13 February 2002 PPDG Phone Meeting
12:30pm PST, 2:30pm CST, 3:30pm EST
This URL: http://www.ppdg.net/mtgs/phone/020213/default.htm
To attend using telephone:
Long Distance users call 1-877-252-5250,
Local users call 510-647-3480,
then press 1, enter 7734# and follow the instructions.
(Note that 7734 is PPDG on your telephone keypad.)
| notes |
Topics |
links |
|
status of DOESG CA, PPDG RA |
|
|
ldap VO server |
|
|
registration agents (RA) behavior |
mh |
|
|
|
|
|
|
|
AOB |
|
Attendees (sites):
LBNL DO, EH, MT, BT, SC, TG, MH, SL; ANL EM, VW; SDSC BZ; FNAL RP, LB; JLAB
IB, AK, BH, CW; Caltech CS, HN; SLAC AdilH;
Notes & Action items (draft)
CA/RA status
TG - Some problem last week now resolved with interaction with Globus s/w.
Another set of hardware to issue bulk certificates, hope to be up early March.
Rest of hardware ordered and expect full environment in May. Could add
more RA's then.
RA appendix for PPDG and FNC in the CP/CPS now. V1.2 should be out for review by
end of Feb.
EM - tech question - question about chaining certificates
MH - French CA has a chain in it. Having a root CA with subordinate
CA's allows us to have additional CA's and also allows us to have the
subordinate CA on the net, which is somewhat of a risk. The root CA is
offline. The current CA (pki1) will have a short lifetime but we are not
sure how short yet. There will be another set up and another CA operating
for the same domain.
SL - For NERSC we would like to at least fiscal year boundary.
MT - Previous experience leads me to want 24 month certificates but 12 is OK.
ldap VO server
CS - have INFN ldap VO server installed and now trying to get access to
certificates to test it.
MH - We will set up an ldap server with the CA at some point, maybe
March. This is Roberto Cecchini's work right?
CS - Yes. You define groups for the VO and then can generate gridmap
files.
MH - You could just replicate the ldap directory from the CA (when we
have it) and would be easier than copying the certificates.
RA behavior
A questionnaire
was sent to ppdg-cara list and people should send replies and comments to that
list.
(discussion about host and service certificates)
PPDG Home
|