150 likes | 267 Views
UK e-Science Certification Authority. Jens G Jensen j.jensen@rl.ac.uk. So what is it?. UK e-Science Certification Authority. Yes, but what is it?. A certificate identifies you to a remote computer - the certificate says you are who you claim to be.
E N D
UK e-Science Certification Authority Jens G Jensen j.jensen@rl.ac.uk
So what is it? • UK • e-Science • Certification • Authority
Yes, but what is it? • A certificate identifies you to a remote computer - the certificate says you are who you claim to be. • A certificate does not contain personal information (other than your name). • A certificate does not contain authorisation information
So, how does it work? 1. Scientist wishes to access a resource, so he sends a copy of the certificate to the resource 2. Resource says: prove it’s your certificate Challenge Response 3. Scientist proves that he has the corresponding private key 4. Resource is convinced that scientist is who he claims to be and decides to give him access Private Key
So what’s a certificate, really? • A certificate is user’s name and public key, signed by a certification authority. • A certificate is useless without a valid signature. • A certificate is useless without the corresponding private key. • The user is responsible for keeping the private key safe.
Yes? So how do I get one? Apply for a certificate (online): • Name • Email address • RA The RA is the Registration Authority. The RA will verify to the CA (Certification Authority) that you are who you say you are. The RA is a local person.
Then what happens? • Your browser generates a public/private key pair (RSA) • The public key is put in the request and sent off to the CA • The private key never leaves the browser The certificate request contains the things that will be in your certificate, namely your name and your public key.
And? Go to the RA with • Photo ID The RA guarantees that the certificate request was created by you.
This is exciting! What next? • The RA approves your request. • The CA issues a certificate to you. • You can download the certificate but it will also be sent by email.
What else should I know? The namespace. Certificates are issued with names of the following form: /C=UK/O=eScience/OU=GridPP/L=Manchester/CN=Joe Bloggs /C=UK/O=eScience /OU=GridPP/L=Manchester /CN=Joe Bloggs That’s us! This identifies the RA, not your organisation, not your location That’s your name
Tell me more about names! • The OU and the L are the organisation and location of the RA. That means everybody knows who approved your certificate request! • The OU is a name that identifies the eScience project. • Your request can be approved by an RA in a different project!
So what’s new? • Web interface - easier to use • RAs are local • better qualified to verifying users • workload distributed - not everything depends on CA
External collaborators • EU DataGrid - http://www.eu-datagrid.org/http://marianne.in2p3.fr/datagrid/ca/ • JISC (Joint Information Systems Committee) http://www.jisc.ac.uk • Other Grids, e.g., CrossGrid - http://www.crossgrid.org/
So who’s working on this? Other people involved with the CA: • David Boyd • Ruth Dixon del Tufo • Tim Pett • Andrew Sansum • Matt Thorpe • Richard Wong
URL User and RA procedures http://www.grid-support.ac.uk/ca/interim_procedure.html