Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.
-
Upload
blake-manning -
Category
Documents
-
view
220 -
download
0
Transcript of Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.
![Page 1: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/1.jpg)
Template Profile
Jens Jensen, STFC RALGridNet2/ UK e-Science CA
OGF22 Boston
![Page 2: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/2.jpg)
The Problem
MINREQ
BestPractice
CA policy
CA practicestatement
CAPRACTICE
Check consistency
![Page 3: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/3.jpg)
New Policies
• Usually written by novice CA mgr– Using bits from other CP/CPSes
• Accentuate the positive– All the good bits get copied around
• Eliminate the negative– All the bad bits get copied around
![Page 4: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/4.jpg)
Problem
• Policies become inconsistent• Don’t satisfy minimal requirements• Need many iterations with reviewer
– Bad for CA manager– Bad for reviewer
![Page 5: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/5.jpg)
Common Examples• RA checking CRL
– 4.5.2 MUST at time of reliance– 4.9.6 MUST at time of reliance– 9.6.4: “according to their satisfaction”
• Email both confidential and not• Flood protection at 1.2 metres on
1st floor
![Page 6: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/6.jpg)
Is it a big problem?
• We already cover half the world• But there is another half
![Page 7: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/7.jpg)
Proposed Solution?• Working group on Template Profile
– Jens, David G, Milan, Anders, Vinod, David O'C, Mike, Sergey, Hardi
• Get the “best” bits from policies• Living document – but needs an
editor• Reviewers best to write/contrib• Become an IGTF document
![Page 8: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/8.jpg)
Status
• …er, not really started yet• Amsterdam meeting Jan 2008
![Page 9: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/9.jpg)
Piecing it together
• Easier to set up new CP/CPS– Too easy?
• Easier to get it right sooner– Often many, many, iterations are
req’d– Greatly delays Accreditation
![Page 10: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/10.jpg)
Operational Reviews
• TAGPMA are leading in this area– Template for operational review– But a reviewer still needs to read the
CP/CPS!!– Quicker if many bits known to be good
• APGridPMA auditing for accreditation– Yoshio’s auditing procedure
![Page 11: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/11.jpg)
Operational Reviews
• Highlight:– Which bits are canonical– Which bits are based on guides– Which bits are changed since
previous version
![Page 12: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/12.jpg)
Piecing it together• Delaying Accreditation is bad
– Reviewers are already overloaded– (Not necessarily with reviews but with real
life jobs)– Time consuming for new CAs
• Get new CAs in early (PMAs)– Not after the policy is written
![Page 13: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/13.jpg)
Pieceing it together
• Not aiming for machine parseable• Or should we?
– (Chadwick, Coghlan/O’Callaghan)
• TAGPMA guide to writing CP/CPS
![Page 14: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/14.jpg)
RFC 3647
![Page 15: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/15.jpg)
What about existing CAs
• Leave alone, for now• Some not satisfying minreqs• Minreqs change, too
– Mythical six months to update
![Page 16: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/16.jpg)
Back on track…?
• Urgent changes - Aggressive option– Do it in six months or else
• Medium urgency– Address with next CP/CPS change– At least before next PMA presentation
• Lower urgency– Discuss at next presentation
![Page 17: Template Profile Jens Jensen, STFC RAL GridNet2/ UK e-Science CA OGF22 Boston.](https://reader036.fdocuments.net/reader036/viewer/2022082412/5514d8d755034640138b6461/html5/thumbnails/17.jpg)
Summary
• Template profile– Approved text for sections where it
makes sense– Approved guidelines (cf TAGPMA) for
other sections– Open bits– Get new CAs in early