Dear CAs, Relying Parties, Users, and all others interested,
In this announcement of the EUGridPMA:
-1- New CA distribution v0.27 available
-2- Update of the Minimum Requirements for Accreditation (v3.2)
Release 0.27 of the CA distribution available
---------------------------------------------
A new distribution of Accredited Authorities by the EUGridPMA, release
version 0.27, is now available for download from the EUGridPMA Repository
https://www.eugridpma.org/distribution/current/
Please download the new packages and install them at your earliest
convenience, since the new package includes upgrades to some of the
existing CAs as well (CNRS Grid-FR and CyGrid) and it fixes a problem
with the use of the UK e-Science CA with recent versions of the OpenSSL
package.
Changes from 0.26 to 0.27 (22 February 2005):
* added additional entry to UKeScience signing policy file to accomodate
openssl 0.9.7c rendering of emailAddress component in the subject DN
* updated DutchGrid CA cert from web site: extended lifetime to 2021 and
changed digest algorithm from MD5 to SHA1
* added a tar-ball distribution with a configure scrfipt for convenience
* Removed DOESG-Root from the accredited CA list, as per request of of
the CA on January 28, 2005. There are no certs left issued by this CA.
* Added Grid-FR CA by CNRS, and extended the signing_policy file of the
associated CNRS-Projets CA.
* A new root certificate for the CyGrid CA (with a new subject name). The
old CyGrid CA has been moved to "-old". Both are in the accredited list.
The next release (0.28) of the CA RPMs is expected for the end of March 2005.
Update of the Minimum Requirements for Accreditation
----------------------------------------------------
The Minimum Requirements guidelines document has been clarified and
elaborated in several places, bringing it better in line again with the
common minimum requirements that are coordinated globally via the
International Grid Federation (IGF) and to make them less ambiguous.
This does not alter the meaning of the requirements in any way.
Thew new version of the document (v3.2) is also available from the
web site at
http://www.eugridpma.org/guidelines/
The changes are:
* better synchronisation with the APGridPMA guidelines (and our own
version 2.1) regarding recovation of certificates.
* clarification of wording regarding the uniqueness of subject names
* a list of CA and RA personnel must now be explicitly maintained
* worded more carefully what the PMA expects regarding scope of new CAs,
and the expected level of commitment and sustainability of member CAs
* the description of the profile of end-entity certificates, that
was in section 4, has been made explicit in a new subsection
4.1. New requirements in this area include a compulsory inclusion
of the CRLDistributionPoints extension, and also AuthorityInfoAccess in
case the CA operated a production-level OCSP responder.
* the use of MD5 has been depricated
Regards,
David Groep.
PS: to leave this mailing list, please visit the EUGridPMA link below and
look at the Subscriber options at the bottom of the page:
http://mailman.eugridpma.org/cgi-bin/listinfo/eugridpma-announce
Dear members, relying parties, and other users,
A new release of the "accredited CA distribution" - version 0.26 - from
the European Grid Authentication PMA in eScience is now available
for download from the usual location:
http://www.eugridpma.org/distribution/current/
This release removed the "Spain-old" CA that expired in November 2004,
but that was causing unnecessary warnings in some software distributions.
It also includes the new RMKI CA, extending coverage for authentication
to Hungary.
The information is provided in RPM and .tar.gz format, the set of
accredited CAs being located in the "accredited/" subdirectory. An
RPM containing only dependencies on the accredited CAs is provided
as "ca_policy_eugridpma-0.26-1.noarch.rpm". For users of RPM the
repository is "yum" enabled.
Large projects serving this software to their sites and end-users are
requested to mirror the distribution.
Regards,
David Groep.
(chair)
--
David Groep
** National Institute for Nuclear and High Energy Physics, PDP/Grid group **
** Room: H1.56 Phone: +31 20 5922179, PObox 41882, NL-1009DB Amsterdam NL **
Dear Relying parties, CAs, and Others,
Although the previous release of the distribution of the EUGridPMA
Accredited Authorities was quite recent, we are forced to issue a new
release that includes a new root certificate for the Spanish DataGrid CA
(DataGrid-ES, whose alias is "Spain").
The new distribution (version 0.25) is now available from the EUGridPMA
repository, including new sources and meta-RPMs. You can update at your
convenience, but if you are relying on certificates issued by DataGrid-ES
you should upgrade before November 12. See:
http://www.eugridpma.org/distribution/current/
Also I would like to remind you that relying parties and any others
interested can subscribe ot the announce(a)eugridpma.org mailing list
(low traffic) via the web site at http://www.eugridpma.org/
Regards,
David Groep.
--
David Groep
** National Institute for Nuclear and High Energy Physics, PDP/Grid group **
** Room: H1.56 Phone: +31 20 5922179, PObox 41882, NL-1009DB Amsterdam NL **
Dear CAs, Relying Parties, and others,
New CAs approved
----------------
On October 20th, the EUGridPMA released a new version of the Accredited
Authorities distribution: version 0.24.
This distribution is now available on the web site at
http://www.eugridpma.org/distribution/0.24/
All relying parties that accept the Minimum Requirements (now at version
3.1) as sufficient, can update to the new Roots of Trust at their
convenience. A change log is included in this mail at the bottom.
Note that the updated LIP CA will start issuing certs from the
new root CA quite soon.
Announcements mailing list
--------------------------
To improve communications from the EUGridPMA Member Authorities to
relying parties, an announcement mailing list has been set up. This
low-traffic list will carry messages like:
- new releases of the distribution,
- changes in the CP/CPS of accredited Authorities,
- aggregated information regarding grave events and incidents.
Everyone is invited to subscribe to the "announce(a)eugridpma.org"
mailing list by:
* Sending a mail to <announce-request(a)eugridpma.org> with a single line
"subscribe" in the body of the message
* Or go to the web interface at:
http://mailman.eugridpma.org/cgi-bin/listinfo/eugridpma-announce
The list is archived and old messages can be reviewed at:
http://mailman.eugridpma.org/pipermail/eugridpma-announce/
Changelog for 0.23->0.24
------------------------
* Added the Slovenian SiGNET CA with hash 747183a and alias: SiGNET
* Added the SEE-GRID CA with hash 468d15b3 and alias: SEE-GRID
* Added the Estonian Grid CA, with hash 566bf40f and
alias: EstonianGrid
* Added the updated LIP CA (called "LIPCA") with hash 11b4a5a2, which
will supercede the old one with hash 41380387. The "LIP" one
will remain in the repository will the end of 2005.
* Added RPM requirements that reflects CA chaining:
CNRS-Projects requires CNRS
CNRS-DataGrid requires CNRS-Projects
DOEGrids requires ESnet
--
David Groep
** National Institute for Nuclear and High Energy Physics, PDP/Grid group **
** Room: H1.56 Phone: +31 20 5922179, PObox 41882, NL-1009DB Amsterdam NL **
To all interested parties:
This list "announce(a)eugidpma.org" carries announcements made by the
EUGridPMA to the members, relying parties and others interested. Such
accouncements include amongst others new releases of the distribution,
changes in the CP/CPS of accredited Authorities.
The web archive is to be found at
http://mailman.eugridpma.org/pipermail/eugridpma-announce/
and you can subscribe by seding an email to <announce-request(a)eugridpma.org>
with a single line in the body: "subscribe".
Please see the EUGridPMA web site for additional details:
http://www.eugridpma.org/
--
David Groep
** National Institute for Nuclear and High Energy Physics, PDP/Grid group **
** Room: H1.56 Phone: +31 20 5922179, PObox 41882, NL-1009DB Amsterdam NL **