EGEE is a project funded by the European Union under contract IST-2003-508833 New VO Integration Fabio Hernandez ROC Managers Workshop,


Similar presentations
29 June 2006 GridSite Andrew VOMS and VOs Andrew McNab University of Manchester.

Forschungszentrum Karlsruhe in der Helmholtz-Gemeinschaft Torsten Antoni – LCG Operations Workshop, CERN 02-04/11/04 Global Grid User Support - GGUS -
Last update 01/06/ :23 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD Site Registration policy & procedures
Joining the Grid Andrew McNab. 28 March 2006Andrew McNab – Joining the Grid Outline ● LCG – the grid you're joining ● Related projects ● Getting a certificate.
EGEE is a project funded by the European Union under contract IST SA1 and NA3 Alistair Mills Grid Deployment Group +41.
EGEE is a project funded by the European Union under contract IST The way ahead Alistair Mills Grid Deployment Group
INFSO-RI Enabling Grids for E-sciencE SA1: Cookbook (DSA1.7) Ian Bird CERN 18 January 2006.
GGF12 – 20 Sept LCG Incident Response Ian Neilson LCG Security Officer Grid Deployment Group CERN.
VOMS Alessandra Forti HEP Sysman meeting April 2005.
Security Area in GridPP2 4 Mar 2004 Security Area in GridPP2 “Proforma-2 posts” overview Deliverables – Local Access – Local Usage.
EGEE is a project funded by the European Union under contract IST Plan for ROC verification Hélène Cordier - Alistair Mills IN2P3, CRNS, France.
02/07/09 1 WLCG NAGIOS Kashif Mohammad Deputy Technical Co-ordinator (South Grid) University of Oxford.
SouthGrid SouthGrid SouthGrid is a distributed Tier 2 centre, one of four setup in the UK as part of the GridPP project. SouthGrid.
Responsibilities of ROC and CIC in EGEE infrastructure A.Kryukov, SINP MSU, CIC Manager Yu.Lazin, IHEP, ROC Manager
The ILC And the Grid Andreas Gellrich DESY LCWS2007 DESY, Hamburg, Germany
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
EGEE is a project funded by the European Union under contract IST User support in EGEE Alistair Mills Torsten Antoni EGEE-3 Conference 20 April.
3-Nov-00D.P.Kelsey, HEPiX, JLAB1 Certificates for DataGRID David Kelsey CLRC/RAL, UK
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Next steps with EGEE EGEE training community.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE-EGI Grid Operations Transition Maite.
Induction: Adding new applications to EGEE infrastructure –April 26-28, Adding new applications to EGEE infrastructure Roberto Barbera EGEE is.
Next Steps: becoming users of the NGS Mike Mineter
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
EGEE is a project funded by the European Union under contract IST EGEE Services Ian Bird SA1 Manager Cork Meeting, April
DataGRID Testbed Enlargement EDG Retreat Chavannes, august 2002 Fabio HERNANDEZ
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks SA1: Grid Operations Maite Barroso (CERN)
Grid Security Vulnerability Group Linda Cornwall, GDB, CERN 7 th September 2005
INFSO-RI Enabling Grids for E-sciencE EGEE SA1 in EGEE-II – Overview Ian Bird IT Department CERN, Switzerland EGEE.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks The EGEE User Support Infrastructure Torsten.
EGEE is a project funded by the European Union under contract IST Support in EGEE Ron Trompert SARA NEROC Meeting, 28 October
Status Organization Overview of Program of Work Education, Training It’s the People who make it happen & make it Work.
EUROPEAN UNION Polish Infrastructure for Supporting Computational Science in the European Research Space Operational Architecture of PL-Grid project M.Radecki,
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Last update 21/01/ :05 LCG 1Maria Dimou- cern-it-gd Current LCG User Registration, VO management and Authorisation Procedures VOMS workshop
INFSO-RI Enabling Grids for E-sciencE An overview of EGEE operations & support procedures Jules Wolfrat SARA.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at
Last update 31/01/ :41 LCG 1 Maria Dimou Procedures for introducing new Virtual Organisations to EGEE NA4 Open Meeting Catania.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Resource Allocation in EGEEIII Overview &
EGEE is a project funded by the European Union under contract IST Roles & Responsibilities Ian Bird SA1 Manager Cork Meeting, April 2004.
Site Certification Process (Round Table) Fabio Hernandez IN2P3 Computing Center - Lyon October
Last update 22/02/ :54 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD VO Registration procedure Presented by.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
Last update 29/02/ :31 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD VOMS status IT GD Group Meeting
EGEE is a project funded by the European Union under contract IST Task Breakdown – SA1 Alistair Mills SA1 - CERN SA1 Meeting Cork, 20 April.
M. Cristina Vistoli EGEE SA1 Organization Meeting EGEE is proposed as a project funded by the European Union under contract IST Regional Operations.
Last update 13/03/ :11 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD Status of the Task Force for User Registration of LHC Experiment Users
Stephen Burke – Sysman meeting - 22/4/2002 Partner Logo The Testbed – A User View Stephen Burke, PPARC/RAL.
EGEE is a project funded by the European Union under contract IST Service Activity 1 M.Cristina Vistoli ROC Coordinator All activity meeting,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Grid is a Bazaar of Resource Providers and.
EGEE is a project funded by the European Union under contract IST Aims and organization of the Biomedical VO Yannick Legré CNRS/IN2P3 NA4/SA1.
INFSO-RI Enabling Grids for E-sciencE Resource allocation and negotiation update C. Vistoli, R. Rumler Operations workshop Bologna.
INFSO-RI Enabling Grids for E-sciencE GOCDB2 Matt Thorpe / Philippa Strange RAL, UK.
INFN-Grid WS, Bari, 2004/10/15 Andrea Caltroni, INFN-Padova Marco Verlato, INFN-Padova Andrea Ferraro, INFN-CNAF Bologna EGEE User Support Report.
EGEE is a project funded by the European Union under contract INFSO-RI DGAS Grid accounting L.Gaido on behalf of A.Guarise LCG Workshop November.
Bob Jones EGEE Technical Director
Regional Operations Centres Core infrastructure Centres
EGEE Middleware Activities Overview
David Kelsey CCLRC/RAL, UK
SA1 Execution Plan Status and Issues
LCG Security Status and Issues
Ian Bird GDB Meeting CERN 9 September 2003
SA1-NA4 Meeting 15 September 2004
EGEE VO Management.
The CCIN2P3 and its role in EGEE/LCG
LCG Operations Workshop, e-IRG Workshop
Update on EDG Security (VOMS)
Grid Security M. Jouvin / C. Loomis (LAL-Orsay)
Pierre Girard ATLAS Visit
INFNGRID Workshop – Bari, Italy, October 2004
Presentation transcript:

EGEE is a project funded by the European Union under contract IST New VO Integration Fabio Hernandez ROC Managers Workshop, May

Milan, May 10-11, Contents Objective Overview of the procedure Case study: VO management in LCG Implementing the procedure  Short-term solution  Mid-term solution

Milan, May 10-11, Objective Identify the procedure to bring a new virtual organization into the EGEE grid infrastructure Identify the tools needed to support the procedure Adopt an implementation strategy for the procedure  Both for short and long term

Milan, May 10-11, Proposed Procedure Step 1: new VO acceptance by the operations group  VO representative requests inclusion through the OAG During the lifetime of the EGEE project this request must be done by NA4 Should include some (even rough) estimation of requested resources May include already identified RCs which agree on providing resources for the VO Must include an appointed VO manager  OAG advises operation management on the opportunity of including the new VO  OMC requests ROCs to identify RCs willing to provide resources for the new VO’s users There should be at least one of them

Milan, May 10-11, Proposed Procedure (cont.) Step 2: identify one or more CICs/ROCs to run core grid services for the new VO  VOMS, RLS, RB, UIs, BDIIs, …  identify one CIC responsible for coordinating the set up of these services Step 3: when the VO services are ready, inform the registrar so that the user registration procedure include the newly accepted VO  Assuming we want a unique registrar for all the users of the EGEE grid  More on this later Step 4: RCs providing resources to the new VO must modify some configuration files Step 5: the new VO users can then start registering and are allowed to enter the grid!

Milan, May 10-11, Case Study: LCG Unique registrar for all supported VOs  Run by CERN  Currently accepting the 4 LHC experiments, Babar, D0 and the LCG Deployment Team VO  User information includes contact information (family name, given name, home institute, address, telephone number and VO affiliation) Currently one individual can belong to only one VO at a time When a new user (holding a user certificated issued by an accepted CA) fills the registration form…  A new entry in the registrar’s data base is created  The request is forwarded to the VO’s manager for approval and inclusion in the VO’s data base The registrar’s data and the VO’s data can be queried through the LDAP protocol  Used by RCs to grant users access to grid resources

Milan, May 10-11, Case Study: LCG (cont.) A separate management service is run for each VO  Currently they are all LDAP-based  The VO manager(s) adds/deletes entries in the LDAP data base No authorization information is stored in the VO data base  Every VO member has the same privileges when accessing grid resources A few members of the each VO have the role of Experiment Software Managers  They have appropriate permissions to modify the experiment’s installed software on RCs

Milan, May 10-11, Implementing the Procedure: Short Term Solution NA4 requested the inclusion of a bio-medical VO in LCG-2 (a.k.a. EGEE-0)  Need to identify RCs willing to provide services for this VO  Two sites in France will: IN2P3 Lyon and IN2P3 Clermont-Ferrand  Anyone else from other regions? Set up a LDAP-based VO management service  This allows for compatibility with the procedures and tools in use by LCG-2  Currently being done in Lyon

Milan, May 10-11, Implementing the Procedure: Long Term Solution (?) Set up VOMS-based service for bio-medical VO  Upward compatibility guaranteed  This will be done in Lyon as soon as the LDAP-based service is up and running  Migration path from LDAP-based to VOMS-based is available

Milan, May 10-11, VOMS Virtual Organisation Membership Service DataGRID middleware Grid service which allows a user to prove he is a member of a VO and that he has certains roles within the VO Features  A user can belong to more than one VO  A user can belong to several groups within a VO  A user can have several roles within a VO Authorization information is embedded in the user grid credentials  Grid services contacted by the user use this information to granting/revoking access to resources  Trust relationship between RCs and the VO

Milan, May 10-11, Questions Should national/regional VOs follow the same procedure? Do we want a unique registrar for the whole grid?  Unique entry point for new users  Who will run it? Can we share the registrar with LCG?  Registrar may be unavailable for a period of time without (big) impact for the service  However, it contains information that is very useful from the operations point of view, namely the users contact information Do we want in the long term to replicate registrar to provide high availability? Do we need an ‘Operations’ VO for people deploying the software?  Something similar to ‘dteam’ in LCG-2 but restricted to operations people Do we need a ‘Guests’ VO for people not belonging to one of the accepted VOs?  For letting people to become familiar with the infrastructure, for instance