Dear Users and Relying Parties of the IGTF and EUGridPMA
Following the severance of three (out of four) undersea cables in the
Mediterranean basin on December 19th, 2008, around 7.30 CET,
your ability to retrieve Certificate Revocation Lists (CRLs) for
some of the IGTF accredited authorities may be limited or absent.
France Telecom, the company responsible for the maintenance of the
cables (Sea Me We3, Sea Me We4, FLAG) is working to repair these
cables and restore connectivity as soon as possible, but it
may take up to December 31st to fully recover. Please see their
press release at:
http://www.francetelecom.com/en_EN/press/press_releases/cp081219en.html
This affects CAs located in the Middle East (in particular PK-Grid (PK)
with hash f5ead794 and IRAN-Grid (IR) with hash ce33db76), as well as MaGrid.
Although not apparent from the press release, academic connectivity to
Morocco (by MARWAN) is provided through the EUMedConnect hub in
Palermo, Sicily, and also suffers from this outage.
Connectivity to PK and IR is intermittent, whereas connectivity to MA
is completely lost since Dec 19th, 0730 CET. At this moment, we have
no better estimates than those made public by France Telecom as to when
service will be restored.
We apologize for this inconvenience.
Best Regards,
David Groep.
--
David Groep
** Nikhef, Dutch National Institute for Sub-atomic Physics,PDP/Grid group **
** Room: H1.56 Phone: +31 20 5922179, PObox 41882, NL-1009DB Amsterdam NL **
Dear CAs, Relying Parties, Users, and all others interested,
In this announcement of the IGTF:
1. Updated IGTF distribution version 1.26 available
=========================================================================
1. Updated IGTF distribution version 1.26 available
=========================================================================
A new distribution of Accredited Authorities by the EUGridPMA, based
on the IGTF Common Source, is now available. It includes the newly
accredited Authorities by all IGTF Members and retires expiring CA
certificates. This is version 1.26, release 1, and it is now available for
download from the Repository (and mirrors) at
https://dist.eugridpma.info/distribution/igtf/current/
Changes from 1.25 to 1.26
-------------------------
(14 December 2008)
* Added accredited classic Indian Grid CA (IGCA) (hash da75f6a8) (IN)
* Updated IUCC root certificate with extended life time (IL)
* Updated BEGrid (web, CRL) and UCSD-PRAGMA (web) URL metadata (BE, AP)
* New BEGrid2008 root certificate (transitional) (BE)
* Extended life time of the SEE-GRID CA (SEE)
* Included CRL for NCSA SLCS CA (US)
* Temporally suspended NGO-Netrust CA (SG)
* Withdrawn expired old PK-Grid CA (d2a353a5, superseded by f5ead794) (PK)
* Experimentally added Texas Advanced Computer Center TACC Root,
Classic, and MICS CAs to the experimental area (US)
If you part of a coordinated-deployment project (such as OSG, EGEE, LCG,
DEISA, NAREGI or others) you may want to await your project announcement
before installing this release.
The download repository is also mirrored by the APGridPMA at
https://www.apgridpma.org/distribution/igtf/current
Note that the location of the igtf-policy-installation-bundle tar-ball
has changed. It is now in the root of the distribution area, as it
contains not only the accredited but also worthless and experimental CAs.
Next Release
------------
The next release of the CA distribution is to be expected at the
beginning of February 2009.
=========================================================================
STANDARD CLAUSES AND REPEATED NOTICES
=========================================================================
Subscribing to the EUGridPMA Newsletter
---------------------------------------
This newsletter carries IGTF information intended for relying parties.
For more information about this newsletter and how to subscribe,
refer to the EUGridPMA web site at https://www.eugridpma.org/
What is contained in the IGTF Trust Anchor Distribution
-------------------------------------------------------
*** ONLY CAs IN THE "accredited/" DIRECTORY and THE CAs INSTALLED
USING THE ca_policy_igtf-classic-<VERSION>-1.noarch.rpm ARE ACCREDITED
Do *not* install certificates from the "worthless/" or "experimental/",
directories, except if you yourself review and accept their policy and
practice statement. The EUGridPMA provides these certificates in
this format for your convenience only, and to allow graceful changeover
for legacy installations.
*** All individual CAs packages, as well as the bundles, have the same
(common) version number and release.
Distribution formats
--------------------
* the distribution containes RPMs and tar-balls of each accredited authority,
as well as meta-RPMs that depends on the RPMs of those accredited.
* the tar "bundle" can be used to install the authorities in a local trust
anchor directory using the "./configure && make install" process:
igtf-policy-installation-bundle-<VERSION>.tar.gz
* the accredited directory contains tar-balls for all "classic", "mics",
and "slcs" accredited CAs:
igtf-preinstalled-bundle-classic-<VERSION>.tar.gz
igtf-preinstalled-bundle-slcs-<VERSION>.tar.gz
igtf-preinstalled-bundle-mics-<VERSION>.tar.gz
* those CAs whose key-length is less than or equal to 2048 bits are also
available in a Java KeyStore (JKS), whose password is "" (empty string).
These is both a JKS for each individual CA, as well as a
"igtf-policy-accredited-classic-<VERSION>.jks" in the "accredited/jks/"
sub-directory (also for -slcs and -mics).
APT and Yum
-----------
As always, the repository is suitable for "yum" based automatic updates,
by adding to the yum.conf file:
[eugridpma]
name=EUGridPMA
baseurl=http://dist.eugridpma.info/distribution/igtf/current/
gpgcheck=1
Also "apt" is supported. For details, see
https://dist.eugridpma.info/distribution/igtf/current/apt/README.txt
Large deployment projects are kindly requested to mirror these directories
in their own distribution repositories.
RPM GPG signing
---------------
Also this new RPM distribution is distributed with GPG-signed RPMs. The
key (ID 3CDBBC71) has been uploaded to the public key servers, along with
my signature as the EUGridPMA Chair (keyID 6F298418). The key is also
contained in the repository. You will need this key if you enable GPG
checking for automatic updates in "yum" or "apt".
Please remember to validate this distribution against the TACAR
trusted repository (https://www.tacar.org/) where possible.
Suggestions
-----------
If you have suggestions or improvements for the distribution format,
to have it better suit your needs, please contact the PMA at
<info(a)eugridpma.org>. Note that there is be a common distribution format
across the entire IGTF (i.e. all three PMAs).
--
David Groep
** Nikhef, Dutch National Institute for Sub-atomic Physics,PDP/Grid group **
** Room: H1.56 Phone: +31 20 5922179, PObox 41882, NL-1009DB Amsterdam NL **