REVIEW-71: XCI-509 Enhance CILogon Silver CA with support for REFEDS Assurance - Design/Security Review

Overview

General design and security risk review for the capability to issue IGTF BIRCH LOA certificates using REFEDS Cappuccino via the CILogon Silver CA for enhanced interoperability.

Review Summary

Primary review feedback:

  • Updated Section B (Introduction) to describe a LIGO-EGI motivating use case.
  • Updated Section G (Interface Design) to document the user and admin interfaces for using the CILogon Silver CA.

Review Output Documents (Final)

XCI-509-CILogon-Silver-REFEDS-Assurance-Design-v1.1.pdf

Review Input Documents

XCI-509-CILogon-Silver-REFEDS-Assurance-Design.pdf

Review Criteria

Please focus on these questions:

  1. Does the proposed design provide the required functionality
  2. Does the proposed design follow XSEDE security guidelines and best practices
  3. Does the proposed design mitigate all significant security risks
  4. Could the proposed design be improved

Schedule

Current Date: 2019-09-15
Current Status: Closed (Design and Security Review)
Target Date Actual Date Activity Milestone
  2019-04-19 Review launch date
2019-04-30 2019-05-15 Written feedback due (Reviewers)
2019-05-15 2019-05-24 Written response date (Review Material Developers)
2019-05-17 2019-05-24 Final approval due and completion date (Reviewers)
Review Created: 2019-04-19 10:21 am
Review Last Updated: 2019-05-24 1:05 pm

 

Reviewers

If you are a reviewer, please login to sign or withdraw from this review.

Required

  • John-Paul Navarro
    VIEWED: 2019-05-24 13:06

Optional

  • Victor Hazlewood
  • Lee Liming
    VIEWED: 2019-04-26 14:32
    SIGNED: 2019-04-26 12:59
  • Jim Marsteller
  • Scott Sakai
    VIEWED: 2019-04-29 14:09
    SIGNED: 2019-04-29 14:09
  • Derek Simmel
  • Shava Smallen
    VIEWED: 2019-05-02 20:11
  • Alexander Withers

Review Material Developers

Jim Basney

Review Facilitator

John-Paul Navarro

 

Please post your comments using the "New topic" or "Post reply" buttons in the forum below.