KEK Grid CASelf Audit Report Wataru Takase, Hiroyuki Matsunaga Computing Research Center KEK Japan

KEK Grid CASelf Audit Report Wataru Takase, Hiroyuki Matsunaga Computing Research Center KEK Japan
Slide Note
Embed
Share

This report discusses the CASelf Audit conducted at KEK, Japan in April 2019 by Wataru Takase and Hiroyuki Matsunaga from the Computing Research Center. It provides insights into the audit findings and discussions held during the IGTF All-Hands Meeting.

  • KEK
  • Computing Research
  • Japan
  • Audit
  • IGTF

Uploaded on Feb 24, 2025 | 0 Views


Download Presentation

Please find below an Image/Link to download the presentation.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author.If you encounter any issues during the download, it is possible that the publisher has removed the file from their server.

You are allowed to download the files provided on this website for personal or commercial use, subject to the condition that they are used lawfully. All files are the property of their respective owners.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author.

E N D

Presentation Transcript


  1. KEK Grid CA Self Audit Report Wataru Takase, Hiroyuki Matsunaga Computing Research Center, KEK, Japan IGTF All-Hands Meeting, April 2019

  2. Staff CA User administrator: Wataru Takase (since last August), Hiroyuki Matsunaga, Takashi Sasaki I am now in charge of the interview of an applicant Two Grid experts (KEK staff) in Belle II group (since last August) Interview Belle II collaborators (mostly in Japan and in US) Because of the service termination of the OSG CA, KEK GRID CA will issue a user certificate to US collaborators in Belle II Security officer: Shunsuke Takahashi, Go Iwai CA operator: Minoru Nakaya, Takayuki Sakadume RA 2 operators Help Desk

  3. Overview Classic X.509 CA. Approved by APGridPMA in Jan. 2006. Serves Japanese high-energy physics and related communities. Major players: Belle II, ATLAS, ALICE, ILC Belle II has started Physics run since last month. System is built with naregi-ca software. OCSP responder: Open CA CP/CPS Current version: 2.3.1 (October 2016) Stable operation this year.

  4. Statistics (as of April 1st) CA users Active users: 170 User certificates Total: 2742 Valid: 161 Host certificates Total: 3375 Valid: 121 Robot certificates Total: 37 Valid: 13

  5. Self Audit Conducted in mid January Results: 1 C and 1 D

  6. Rated C CP/CPS documents should be structured as defined in RFC 3647. Structured as defined in RFC 2527. Long-standing issue, but not yet done. Will revise the documents if we have time.

  7. Rated D The on-line CA architecture must provide for a log of issued certificates and revocations. This log should be tamper-protected. Due to limitation of our HSM (nCipher), the log is not tamper-protected. For the protection, we plan to send the log to an external device within 2 years.

More Related Content