TCS (eScience) Personal CA Milan Sova Context TCS: TERENA SSL CA - - PowerPoint PPT Presentation

tcs escience personal ca
SMART_READER_LITE
LIVE PREVIEW

TCS (eScience) Personal CA Milan Sova Context TCS: TERENA SSL CA - - PowerPoint PPT Presentation

TCS (eScience) Personal CA Milan Sova Context TCS: TERENA SSL CA TERENA eScience SSL CA TERENA Personal CA TERENA eScience Personal CA TERENA Code Signing CA Concept CA as SAML SP RAs as SAML IdPs


slide-1
SLIDE 1

TCS (eScience) Personal CA

Milan Sova

slide-2
SLIDE 2

Context

  • TCS:

– TERENA SSL CA – TERENA eScience SSL CA – TERENA Personal CA – TERENA eScience Personal CA – TERENA Code Signing CA

slide-3
SLIDE 3

Concept

  • CA as SAML SP
  • RAs as SAML IdPs
  • “self-service” for users
slide-4
SLIDE 4

Contracts

  • TERENA – Comodo
  • TERENA – NRENs

(NREN != Identity Federation)

  • NRENs – member organizations

...all refer to CPS

– identity vetting requirements – ...

slide-5
SLIDE 5

Connecting IdPs

  • SP-centric federation

– IdPs registered with the SP – metadata usually distributed via federations

slide-6
SLIDE 6

Control

  • eduPersonEntitlement

– IdP-based authorization – released by IdP for properly vetted and eligible

users

slide-7
SLIDE 7

Content of a certificate

  • unique ID

– traceability, naming conflicts

  • specific attribute, eduPersonPrincipalName,...

– in CN (eScience Personal CA) – in CN or unstructuredName (Personal CA)

slide-8
SLIDE 8

Content of a certificate II

  • commonName

– “reasonable representation” of person's name – CN, displayName,...

  • email

– up to 10 addresses verified by IdP

  • organization name

– pre-registered with SP

  • country

– pre-registered with SP

slide-9
SLIDE 9

Content of a certificate - example

Subject: CN=Milan Sova 6356,O=CESNET,C=CZ Attribute: CN TCS-ID OrgName CountryCode

slide-10
SLIDE 10

Conclusions

  • It works!
  • ...not really using the existing federation fabric

– no legal inter-federation infrastructure – no unified attribute set provided by IdPs