Monthly Archives: March 2008

CAcert Assurance event ApacheCon Eur’08, Amsterdam, Apr 7-11 2008

ApacheCon logo

At the ApacheCon April 7-11, 2008 in Amsterdam, the official Apache User conference of the Apache Software Foundation there will be a CAcert booth for Individual and Organisation Assurances from 9-11 April. Visit the booth!

Be prepared and if you are not a CAcert Coimmunity Member yet, read the Community Agreement, join and registrate and print at least three Community Application (CAP) forms with your name and email address for the Assurance event.
The Oophaga Foundation, which organisation is taking care of CAcert events in Holland is looking for CAcert assurers who can help to assure on these conference dates. Please react to  cacert-support if you want to help.

Audit Report 20080321

As promised, there is now a current report posted on the wiki from Audit. Highlights:

  • CAcert is in the process of rolling out its new CAcert Community Agreement. The website now refers to it.
  • Soon, expect to see checkboxes to tick with statements like “I agree to the CAcert Community Agreement”.
  • The Assurance Policy is the next policy that the Audit needs tied down. Currently, it is at an advanced stage. Debate is going on as to whether to drop the requirement for Dates of Birth, as these are considered useful for fraud in some places. Unfortunately, the system does use this as an internal discriminator, so there are pros and cons.
  • Pat Wilson is now working on the Security Manual. Thanks, and welcome Pat!
  • The critical systems are the critical path for audit! Evaldo has been tasked to build the sysadm team, move the systems and implement dual control. See other blog entries!
  • Have you met the Assurer Challenge yet? CATS is in place, and some time soon, assurances will be blocked for those who have not as yet met the challenge.
  • If you are interested in the Audit work, there is a ToDo list on the wiki, and I have put the audit criteria online with the working commentary and (wip) conformance. See the main report for that location and the secret password!

That’s it from the Audit side. Now over to you!

Audit Report 20080111

One of the things that happened last year was to negotiate an audit funding deal with NLnet. (This has now agreed and first tranche of funds has been delivered to CAcert.) One of the requirements imposed on CAcert was to deliver reports to the Community and to NLnet at each event like milestones, and at approximately 2 month intervals.

With that in mind, I wrote a 2008 New Year’s report as a sort of checkpoint. For some reason it wasn’t published then, but is now on the wiki. Highlights are these:

  1. Many policies are now in POLICY or DRAFT. Some important work-in-progress projects are started, especially the Assurance Policy. This project needs help!
  2. The work on Risks/Liabilities/Obligations finally settled on a CAcert Community Agreement.
  3. NLnet funds CAcert for audit, described here.
  4. Non-critical systems were moved last year to Netherlands BIT center, but critical systems are still in their halfway house. CAcert needs more sysadms.
  5. Audit Criteria are going on-line.
  6. Best is last: CATS went on line: Have you done the Assurer Challenge yet?

The full report is found on the wiki area. Bear in mind that this report is late, and another is already due. I’ll start on that now!

IT fair in Bamberg, Germany

There will be a CAcert booth at the IT fair in Bamberg, Germany organized by trainees of Deutsche Telekom AG on 19th and 20th of March. Main topics will be Linux and networking. More information can be found on the website (german).
Address: Deutsche Telekom AG, Wilhelmsplatz 3, 96047 Bamberg, Germany
Im Rahmen der von Auszubildenden der Deutschen Telekom organisierten IT-Messe zum Thema Linux und Netzwerk wird es auch einen CAcert-Stand geben. Die Messe findet vom 19.-20. März in Bamberg statt. Weitere Informationen können der Webseite entnommen werden.
Adresse: Deutsche Telekom AG, Wilhelmsplatz 3, 96047 Bamberg