. Version 1.0 September 22, 2008

Flexible Identity Federation

IGI Portal architecture and interaction with a CA- online

Apple Inc. Certification Authority Certification Practice Statement Worldwide Developer Relations Version 1.14 Effective Date: September 9, 2015

Sophos UTM. Remote Access via PPTP Configuring Remote Client

This manual will help you connect your Microsoft Windows XP, Vista, or 7, or Apple OS X computer to the University of Maryland campus data network.

6. Is it mandatory to have the digital certificate issued from NICCA? Is it mandatory for the sender and receiver to have a NIC id?...

Portal Recipient Guide

Secure Web Appliance. SSL Intercept

PKI: Public Key Infrastructure

SAML-Based SSO Solution

Using etoken for SSL Web Authentication. SSL V3.0 Overview

Website Administration Security Guide

Access Your Cisco Smart Storage Remotely Via WebDAV

Remember, this is not specific to your address alone... the METHOD you retrieve your is equally important.

VPN Web Portal Usage Guide

Personal Secure Certificate

Personal Secure Certificate

CHARTER BUSINESS custom hosting faqs 2010 INTERNET. Q. How do I access my ? Q. How do I change or reset a password for an account?

Australian Synchrotron, Storage Gateway

Technical notes for HIGHSEC eid App Middleware

Authentication Methods

Sophos Mobile Control Installation guide

SAS Visual Analytics 7.2 for SAS Cloud: Quick-Start Guide

Sophos UTM. Remote Access via IPsec Configuring Remote Client

eduroam wireless setup guide for Windows 7, XP and Vista

Entrust Managed Services PKI Administrator s Quick Start Guide

Remote Access End User Reference Guide for SHC Portal Access

GlobalSign Integration Guide

Grid Computing - X.509

Recommended Browser Setting for MySBU Portal

Certificates for computers, Web servers, and Web browser users

Web Manual: September 2014

How do I start a meeting?

Web Conferencing Version 8.3 Troubleshooting Guide

Alberni Valley IT Services Virtual domain information.

Ciphermail for BlackBerry Quick Start Guide

FAQS. You can schedule a WebEx session ahead or start it instantly in your choice of ways:

Wavecrest Certificate

SEZ SEZ Online Manual Digital Signature Certficate [DSC] V Version 1.2

The SSL device also supports the 64-bit Internet Explorer with new ActiveX loaders for Assessment, Abolishment, and the Access Client.

GO!Enterprise MDM Device Application User Guide Installation and Configuration for ios with TouchDown

Djigzo S/MIME setup guide

DFN-Services - what is the benefit for large scientific collaborations?

Mobile OTPK Technology for Online Digital Signatures. Dec 15, 2015

EURECOM VPN SSL for students User s guide

Tidspunkt : : :59 (49 dag(e)) Operativsystem (OS) fordelt på browsere Total: Safari9 ios %

Remote Access Services Microsoft Windows - Installation Guide

Web Manual: October 2015

What security and assurance standards does Trustis use for TMDCS certificate services?

How To Sync Google Drive On A Mac Computer With A Gmail Account On A Gcd (For A Student) On A Pc Or Mac Or Mac (For An Older Person) On An Ipad Or Ipad (For Older People) On

How To Login To Webex Online

Accessing UniSIM MyMail For Students and Associates Via Microsoft Office 365. UniSIM - Restricted

National Certification Authority Framework in Sri Lanka

How To Make A Trustless Certificate Authority Secure

Sophos UTM. Remote Access via SSL Configuring Remote Client

Digital Signature Certificate Online Enrollment Guide using etoken

Class 3 Registration Authority Charter

Requirements on terminals and network Telia Secure Remote User, TSRU (version 7.3 R6)

Mail Programs. Manual

Brocade Engineering. PKI Tutorial. Jim Kleinsteiber. February 6, Page 1

Recommended operating systems and software for end user services. Operating systems and software not supported for end user services

GO!Enterprise MDM Device Application User Guide Installation and Configuration for ios Devices

Middleware integration in the Sympa mailing list software. Olivier Salaün - CRU

User Documentation. Available Services 1. Quick Links 1. External Links 1. Logging on/off Changing your password 3

Bugzilla ID: Bugzilla Summary:

SHC Client Remote Access User Guide for Citrix & F5 VPN Edge Client

Using the FDO Remote Access Portal

Agenda. How to configure

Sophos Mobile Control Installation guide. Product version: 3.5

How to use

Sophos UTM. Remote Access via PPTP. Configuring UTM and Client

How to configure your Desktop Computer and Mobile Devices post migrating to Microsoft Office 365

How To Configure Using Different Clients

8x8 Click2Pop User Guide

CSC E Mail. Mobile Device Configuration Settings and Setup Instructions

To participate in the hands-on labs in this class, you need to bring a laptop computer with the following:

Setting up secure communication with Ericsson. Guideline for Ericsson partners

Easily integrate Mac into Microsoft System Center

UMMS SSL VPN Instructions

Realize Greater Profits As An Authorized Reseller Of Network Solutions nsprotect Secure SSL Certificates

SCS: the new Server Certificate Service offering from SWITCH/TERENA

Dr. Cunsheng DING HKUST, Hong Kong. Security Protocols. Security Protocols. Cunsheng Ding, HKUST COMP685C

Overview of Extended Validation (EV) SSL

Digital certificates and SSL

Transcription:

Overview of DFN`s Certificate Services - Regular, Grid and short-lived - Marcus Pattloch (DFN-Verein) DESY Computing Seminar 13. July 2009, Hamburg

Overview Certificates what are they good for (and what not)? Regular Certificates what (almost) everyone needs Grid Certificates why another hierarchy? Short-lived Certificates (SLCS) shibboleth, DFN-AAI, identity management Conclusions Seite 2

Certificates Seite 3

What is a certificate? Certificate = digital identity card for use on the internet Once I have a certificate and use it in electronic communication, everyone can prove that I am who I claim to be E.g. on a chipcard (but: not every chipcard contains a certificate) Marcus Pattloch Seite 4

Use of certificates Confidentiality encryption of documents and e-mails Signature signing.pdf documents signing e-mails creating time stamps on documents Authentication (not authorization!!) server identification (SSL, https) ID for access to protected websites ID for access to databases etc. (ssh, IPsec) Seite 5

Digital identity card my private key & my personal data Marcus Pattloch An infrastructure is needed to guarantee the link between the private key and the personal data. This is done by a public key infrastructure (PKI) Seite 6

What is a PKI? A PKI is an infrastructure generating certificates and consisting of the following main components Registration Authorities (RA) Certification Authorities (CA) Policies Directory Service for certificates (PKI-aware applications) Seite 7

Splitting tasks makes it much easier Registration Authority administrative tasks done on site Certification Authority technically demanding tasks organisationally demanding tasks operated by DFN for all (!) sites Seite 8

Hierarchy of CAs DFN-PCA Univ. of Hamburg CA DESY CA... Certification Authority n......... Person A... Server B Person C... Server D Person X Seite 9

List of DFN-PKI participants http://www.pki.dfn.de Seite 10

Mozilla and certificates Very useful add-on for Mozilla Firefox and Thunderbird Cert Viewer Plus 1.5 by Kaspar Brand (Switch - Swiss research network) extension of menue improved saving and viewing of certificates Seite 11

Regular Certificates Seite 12

Regular certificates Regular (non-grid) certificates are what most people need Validity of certificates server certificates max. 5 years user certificates max. 3 years CA certificate max. 12 years Certificates are linked into standard webbrowsers, i.e. no pop-up boxes from webservers e-mail signatures can automatically be verified Seite 13

Status of integration Status of integration of Telekom Root CA2, thus also of root of DFN-PKI Global Windows: all desktop versions (2k, XP, Vista, 7) Apple: since June 2008 (OS X, ipod, iphone) Opera: since 2008 Mozilla: since Firefox 3.5, Thunderbird 3.0 Sun Java: since V6u11 (11.08) Google Chrome: yes, independent of OS All details about integration: www.pki.dfn.de/integration Seite 14

Demo: Obtaining a regular certificate http://www.pki.dfn.de/testpki-zugang Seite 15

Summary: Regular certificates More than 250 sites in Germany have a CA within DFN-PKI More than 60.000 valid certificates issued Regular certificates do the job and are what everyone needs but there is one exception... Seite 16

Grid Certificates Seite 17

Accessing resources in D-Grid (1) Within a VO no (grid) certificates necessary TextGrid BauVOGrid AstroGrid Seite 18

Accessing resources in D-Grid (2) More than 25 other D-Grid projects! TextGrid BauVOGrid AstroGrid Seite 19

Grid PMAs To deal with certificates in grids a new body was set-up by grid / HEP people European Grid Policy Management Authority (EUGridPMA) definition of policies and procedures for (worldwide) use of grid certificates International Grid Trust Federation IGTF EUGridPMA Asia Pacific PMA The Americas PMA Seite 20

Grid certificates in Germany DFN Grid CA (DFN-Verein) and GridKA CA (FZ Karlsruhe) are both accredited to EUGridPMA DFN Grid CA GridKA CA C= DE C= DE O= GridGermany O= GermanGrid OU= site name OU= site name [OU] = e.g. name of division CN= given name surname CN= given name surname [hostname/service] [hostname/service] Seite 21

Obtaining a grid certificate Seite 22

Regular vs. grid certificates Why not just use regular certificates in grids? technically no difference (both based on X.509) But grid certificates have to follow some strange rules, e.g. basically just one CA per country no sub-cas thus no CA-hierarchies very short validity of certificates (max. 13 months) Strange rules for grid certificates force users to have more than just one certificate hard to see a practical reason for this... Seite 23

Status quo Issuing grid certificates in D-Grid works Number of issued certificates is much smaller than in the regular world Users complain that they need different certificates that they have to obtain a new grid certificate every 12 month The question remains whether current grid certificates are the perfect solution... Seite 24

Certificates in D-Grid Documents about certificates in D-Grid Authentifizierung im D-Grid (12.2005) Split between authentication and authorization Registration authorities (RAs) per site, not for dynamic structures like projects or VOs Non-academic partners can basically be served by every RA Verwendung von Zertifikaten im D-Grid (3.2008) New types of Grid certificates possible (SLCS, Robotcertificates for use in portals) All D-Grid certificates require face-to-face identification of subscribers (= someone who wants a certificate) Seite 25

Short-lived Certificates Seite 26

SLCS (1) Some grid users don t want to have a certificate at all but: use of grid middleware is only possible with certificates Idea for new type of grid certificates was born SLCS (Short Lived Credential Services) idea: create short-lived certificate on-the-fly using standard user credentials (userid, password) this should make everything much easier, but... Seite 27

SLCS (2) Security requirements for SLCS are as high as for grid certificates e.g. face-to-face identification of subscribers This results in an even more complicated basic infrastructure GridShib software Shibboleth based authentication / authorization infrastructure (DFN-AAI) identity management system in place, data must be updated regularly Seite 28

Live Demo: SLCS Certificate https://test-slcs.pca.dfn.de/gridshib-ca/ Seite 29

SLCS architecture for portals Seite 30

Conclusions Seite 31

Conclusions DFN offers different kinds of certificates regular, grid, SLCS share of regular certificates is around 98% (!) but for the time being grid users need at least two certificates Obtaining a certificate is quite easy since more than 250 sites take part in DFN-PKI More information www.pki.dfn.de pki@dfn.de Seite 32