Title Tweaking the Certificate Lifecycle for the UK eScience CA
Abstract We are improving the UK eScience Certification Authority (CA) by making tweaks to our certificate lifecycle and developing a REST interface to the UK eScience CA with client tools that can be customised accordingly. The UK National Grid Service (NGS) Support Centre provides helpdesk support for the UK eScience CA, receiving many tickets relating to certificates and their renewals. This is largely due to browser incompatibilities with our OpenCA Web interface. In addition, our current certificate lifecycle could be improved with the introduction of new and streamlined processes that would make it easier for users to manage their personal and host certificates. These include; a)renewals of recently expired certificates, b) a light weight certificate re-application process that requires only a virtual meeting with an RA, c) a certificate change interface for amending selected certificate attributes which may not require a meeting with an RA, and finally, d) a service for requesting a bulk of host certificates in a single request. To achieve these improvements, we are developing a REST interface for the UK CA with accompanying client tools. Although this requires extra development effort, this enables us to take control of our certificate lifecycle with the aim of providing an improved user experience.
Organisation ESC , STFC , ESC-SCT
Keywords RA , certificate , CA , Grid , certification authority , engineering
Language English (EN)
Presentation Presented at EGI Community Forum 2012 / EMI Technical Conference (EGICF2012), Munich, Germany, 26-30 Mar 2012. JK-EGI-CF.pptx 2012
Paper In Conference Proceedings In EGI Community Forum 2012 (EGICF12), Munich, Germany, 26-30 Mar 2012, (2012). http://pos.sissa.…ICF12-EMITC2_151.pdf 2012
