Why does the GridShib CA care about the umask?
When your web browser launches the Java Web Start file used by the GridShib CA to download your credentials, the browser writes a file to the temporary directory used by Java Web Start. This file contains a secret value (detail: the Shibboleth session id) used by the Java Web Start application. If your umask is set insecurely this temporary file could be read by other users on your system and used to impersonate you and get a copy of your Grid credential from the GridShib CA.