Recruiting and Training Delegated Administrators

A knowledge base article about Recruiting and Training Delegated Administrators provided by the UC Berkeley IT Service Hub - Knowledge Portal

Recruiting DRAOs

Central administrative team

Who administers the program?

The InCommon Certificate service is managed by UC Berkeley's CalNet team, which oversees Identity and Access Management services for our campus. The five members of the CalNet team have all been granted RAO level permissions (see Chain of Trust section). For any given week, the "on-call" staff person processes certificate requests.

How do customers submit requests?

The CalNet team uses a published mailing list, calnet-pki@lists.berkeley.edu, to accept and process certificate requests.

Instructions to customers making certificate requests are included in our published InCommon Certificate FAQ.

How are requests reviewed/validated as legitimate?

UC Berkeley already had a pre-established program for registering a Security Contact for all campus hosts. As part of implementing the InCommon Certificate program, CalNet team members were given access to the Security Contact Application so that RAO's could look up the Security Contact for any given host. The CalNet RAO forwards the certificate request to the registered Security Contact. Once approved, the CalNet team member uses the InCommon CSM application to enter and review the CSR and approve the certificate.

Central vs. delegated administration

We anticipate some campus customers will continue to send certificate requests directly to the CalNet team, but our hope is that the vast majority of requests can be handled by local, departmental certificate administrators (DRAOs). Please see sections below on our approach to recruiting and training those administrators.

Initial recruitment of delegated administrators

Central IT Staff

The CalNet team began by requesting that the Deputy CIO approve DRAO status for a handful of central IST staff. These staff manage hosts on behalf of other campus departments and for campus-wide services. They were granted permission to approve certificates at the top level .berkeley.edu domain.

Departmental IT Staff

The CalNet team then identified the highest level IT staff in large campus departments like the business school, law school, EECS, etc, asking that they appoint delegated certificate administrators for their departments. We also asked approved departmental administrators to provide us the subdomains/hosts to enroll for that department. See sample letters, here.

We maintain the list of approved departmental administrators in our internal wiki, noting the department name, managerial sponsor, and date the administrator was approved. Our default is to grant DRAO status for 3 years, which is the default certificate length we grant as well.

We will review the list of DRAOs at least annually to remove accounts for employees who have left the university.

Adding DRAOs to the InCommon CSM

Once management has appointed or approved a DRAO, we contact the administrator to request enrollment information. See our sample enrollment letter and screenshots for adding DRAOs to the InCommon CSM.

Ad hoc recruitment of delegated administrators

While we hope to catch as many departments as possible in our initial efforts to recruit departmental administrators, we know we will miss some. When requests come to our central service mailing lists, calnet-pki@lists.berkeley.edu, our response includes a paragraph requesting contact information for a high level manager in that department who could authorize departmental administrators. We check that person's standing via the campus directory and then send the manager our letter to authorize departmental administrators.

Training DRAOs

At UC Berkeley, we require all DRAOs to participate in an in-person training before we approve their DRAO status. Below is an outline of the training and some related documentation. Below is our training outline:

Your responsibility as a DCA

Some tips for generating CSRs

Using the InCommon CSM tool

Some questions we have received: