Get a personal certificate

The authentication of users in grid infrastructures is based on X.509 certificates, which are issued by certification authorities (CA). These CAs, mostly covering one country, form grid trust federations in order to allow users to access different grid infrastructures across different nations using only one X.509 certificate.

 

The personal certificate released by a Certification Authority that is accredited by the European Policy management Authority for Grid Authentication (EUGridPMA). EUGridPMA is the international organisation which coordinates the trust fabric for e-Science grid authentication in Europe. The Grid accredited authority for Italy is the INFN Certification Authority. The certificate has to be installed in a User Interface where you got an account. These are the steps to get your personal certificate from INFN CA:

    • install the Certification Autority certificate on your browser 
    • identify yourself to the Registration Authority in your department and ask him for an ID . If there no Registration Authority is available in your organization, a new one has to be defined 
    • ask for your Personal Certificate using the ID given to you by the RA 
    • install your Personal Certificate on your browser (the same browser of step 1). You have to wait for a couple of days to receive a mail with a web link to the page containing your certificate.
    • export your Personal Certificate from your browser 
    • copy your Personal Certificate in your home directory of a User Interface where you got an account

Additional documentation

More information on the process described above is provided here: INFN-GRID personal certificates howto

For an exhaustive guide on certificates please refer to: A Brief Guide to Certificate Management  (M. Luvisetto)

 A good introduction on Grid security is also available from the Globus site: Overview of the Grid Security Infrastructure (external link, Globus.org)