Dear CAs, Relying Parties, Users, and all others interested,
In this announcement of the EUGridPMA:
1. New distribution 1.5 available with various updates
We hope that you find this update useful and welcome any comments you
may have. Also, feel free to redistribute this information widely as
you see appropriate.
Regards,
David Groep
For more information about this newsletter and the mailing list,
please refer to the EUGridPMA web site at https://www.eugridpma.org/
=========================================================================
1. New distribution (1.5) with various updates
=========================================================================
A new distribution of Accredited Authorities by the EUGridPMA, based
on the IGTF Common Source, is now available. It includes the newly
accredited Authorities by all IGTF Members. This is version 1.5,
release 1, and it is now available for download from the Repository at
https://www.eugridpma.org/distribution/igtf/current/
or
https://www.eugridpma.org/distribution/igtf/1.5/
You can download the new packages and install them at your convenience.
PLEASE NOTE:
If you part of a coordinated-deployment project (such as OSG, EGEE, LCG,
DEISA, NAREGI or others) you may want to await your project announcement
before installing this release.
Modified accredited CAs:
Russia RDIG New CRL download location
GermanGrid CA Extended root certificate lifetime
(would have expired June 10, 2007)
Grid-Ireland Extended root certificate lifetime
(would have expired July 27, 2007)
ASGCC CA no longer authoritative for /C=CN/O=IHEP
AIST CA modified extensions in root certificate
SWITCH list of organisations (namespace) updated
A detailed summary of changes can also be found in the distribution.
Next Release
------------
The next release of the CA RPMs is to be expected in July 2006, (of course
barring special circumstances).
=========================================================================
STANDARD CLAUSES AND REPEATED NOTICES: Distribution information
=========================================================================
Notice on directory structure
-----------------------------
*** ONLY CAs IN THE "accredited/" DIRECTORY and THE CAs INSTALLED
USING THE ca_policy_igtf-classic-1.5-1.noarch.rpm ARE ACCREDITED
Do *not* install certificates from the "worthless/" or "experimental/",
directories, except if you yourself review and accept their policy and
practice statement. The EUGridPMA provides these certificates in
this format for your convenience only, and to allow graceful changeover
for legacy installations.
*** The Fermilab Kerberized CA, although not an accredited CA according
to the "classic" profile, has been available from the EUGridPMA
repository before in the "others/" directory. Due to the reorganization,
this authority has moved to the "experimental/" area. When the KCA has
been accepted by the TAGPMA, the location of this authority will change.
*** All individual CAs packages, as well as the bundles, have the same
(common) version number "1.5" and release "1".
Distribution formats
--------------------
* the distribution traditionally contained a set of RPMs and tar-balls
per accredited authorities, as well as meta-RPMs that depends on the RPMs
of those accredited.
* the "tar-bundle" that can be used to install the authorities in a
local trust directory using the "./configure && make install"
mechanism has been renamed to avoid confusion. It is called:
igtf-policy-installation-bundle-1.5.tar.gz
It has the same functionality and can still be found in the
"accredited/" subdirectory.
* the accredited directory now contains two additional tar-balls that
contain, respectively, *all* "classic" and "slcs" accredited CAs:
igtf-preinstalled-bundle-classic-1.5.tar.gz
igtf-preinstalled-bundle-slcs-1.5.tar.gz
(note there are no SLCS-accredited authorities at this time)
* those CAs whose key-length is less than 4095 bits are also
available in a Java KeyStore (JKS), whose password is "eugridpma".
These is both a JKS for each individual CA, as well as a
"igtf-policy-accredited-classic-1.5.jks" in the "accredited/jks/"
sub-directory.
APT and Yum
-----------
As always, the repository is suitable for "yum" based automatic updates,
by adding to the yum.conf file:
[eugridpma]
name=EUGridPMA
baseurl=http://www.eugridpma.org/distribution/igtf/current/
gpgcheck=1
Also "apt" is supported. For details, see
http://www.eugridpma.org/distribution/igtf/current/apt/README.txt
Large deployment projects are kindly requested to mirror these directories
in their own distribution repositories.
RPM GPG signing
---------------
Also this new RPM distribution is distributed with GPG-signed RPMs. The
key (ID 3CDBBC71) has been uploaded to the public key servers, along with
my signature as the EUGridPMA Chair (keyID 6F298418). The key is also
contained in the repository. You will need this key if you enable GPG
checking for automatic updates in "yum" or "apt".
Please remember to validate this distribution against the TACAR
trusted repository (https://www.tacar.org/) where possible.
Suggestions
-----------
If you have suggestions or improvements for the distribution format,
to have it better suit your needs, please contact the PMA at
<info(a)eugridpma.org>. Note that there is be a common distribution format
across the entire IGTF (i.e. all three PMAs).
--
David Groep
** National Institute for Nuclear and High Energy Physics, PDP/Grid group **
** Room: H1.56 Phone: +31 20 5922179, PObox 41882, NL-1009DB Amsterdam NL **
From: David Groep <info(a)eugridpma.org>
Date: Tue, 20 May 2006 12:00:00 +0200
Subject: New version of "fetch-crl" available and selected CRL issues
Dear CAs, Relying Parties, Users, and all others interested,
In this announcement of the EUGridPMA:
1. Clock skew problem with HellasGrid and SEE-GRID CAs resolved
2. Fetch-CRL utility updated to deal with CRLs issued in the future
We hope that you find this update useful and welcome any comments you
may have. Also, feel free to redistribute this information widely as
you see appropriate.
Regards,
David Groep
For more information about this newsletter and the mailing list,
please refer to the EUGridPMA web site at https://www.eugridpma.org/
=========================================================================
1. Clock skew problem with HellasGrid and SEE-GRID CAs resolved
=========================================================================
The following information is provided courtesy of the HellasGrid
and SEE-GRID-Catch-all Authorities:
A problem came into our attention regarding all the CRLs issued by
both HellasGrid and SEE-GRID CA starting from 5/5/2006.
For an unknown reason there was a clock skew of the computer running
the CA off-line services which resulted in setting the clock 23 days
forward in the future. [...] The result was that CRLs were issued and
published with the last update field having the date 28 May.
We have generated a new CRL with the current date that will fix the
problem [..], but a new [...] problem has been introduced. The
[previous version of] edg-fetch-crl, used by many Grid sites, performs
a check on the value of the last update field and refuses to download a
CRL that has a date older than the currently installed CRL (logging an
error via syslog).
This problem has been resolved as of May 19th, 11:26 hrs GMT.
In order for this new CRL to be correctly processed by the fetch-crl
utility, which is provided as a service by (amongst others) the EUGridPMA,
relying parties that use this version of fetch-crl should upgrade to the
latest version. Unless you upgrade to the new version of fetch-crl, the new,
correct, CRLs for the HellasGrid and SEE-GRID CAs will NOT be retrieved.
Please see section 2 of this announcement for details.
[thanks to Christos Kanellopoulos for the analysis of this issue]
=========================================================================
2. Fetch-CRL utility updated to deal with CRLs issued in the future
=========================================================================
As a courtesy service to the community, the EUGridPMA provides the
"fetch-crl" utility - originally developed by Fabio Hernandez, CC-IN2P3 -
to periodically retrieve CRLs from the web sites of the certification
authorities.
This utility is extremely careful in not replacing CRLs that already
exist locally by ones that are downloaded from the web. Versions up to and
including EGP-2.5.1 are slightly too careful, and will also refuse to
install a newly downloaded correct CRL if the currently installed one
has a issuance date in the future. Thus, versions <= EGP-2.5.1 cannot be
used to retrieve the corrected CRLs issued by the HellasGrid and SEE-GRID
CAs on May 19th.
A new version of fetch-crl (EGP-2.6.0) that corrects this issue, as well as
adding a non-suppressable warning about newly-downloaded but not-yet-valid
CRLs, is now available from the EUGridPMA web site at:
http://www.eugridpma.org/distribution/util/fetch-crl/
in RedHat Package Management (RPM) and gzipped-tarball format.
Changes in version EGP 2.6
--------------------------
(2006.05.20)
* if the current local CRL has a lastUpdate time in the future, and the
newly downloaded CRL is older that the current one, allow the
installation of the newly downloaded CRL and issue a warning.
* added non-suppressable warning in case the newly downloaded CRL has a
lastUpdate time in the future, but install that CRL anyway (as the local
clock might have been wrong).
Installation that use YUM package management can add
http://www.eugridpma.org/distribution/util/
to their yum.conf file and upgrade in that way.
=========================================================================
Additional Information
=========================================================================
Notice:
The next release of the IGTF Accredited Authority distribution is
expected in early June, 2006.
From: David Groep <info(a)eugridpma.org>
Date: Tue, 15 May 2006 10:00:00 +0200
Subject: IGTF (EUGridPMA) CA distribution 1.4 and updates
Dear CAs, Relying Parties, Users, and all others interested,
In this announcement of the EUGridPMA:
1. New distribution 1.4 available
with updated NorduGrid root certificate
We hope that you find this update useful and welcome any comments you
may have. Also, feel free to redistribute this information widely as
you see appropriate.
Regards,
David Groep
For more information about this newsletter and the mailing list,
please refer to the EUGridPMA web site at https://www.eugridpma.org/
=========================================================================
1. New distribution (1.4) with new NordoGrid root certificate
=========================================================================
** Important Notice:
This release 1.4 is the first release after version 1.2. There is
and will not be a version 1.3 of the IGTF Release. Please see the
detailed CHANGES file in the distribution for details.
A new distribution of Accredited Authorities by the EUGridPMA, based
on the IGTF Common Source, is now available. It includes the newly
accredited Authorities by all IGTF Members. This is version 1.4,
release 1, and it is now available for download from the Repository at
https://www.eugridpma.org/distribution/igtf/1.4/
or
https://www.eugridpma.org/distribution/igtf/current/
You can download the new packages and install them at your convenience.
If you part of a coordinated-deployment project (such as OSG, EGEE, LCG,
DEISA, NAREGI or others) you may want to await your project announcement
before installing this release.
Modified accredited CAs:
NorduGrid Updated root trust anchor with extended lifetime.
A detailed summary of changes can be found in the distribution.
Notice on directory structure
-----------------------------
*** *ONLY* CAs IN THE "accredited/" DIRECTORY and THE CAs INSTALLED
USING THE ca_policy_igtf-classic-1.4-1.noarch.rpm ARE ACCREDITED
Do *not* install certificates from the "worthless/" or "experimental/",
directories, except if you yourself review and accept their policy and
practice statement. The EUGridPMA provides these certificates in
this format for your convenience only, and to allow graceful changeover
for legacy installations.
*** The Fermilab Kerberized CA, although not an accredited CA according
to the "classic" profile, has been available from the EUGridPMA
repository before in the "others/" directory. Due to the reorganization,
this authority has moved to the "experimental/" area. When the KCA has
been accepted by the TAGPMA, the location of this authority will change.
*** All individual CAs packages, as well as the bundles, have the same
(common) version number "1.4" and release "1".
=========================================================================
Distribution information
=========================================================================
We warmly welcome your comments and suggestions to improve deployability
of the CA distribution.
* the distribution traditionally contained a set of RPMs and tar-balls
per accredited authorities, as well as meta-RPMs that depends on the RPMs
of those accredited.
* the "tar-bundle" that can be used to install the authorities in a
local trust directory using the "./configure && make install"
mechanism has been renamed to avoid confusion. It is called:
igtf-policy-installation-bundle-1.2.tar.gz
It has the same functionality and can still be found in the
"accredited/" subdirectory.
* the accredited directory now contains two additional tar-balls that
contain, respectively, *all* "classic" and "slcs" accredited CAs:
igtf-preinstalled-bundle-classic-1.4.tar.gz
igtf-preinstalled-bundle-slcs-1.4.tar.gz
(note there are no SLCS-accredited authorities at this time)
* those CAs whose key-length is less than 4095 bits are also
available in a Java KeyStore (JKS), whose password is "eugridpma".
These is both a JKS for each individual CA, as well as a
"igtf-policy-accredited-classic-1.4.jks" in the "accredited/jks/"
sub-directory.
APT and Yum
-----------
As always, the repository is suitable for "yum" based automatic updates,
by adding to the yum.conf file:
[eugridpma]
name=EUGridPMA
baseurl=http://www.eugridpma.org/distribution/igtf/current/
gpgcheck=1
and also "apt" is supported. For details, see
http://www.eugridpma.org/distribution/igtf/current/apt/README.txt
Large deployment projects are kindly requested to mirror these directories
in their own distribution repositories.
RPM GPG signing
---------------
Also this new RPM distribution is distributed with GPG-signed RPMs. The
key (ID 3CDBBC71) has been uploaded to the public key servers, along with
my signature as the EUGridPMA Chair (keyID 6F298418). The key is also
contained in the repository. You will need this key if you enable GPG
checking for automatic updates in "yum" or "apt".
Please remember to validate this distribution against the TACAR
trusted repository (https://www.tacar.org/) where possible.
=========================================================================
Next Release
=========================================================================
The next release of the CA RPMs is to be expected in May 2006, (of course
barring special circumstances).
If you have suggestions or improvements for the distribution format,
to have it better suit your needs, please contact the PMA at
<info(a)eugridpma.org>. There will be a common distribution format across
the entire IGTF (i.e. all three PMAs).
--
David Groep
** National Institute for Nuclear and High Energy Physics, PDP/Grid group **
** Room: H1.56 Phone: +31 20 5922179, PObox 41882, NL-1009DB Amsterdam NL **
Dear CAs, Relying Parties, Users, and all others interested,
In this announcement of the EUGridPMA:
1. New distribution IGTF 1.2 available
We hope that you find this update useful and welcome any comments you
may have. Also, feel free to redistribute this information widely as
you see appropriate.
Regards,
David Groep
For more information about this newsletter and the mailing list,
please refer to the EUGridPMA web site at https://www.eugridpma.org/
=========================================================================
1. New distribution IGTF 1.2 available
=========================================================================
A new distribution of Accredited Authorities by the EUGridPMA, based
on the IGTF Common Source, is now available. It includes the newly
accredited Authorities by all IGTF Members. This is version 1.2,
release 1, and it is now available for download from the Repository at
https://www.eugridpma.org/distribution/igtf/1.2/
or
https://www.eugridpma.org/distribution/igtf/current/
You can download the new packages and install them at your convenience.
If you part of a coordinated-deployment project (such as OSG, EGEE, LCG,
DEISA, NAREGI or others) you may want to await your project announcement
before installing this release.
Modified accredited CAs:
KISTI CA new email contact address
pkIRISGrid re-quoted the signing_policy file for consistency
SWITCH new organisation added to namespace
ArmeSFO new CRL location on a dedicated sever based in Karlsruhe
Suspended:
SWITCH-CA2 the new SwissSign hierarchy that is based off the
self-signed Silver root has been suspended, pending
acceptance of the root by the WebTrust auditors.
(for procedural reasons, CRLs cannot be made available
by SwissSign prior to acceptance by KPMG)
This will remove: ca_SwissSign-Silver-Root,
ca_SWITCH-Personal2, ca_SWITCH-CA2, ca_SWITCH-Server2
A detailed summary of changes can be found in the distribution.
Notice on directory structure
-----------------------------
*** *ONLY* CAs IN THE "accredited/" DIRECTORY and THE CAs INSTALLED
USING THE ca_policy_igtf-classic-1.2-1.noarch.rpm ARE ACCREDITED
Do *not* install certificates from the "worthless/" or "experimental/",
directories, except if you yourself review and accept their policy and
practice statement. The EUGridPMA provides these certificates in
this format for your convenience only, and to allow graceful changeover
for legacy installations.
*** The Fermilab Kerberized CA, although not an accredited CA according
to the "classic" profile, has been available from the EUGridPMA
repository before in the "others/" directory. Due to the reorganization,
this authority has moved to the "experimental/" area. When the KCA has
been accepted by the TAGPMA, the location of this authority will change.
*** All individual CAs packages, as well as the bundles, have the same
(common) version number "1.1" and release "1".
=========================================================================
Distribution information
=========================================================================
We warmly welcome your comments and suggestions to improve deployability
of the CA distribution.
* the distribution traditionally contained a set of RPMs and tar-balls
per accredited authorities, as well as meta-RPMs that depends on the RPMs
of those accredited.
* the "tar-bundle" that can be used to install the authorities in a
local trust directory using the "./configure && make install"
mechanism has been renamed to avoid confusion. It is called:
igtf-policy-installation-bundle-1.2.tar.gz
It has the same functionality and can still be found in the
"accredited/" subdirectory.
* the accredited directory now contains two additional tar-balls that
contain, respectively, *all* "classic" and "slcs" accredited CAs:
igtf-preinstalled-bundle-classic-1.2.tar.gz
igtf-preinstalled-bundle-slcs-1.2.tar.gz
(note there are no SLCS-accredited authorities at this time)
* those CAs whose key-length is less than 4095 bits are also
available in a Java KeyStore (JKS), whose password is "eugridpma".
These is both a JKS for each individual CA, as well as a
"igtf-policy-accredited-classic-1.2.jks" in the "accredited/jks/"
sub-directory.
APT and Yum
-----------
As always, the repository is suitable for "yum" based automatic updates,
by adding to the yum.conf file:
[eugridpma]
name=EUGridPMA
baseurl=http://www.eugridpma.org/distribution/igtf/current/
gpgcheck=1
and also "apt" is supported. For details, see
http://www.eugridpma.org/distribution/igtf/current/apt/README.txt
Large deployment projects are kindly requested to mirror these directories
in their own distribution repositories.
RPM GPG signing
---------------
Also this new RPM distribution is distributed with GPG-signed RPMs. The
key (ID 3CDBBC71) has been uploaded to the public key servers, along with
my signature as the EUGridPMA Chair (keyID 6F298418). The key is also
contained in the repository. You will need this key if you enable GPG
checking for automatic updates in "yum" or "apt".
Please remember to validate this distribution against the TACAR
trusted repository (https://www.tacar.org/) where possible.
=========================================================================
Next Release
=========================================================================
The next release of the CA RPMs is to be expected in May 2006, (of course
barring special circumstances).
If you have suggestions or improvements for the distribution format,
to have it better suit your needs, please contact the PMA at
<info(a)eugridpma.org>. There will be a common distribution format across
the entire IGTF (i.e. all three PMAs).
--
David Groep
** National Institute for Nuclear and High Energy Physics, PDP/Grid group **
** Room: H1.56 Phone: +31 20 5922179, PObox 41882, NL-1009DB Amsterdam NL **
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Dear CAs, Relying Parties, Users, and all others interested,
After the release of distribution 1.1, I have received a number of valuable
suggestions to improve the distribution format, in particular for the
tar-based installation bundle. Also, the meta-RPM contained a typo that
prevented the (discontinued) ca_CNRS-DataGrid to be obsoleted correctly.
Therefore, a new release (R2) of this version 1.1 has been made
available, containing these changes:
~ Changes from 1.1 R1 to 1.1 R2
~ -----------------------------
~ (22 Feb 2006)
~ NOTE: THERE ARE NO CHANGES TO THE CONTENT IN THIS SUB-RELEASE
~ * Corrected typo in the obsoletion of the old ca_CNRS-DataGrid
~ * Improved understandability of the igtf-policy-installation-bundle
The igtf-policy-installation-bundle-1.1.tar.gz now contains a README.txt
file with more detailed instructions and a clearer internal structure.
Comments are of course always welcome.
Regards,
David Groep.
=========================================================================
Next Release
=========================================================================
The next release of the CA RPMs is to be expected around mid-March 2006,
(of course barring special circumstances).
If you have suggestions or improvements for the distribution format,
to have it better suit your needs, please contact the PMA at
<info(a)eugridpma.org>. There will be a common distribution format across
the entire IGTF (i.e. all three PMAs).
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3-nr1 (Windows XP)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFD/DbLcnpzXG8phBgRAoK/AJ9GpTAFoE7f3CJXYaZ+Uy/qy1ofHQCeJrJJ
SUMUn3QIQC/Hgm76IQYTBUc=
=PA5G
-----END PGP SIGNATURE-----
From: David Groep <info(a)eugridpma.org>
Date: Mon, 20 Feb 2005 15:00:00 +0100
Subject: EUGridPMA (IGTF) CA distribution 1.1 and updates
Dear CAs, Relying Parties, Users, and all others interested,
In this announcement of the EUGridPMA:
1. Release frequency increase
2. New distribution 1.1 available with new authorities
3. Distribution changes and improved deployability
4. Namespace constraints policies
5. Informational services experiments from the EUGridPMA
We hope that you find this update useful and welcome any comments you
may have. Also, feel free to redistribute this information widely as
you see appropriate.
Regards,
David Groep
For more information about this newsletter and the mailing list,
please refer to the EUGridPMA web site at https://www.eugridpma.org/
=========================================================================
1. Release frequency increase
=========================================================================
On the request of the relying parties expressed in the IGTF and CA-OPS
meetings during GGF16 in Athens, Greece, there will be more frequent
releases of the IGTF distribution. In this way, changes such as
CRL location changes, and newly accredited CAs, will be available to
relying parties faster.
In the new scheme, the maximum delay for a new distribution will be
two (2) weeks after all technical information has been made available.
The time to deployment of any such regular update release is left to
the descretion of the relying parties.
Specific security updates will be released more frequently as necessary,
and should preferably be implemented as soon as possible. Such security
updates will be clearly marked as such.
=========================================================================
2. New distribution (1.1) with new authorities
=========================================================================
A new distribution of Accredited Authorities by the EUGridPMA, based
on the IGTF Common Source, is now available. It includes the newly
accredited Authorities by all IGTF Members. This is version 1.1,
release 1, and it is now available for download from the Repository at
https://www.eugridpma.org/distribution/igtf/1.1/
or
https://www.eugridpma.org/distribution/igtf/current/
You can download the new packages and install them at your convenience.
If you part of a coordinated-deployment project (such as OSG, EGEE, LCG,
DEISA, NAREGI or others) you may want to await your project announcement
before installing this release.
New Authorities:
APAC Australian Partnership for Advanced Computing
KEK High Energy Accelerator Research Organization (Japan)
NAREGI National Research Grid Initiative (Japan)
pkIRISGrid IRISGrid PKI (RedIRIS, Spain)
Modified:
GridCanada added new root certificate
SWITCH new Personal and Server CA certificates
SWITCH-CA2 new CA hierarchy based off the SwissSign Silver Root
Discontinued:
Datagrid-FR no longer contains valid end-entity certs
CyGrid-old expired and replaces by "CyGrid"
This release also contains various updates and corrections to the CRL
download locations and the CA contact information.
A detailed summary of changes can be found in the distribution.
Notice on directory structure
-----------------------------
*** *ONLY* CAs IN THE "accredited/" DIRECTORY and THE CAs INSTALLED
USING THE ca_policy_igtf-classic-1.0-1.noarch.rpm ARE ACCREDITED
Do *not* install certificates from the "worthless/" or "experimental/",
directories, except if you yourself review and accept their policy and
practice statement. The EUGridPMA provides these certificates in
this format for your convenience only, and to allow graceful changeover
for legacy installations.
*** The Fermilab Kerberized CA, although not an accredited CA according
to the "classic" profile, has been available from the EUGridPMA
repository before in the "others/" directory. Due to the reorganization,
this authority has moved to the "experimental/" area. When the KCA has
been accepted by the TAGPMA, the location of this authority will change.
*** All individual CAs packages, as well as the bundles, have the same
(common) version number "1.1" and release "1".
=========================================================================
3. Distribution changes and improved deployability
=========================================================================
We warmly welcome your comments and suggestions to improve deployability
of the CA distribution. Based on some suggestions received, some changes
have been implemented in this release.
The distribution traditionally contained a set of RPMs and tar-balls
per accredited authorities, as well as meta-RPMs that depends on the RPMs
of those accredited.
In this release, we add several new components.
* the "tar-bundle" that can be used to install the authorities in a
local trust directory using the "./configure && make install"
mechanism has been renamed to avoid confusion. It is called:
igtf-policy-installation-bundle-1.1.tar.gz
It has the same functionality and can still be found in the
"accredited/" subdirectory.
* the accredited directory now contains two additional tar-balls that
contain, respectively, *all* "classic" and "slcs" accredited CAs:
igtf-preinstalled-bundle-classic-1.1.tar.gz
igtf-preinstalled-bundle-slcs-1.1.tar.gz
(note there are no SLCS-accredited authorities at this time)
* those CAs whose key-length is less than 4095 bits are also
available in a Java KeyStore (JKS), whose password is "eugridpma".
These is both a JKS for each individual CA, as well as a
"igtf-policy-accredited-classic-1.1.jks" in the "accredited/jks/"
sub-directory.
APT and Yum
-----------
As always, the repository is suitable for "yum" based automatic updates,
by adding to the yum.conf file:
[eugridpma]
name=EUGridPMA
baseurl=http://www.eugridpma.org/distribution/igtf/current/
gpgcheck=1
and also "apt" is supported. For details, see
http://www.eugridpma.org/distribution/igtf/current/apt/README.txt
Large deployment projects are kindly requested to mirror these directories
in their own distribution repositories.
RPM GPG signing
---------------
Also this new RPM distribution is distributed with GPG-signed RPMs. The
key (ID 3CDBBC71) has been uploaded to the public key servers, along with
my signature as the EUGridPMA Chair (keyID 6F298418). The key is also
contained in the repository. You will need this key if you enable GPG
checking for automatic updates in "yum" or "apt".
Please remember to validate this distribution against the TACAR
trusted repository (https://www.tacar.org/) where possible.
=========================================================================
4. Namespace constraints policies
=========================================================================
The assertions by the IGTF on the compliance of the authorities
only extend within the namespaces as accredited by the PMAs. This
ensures that any certificate subject name corresponds to one and
only one entity, and allows you to rely on this subject name
for subsequent decisions. This uniqueness applies only
*within the namespace constraints* set by the PMAs.
For this reason, the distribution has, since its conception, contained
a set of "signing_policy" files that specify exactly what subject
names of each CA are subject to the IGTF assertions.
On request of several middleware development projects, this very same
set of namespace constraints is now also specified in a new format in
a separate ".namespaces" file.
There is no difference in content between these two files, but the
format and interpreting semantics are different.
For information regarding the new ".namespaces" file, please see
http://www.eugridpma.org/documentation/
In the future, this format may yet again be extended or replaced by
another format, as discussions within the Global Grid Forum continue.
Your participation, via the CA-OPS Working Group, is of course welcome.
=========================================================================
5. Informational Services from the EUGridPMA
=========================================================================
To better service the community, contact information of the members
is made available from the EUGridPMA web site. Look under "membership"
and find the web site and a link to the Policy and Practice Statements.
Experimentally, the following services are also available:
* a "subject locator" - given a DN, find out which Authority manages
that namespace:
http://www.eugridpma.org/showca.php
* Status News - short notices by the PMA that do not warrant issuing
a newsletter because of their transient nature.
http://www.eugridpma.org/statusnews/
In the near future, this system will be enhanced with a more detailed
monitoring page that contains notices posted by the member authorities,
such as scheduled web site maintenance. This service will be kindly
provided by SiGNET.
=========================================================================
Next Release
=========================================================================
The next release of the CA RPMs is to be expected around mid-March 2006,
(of course barring special circumstances).
If you have suggestions or improvements for the distribution format,
to have it better suit your needs, please contact the PMA at
<info(a)eugridpma.org>. There will be a common distribution format across
the entire IGTF (i.e. all three PMAs).
Dear CAs, Relying Parties, Users, and all others interested,
In this announcement of the EUGridPMA:
1. International Grid Trust Federation to introduce new authorities
2. New distribution (1.0) with new layout and authorities
Summary of changes
Notice on directory structure
RPM distribution and meta-packages
Info meta-data for authorities
Obsoleting of the EUGridPMA meta-package by the IGTF policy
RPM GPG signing
We hope that you find this update useful and welcome any comments you
may have. Also, feel free to redistribute this information widely as
you see appropriate.
Regards,
David Groep
For more information about this newsletter and the mailing list,
please refer to the EUGridPMA web site at https://www.eugridpma.org/https://www.eugridpma.org/newsletter/eugridpma-newsletter-20051025.txt
=========================================================================
1. International Grid Trust Federation to introduce new authorities
=========================================================================
With the foundation of the International Grid Trust Federation (IGTF)
on October 5th, the authentication profile (minimum requirements)
guidelines on X.509 CAs with secured infrastructure has been accepted
as the basis for accrediting "classic" authorities by all three PMAs:
not only the EUGridPMA, but also the APGridPMA (for the Asia Pacific
region) and the TAGPMA (covering the Americas).
In the AP region, four authorities have been accredited according
to this profile, following an in-depth review and an on-site audit.
This includes the two authorities (IHEP in Beijing and ASGCC in Taipei)
that were already previously accredited by the EUGridPMA.
The APGridPMA also brings in two new CAs: KISTI (South Korea) and
AIST (Japan).
The EUGridPMA will from now on distribute the entire corpus of
IGTF accredited CAs, regardless of their accrediting PMA (as announced
in the October 6th newsletter. Today, this includes the "classic"
profile only, but in the near future also the new profile covering
short-lived credential services ("slcs"). If you have previously
accepted the assurance level for classic CAs from the EUGridPMA, we
suggest you place equal trust in the IGTF "classic" profile. You
should make a new trust assessment with respect to the SLCS profile,
once this profile has been accepted by its maintaining body, the TAGPMA.
This advice is reflected in the upgrade path for the EUGridPMA
distribution format, as explained below.
For more information regarding the IGTF, please refer to the
IGTF or EUGridPMA web site at:
http://www.gridpma.org/
=========================================================================
2. New distribution (1.0) with new layout and formats
=========================================================================
A new distribution of Accredited Authorities by the EUGridPMA, based
on the IGTF Common Source, is now available. As several major changes
have been introduced in this release, and because of the use of a
common distribution format throughout the IGTF, the version number
has been bumped to 1.0. Future releases will sequentially increment
this number (1.1, 1.2 ... 1.9, 1.10, 1.11, ... 1.1201, etc.)
This is version 1.0, release 1, and it is now available for download
from the EUGridPMA repository at
https://www.eugridpma.org/distribution/igtf/1.0/
or
https://www.eugridpma.org/distribution/igtf/current/
You can download the new packages and install them at your convenience.
Summary of changes
------------------
Changes from 0.32 to 1.0
-------------------------
(25 October 2005)
* IGTF policy meta-packages replace EUGridPMA-only ones. The legacy
"ca_policy_eugridpma" RPMs now depend on their IGTF counterparts. The
EUGridPMA specific files will be withdrawn in a future release.
* New directory structure moves all data regarding accredited authorities
to the singe "accredited/" directory (including the policy meta-RPM)
* Tar-ball installation now supports multiple profiles and targets
* Meta-data (".info") for each CA added, and installed in trusted directory
* The "experimental" profile supersedes the "others/"areainthe distribution
(note: this affects the FNAL_KCA, which may shortly be added as an
accredited authority under a new Short-Lived Credential Services profile)
* Discontinued authorities are no longer distributed
* APGridPMA accreditations added: KISTI and AIST
* New EUGridPMA accreditations: TR-Grid and BalticGrid
* CRL URL for SiGNET changed to http instead of https
* Added compatibility namespace forNIIF "/C=HU/O=NIIF CA/OU=NIIF/OU=GRID/*"
Notice on directory structure
-----------------------------
*** *ONLY* CAs IN THE "accredited/" DIRECTORY and THE CAs INSTALLED
USING THE ca_policy_igtf-classic-1.0-1.noarch.rpm ARE ACCREDITED
Do *not* install certificates from the "worthless/" or "experimental/",
directories, except if you your self review and accept their policy and
practice statement. The EUGridPMA provides these certificates in
this format for your convenience only, and to allow graceful changeover
for legacy installations.
*** The Fermilab Kerberized CA, although not an accredited CA according
to the "classic" profile, has been available from the EUGridPMA
repository before in the "others/" directory. Due to the reorganization,
this authority has moved to the "experimental/" area. When an
authentication profile (SLCS) suitable for the KCA has been
accepted by the TAGPMA, the location of this authority will be
reconsidered.
*** All individual CAs packages, as well as the bundles, have the same
(common) version number "1.0" and release "1".
RPM distribution and meta-packages
----------------------------------
For those using RPM based Linux distribution, a "meta-RPM" is available
from the repository, ca_policy_igtf-classic-1.0-1.noarch.rpm, that contains
dependencies on the RPMs of all accredited CAs. The repository is
suitable for "yum" based automatic updates, by adding to the yum.conf file:
[eugridpma]
name=EUGridPMA
baseurl=http://www.eugridpma.org/distribution/igtf/current/
gpgcheck=1
Also "apt" is supported. See
http://www.eugridpma.org/distribution/igtf/current/apt/README.txt
for details.
Info meta-data for authorities
------------------------------
The RPM packages (and the files installed via the accredited tar bundle)
now also include a ".info" file for each installed root certificate.
This info file contains important meta-data regarding the CA, in a plain-
text "attribute=value" format. At a minimum, this file will contain:
alias preferred short name of the CA
status accreditation profile name (or "worthless/experimental")
email contact address of the CA for incidents
sha1fp SHA1 fingerprint of the certificate
version version number of the package that contains this CA
The file may contains comments (i.e. lines starting with "#"). For an
example, unpack the igtf-accredited bundle from the accredited/ directory:
igtf-policy-accredited-bundle-1.0.tar.gz
and look at, e.g., "igtf-policy-accredited-bundle-1.0/16da7552.info"
Obsoleting of the EUGridPMA meta-package by the IGTF policy
-----------------------------------------------------------
In previous releases, a similar meta-package for bulk installations,
called "ca_policy_eugridpma-classic-<ver>-<rel>" has been provided.
Following our recommendation to extend your trust to all IGTF accredited
"classic" authorities, you are requested now to install
"ca_policy_igtf-classic-1.0-1" and un-install the obsolete eugridpma-only
meta-package. There will no longer be a meta-package with only EUGridPMA
accredited CAs.
For compatibility purposes, the ca_policy_eugridpma-classic package is
still provided with release 1.0, but has a single dependency on the
entire ca_policy_igtf-classic bundle. If you do automatic updating
using this meta-package, you will *automatically* add all IGTF accredited
"classic" authorities to your list of trusted authorities.
For release 1.0, this means that KISTI and AIST will be added. We are
sure this matches the expectations of our relying parties, and
it implements the EUGridPMA and IGTF recommendations on compatible
assurance levels between the PMAs. For policy-related issues, please
refer to the IGTF Federation Document for details.
Similar considerations hold for the tar-based installation using the
"configure && make && make install" mechanism. This accredited bundle
(which supports all authentication profiles using the "--with-profile="
mechanism) also contains all IGTF accredited CAs.
RPM GPG signing
---------------
Also this new RPM distribution is distributed with GPG-signed RPMs. The
key (ID 3CDBBC71) has been uploaded to the public key servers, along with
my signature as the EUGridPMA Chair (keyID 6F298418). The key is also
contained in the repository. You will need this key if you enable GPG
checking for automatic updates in "yum" or "apt".
Please remember to validate this distribution against the TACAR
trusted repository (https://www.tacar.org/) where-ever possible.
=========================================================================
Next Release
=========================================================================
The next release of the CA RPMs is to be expected around November 2005,
(of course barring special circumstances).
If you have suggestions or improvements for the distribution format,
to have it better suit your needs, please contact the PMA at
<info(a)eugridpma.org>. There will be a common distribution format across
the entire IGTF (i.e. all three PMAs).
--
David Groep
** National Institute for Nuclear and High Energy Physics, PDP/Grid group **
** Room: H1.56 Phone: +31 20 5922179, PObox 41882, NL-1009DB Amsterdam NL **
Dear CAs, Relying Parties, Users, and all others interested,
Today, at the 15th Global Grid Forum in Boston, the International Grid
Trust Federation was officially established. With this, the process
started almost five years ago has reached a new milestone:
http://www.gridpma.org/docs/igtf-newsrelease-20051005.pdf
The IGTF is a federation of certification authorities or grid policy
management authorities (grid PMAs), and the major grid infrastructure
projects that together define the policies and standards for grid
identity management. Comprising the three regional grid policy management
bodies, the EUGridPMA, the Asia Pacific Grid PMA (APGridPMA), and The
Americas GridPMA (TAGPMA), the federation today has 61 members and
covers 50 countries and regions.
The new federation builds on the foundations laid by the EUGridPMA. The
same minimum requirements on classic CAs that have been the basis of the
EUGridPMA have been adopted by all IGTF members, so that relying parties
can have the same level of trust in the CAs that are accredited by the
APGridPMA and the TAGPMA.
The new distribution of trust anchors will reflect this equivalence, by
distributing new common metapackages "ca_policy_igtf" that replaces the
current EUGridPMA-only bundles. The IGTF meta-packages will contain
all CAs accredited under a given profile, regardless of their regional
affiliation.
The APGridPMA and TAGPMA, at the same time enriched the federation with
new profiles that enable more high-quality identity providers to issue
certificates. They will be issuing credentials to users in their own
organisation, leveraging strong local methods of authentication, like
Kerberos.
These "short-lived credential generation services" usually issue (proxy)
certificates valid for hours or a few days, thus eliminating the need for
long-term key management by the end-user. It is expected that by November
this year the PMAs will be able to distribute a bundle of CAs accredited
under this new "SLCGS" Authentication Profile.
For the activities of the IGTF, pointers to all authentication profiles,
and the IGTF Charter, please go to the web site at:
http://www.gridpma.org/
or look at any of the regional PMA pages for the IGTF information.
A new distribution (0.33) is due by the end of October 2005.
We hope that you find this update useful and welcome any comments you
may have. Also, feel free to redistribute this information widely as
you see appropriate.
Regards,
David Groep
For more information about this newsletter and the mailing list,
please refer to the EUGridPMA web site at https://www.eugridpma.org/
Dear CAs, Relying Parties, Users, and all others interested,
In this announcement of the EUGridPMA:
1. New distribution (0.32) with repairs and updated root cert
We hope that you find this update useful and welcome any comments you
may have. Also, feel free to redistribute this information widely as
you see appropriate.
Regards,
David Groep
For more information about this newsletter and the mailing list,
please refer to the EUGridPMA web site at https://www.eugridpma.org/
=========================================================================
1. New distribution version 0.32
=========================================================================
A new distribution of Accredited Authorities by the EUGridPMA, release
version 0.32, is now available for download from the EUGridPMA Repository
https://www.eugridpma.org/distribution/current/
Note that this updates the previous release that was issued three days
ago. There are two reasons for this update:
* The Russian Data Intensive Grid (RDIG) CA has released a new
root certificate with a keylength of 2048 bits. The
previous key (4096 bits in length) caused problems in various
software suites, in particular some Java implementations.
NOTE that the has remains unchanged, and the previous web locations
will be re-used. In the transition period, you may encounter
inconsistencies between the new CA cert and the (still old) CRL
downloaded from the crl_url. This inconsistency has no other
security impacts than to render the CA inactive, i.e., this is a
safe default.
* The signing policy file for the new CESNET CA was incomplete and
left out the namespace that was actually in use. The correct
namespace is /DC=cz/DC=cesnet-ca/*.
Notice:
*ONLY* CAs IN THE "accredited/" DIRECTORY and
THE CAs INSTALLED USING THE ca_policy_eugridpma-0.32-1.noarch.rpm
ARE ACCREDITED
Do *not* install certificates from the "worthless/", "other/",
or "discontinued/" directories, except if you your self review
and accept their policy and practice statement. The EUGridPMA
provides these certificates in this format for your convenience
only, and to allow graceful changeover for legacy installations.
You can download the new packages and install them at your convenience.
Changes from 0.31 to 0.32
-------------------------
(23 August 2005)
* Corrected namespace for the new CESNET CA
* New RDIG root certificate with a 2048 bit key length for increased
compatibility with existing software suites.
For those using RPM based linux distribution, a "meta-RPM" is available
from the repository, ca_policy_eugridpma-0.32-1.noarch.rpm, that contains
dependencies on the RPMs of all accredited CAs. The repository is
suitable for "yum" based automatic updates.
This is the first RPM distribution that will (on an experimental basis)
used GPG-signed RPMs. The key (ID 3CDBBC71) has been uploaded to
the public key servers, along with my signature as the EUGridPMA
Chair (keyID 6F298418). The key is also contained in the repository.
The next release of the CA RPMs is to be expected around October 2005,
(of course barring special circumstances). The format of those new releases
is currently under considation. If you want to contribute to the
discussion or to suggest improvements to have it better suit your needs,
please contact the PMA at <info(a)eugridpma.org>. There will be a common
distribution format across the entire IGTF (i.e. all three PMAs).
Dear CAs, Relying Parties, Users, and all others interested,
In this announcement of the EUGridPMA:
1. New distribution (0.31) with repairs and clarifications
We hope that you find this update useful and welcome any comments you
may have. Also, feel free to redistribute this information widely as
you see appropriate.
Regards,
David Groep
For more information about this newsletter and the mailing list,
please refer to the EUGridPMA web site at https://www.eugridpma.org/
=========================================================================
1. New distribution version 0.31
=========================================================================
A new distribution of Accredited Authorities by the EUGridPMA, release
version 0.31, is now available for download from the EUGridPMA Repository
https://www.eugridpma.org/distribution/current/
Note that this updates the previous release that was issued three days
ago. There are two reasons for this update:
* The Russian Data Intensive Grid (RDIG) CA was accidentally
left out of the accredited list. Thus, if you install the
old release, you will not get the RDIG CA, contrary to the
release notes.
* There was confusion about which CAs were actually accredited,
and are thus "safe" to install in a production system
*ONLY* CAs IN THE "accredited/" DIRECTORY and
THE CAs INSTALLED USING THE ca_policy_eugridpma-0.31-1.noarch.rpm
ARE ACCREDITED
Do *not* install certificates from the "worthless/", "other/",
or "discontinued/" directories, except if you your self review
and accept their policy and practice statement. The EUGridPMA
provides these certificates in this format for your convenience
only, and to allow graceful changeover for legacy installations.
You can download the new packages and install them at your convenience.
Changes from 0.30 to 0.31
-------------------------
(15 July 2005)
* Corrected packaging problem which left RDIG out of accredited CA group
* renamed the "unknown/" directory to "discontinued/"
* Added explanatory text to the distribution regarding the "other/",
"worthless/" and "discontinued/" directories
For those using RPM based linux distribution, a "meta-RPM" is available
from the repository, ca_policy_eugridpma-0.31-1.noarch.rpm, that contains
dependencies on the RPMs of all accredited CAs. The repository is
suitable for "yum" based automatic updates.
This is the first RPM distribution that will (on an experimental basis)
used GPG-signed RPMs. The key (ID 3CDBBC71) has been uploaded to
the public key servers, along with my signature as the EUGridPMA
Chair (keyID 6F298418). The key is also contained in the repository.
The next release of the CA RPMs is to be expected around August 2005,
(of course barring special circumstances). The format of those new releases
is currently under considation. If you want to contribute to the
discussion or to suggest improvements to have it better suit your needs,
please contact the PMA at <info(a)eugridpma.org>. There will be a common
distribution format across the entire IGTF (i.e. all three PMAs).