INFSO-RI-508833 Enabling Grids for E-sciencE www.eu-egee.org www.glite.org JRA3 Åke Edlund On behalf of JRA3 EGEE 8th All-activity meeting January 18-19,

Slides:



Advertisements
Similar presentations
GGF16, Athens AuthZ Interoperability Here and Now Workshop, 16 Feb 2006.
Advertisements

EGEE-II INFSO-RI Enabling Grids for E-sciencE The gLite middleware distribution OSG Consortium Meeting Seattle,
INFSO-RI Enabling Grids for E-sciencE Security (JRA3) Åke Edlund, JRA3 Manager, KTH David Groep, EUGridPMA chair, NIKHEF EGEE 1.
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
INFSO-RI Enabling Grids for E-sciencE Operational Security OSCT JSPG March 2006 Ian Neilson, CERN.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE-III Program of Work Erwin Laure EGEE-II / EGEE-III Transition Meeting CERN,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks JRA2: Quality Assurance & Security Coordination.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Extending user controlled security domain.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks CE Federation JRU Status Martin Polak GUP.
INFSO-RI Enabling Grids for E-sciencE SA1: Cookbook (DSA1.7) Ian Bird CERN 18 January 2006.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
Apr 30, 20081/11 VO Services Project – Stakeholders’ Meeting Gabriele Garzoglio VO Services Project Stakeholders’ Meeting Apr 30, 2008 Gabriele Garzoglio.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Steven Newhouse EGEE’s plans for transition.
INFSO-RI Enabling Grids for E-sciencE EGEE and Industry Bob Jones EGEE-II Project Director Final EGEE Review CERN, May 2006.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE – paving the way for a sustainable infrastructure.
EGEE is a project funded by the European Union under contract IST JRA3 Security Åke Edlund Security Head PEB All-Activity Meeting, June 18,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Ake Edlund EGEE Sec Head 9th MWSG meeting, SLAC,
INFSO-RI Enabling Grids for E-sciencE Plan until the end of the project and beyond, sustainability plans Dieter Kranzlmüller Deputy.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks JRA1 summary Claudio Grandi EGEE-II JRA1.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security Token Service Valéry Tschopp - SWITCH.
INFSO-RI Enabling Grids for E-sciencE NA5 – Policy and International Cooperation Panagiotis Louridas, Fotis Karagiannis, GRNET Final.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks State of Interoperability Laurence Field.
JRA Execution Plan 13 January JRA1 Execution Plan Frédéric Hemmer EGEE Middleware Manager EGEE is proposed as a project funded by the European.
INFSO-RI Enabling Grids for E-sciencE External Projects Integration Summary – Trigger for Open Discussion Fotis Karayannis, Joanne.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Linda Cornwall CCLRC (RAL) FP6 Security workshop.
US LHC OSG Technology Roadmap May 4-5th, 2005 Welcome. Thank you to Deirdre for the arrangements.
INFSO-RI Enabling Grids for E-sciencE Policy and International cooperation Matti Heikkurinen, NA5 leader CERN All Activity Meeting.
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
INFSO-RI Enabling Grids for E-sciencE EGEE SA1 in EGEE-II – Overview Ian Bird IT Department CERN, Switzerland EGEE.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Dr Linda Cornwall CCLRC (RAL) FP6 Security workshop.
INFSO-RI Enabling Grids for E-sciencE EGEE Security Joni Hahkala, UH-HIP On behalf of JRA3 JRA1 AH March 22-24, 2006.
Andrew McNabSecurity Middleware, GridPP8, 23 Sept 2003Slide 1 Security Middleware Andrew McNab High Energy Physics University of Manchester.
INFSO-RI Enabling Grids for E-sciencE EGEE Middleware reengineering Claudio Grandi – JRA1 Activity Manager - INFN EGEE Final EU.
EGEE-III INFSO-RI Enabling Grids for E-sciencE Antonio Retico CERN, Geneva 19 Jan 2009 PPS in EGEEIII: Some Points.
Glite. Architecture Applications have access both to Higher-level Grid Services and to Foundation Grid Middleware Higher-Level Grid Services are supposed.
INFSO-RI Enabling Grids for E-sciencE Security Summary Åke Edlund, JRA3 4 th EGEE Conference Pisa, Italy 28 th October 2005.
INFSO-RI Enabling Grids for E-sciencE JRA3 Security Åke Edlund, JRA3 Manager, KTH On behalf of JRA3 EGEE 2 nd EU Review.
INFSO-RI Enabling Grids for E-sciencE All activity meeting Vincent Breton On behalf of NA4.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks New Authorization Service Christoph Witzig,
INFSO-RI Enabling Grids for E-sciencE An overview of EGEE operations & support procedures Jules Wolfrat SARA.
INFSO-RI Enabling Grids for E-sciencE Policy and International cooperation Fotis Karayannis, NA5 activity leader All Activity Meeting.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Middleware reengineering Claudio Grandi (INFN – Bologna) EGEE Final.
INFSO-RI Enabling Grids for E-sciencE Quality Assurance Gabriel Zaquine - JRA2 Activity Manager - CS SI EGEE Final EU Review
INFSO-RI Enabling Grids for E-sciencE SAML-XACML interoperability Oscar Koeroo.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Ian Bird All Activity Meeting, Sofia
INFSO-RI Enabling Grids for E-sciencE Security (JRA3) Åke Edlund, JRA3 Manager, KTH David Groep, Security Expert, NIKHEF EGEE 1.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks NA5: Policy and International Cooperation.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks OpenSAML extension library and API to support.
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
INFSO-RI Enabling Grids for E-sciencE NPM Security Alistair K Phipps (NeSC) JRA4 Face To Face, CERN, Geneva.
EGEE is a project funded by the European Union under contract IST EGEE Security Åke Edlund Security Head EU IST-FP6 Concertation, 17 th September.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Study on Authorization Christoph Witzig,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Study on Authorization Christoph Witzig,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Application Porting Support Gergely Sipos,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks NA5: Policy and International Cooperation.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks NA5: Policy and International Cooperation.
INFSO-RI Enabling Grids for E-sciencE EGEE general project update Fotis Karayannis EGEE South East Europe Project Management Board.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Ake Edlund for JRA3 EGEE EU Review (CERN) May 23-24, 2006.
INFSO-RI Enabling Grids for E-sciencE Padova site report Massimo Sgaravatto On behalf of the JRA1 IT-CZ Padova group.
2 nd EGEE/OSG Workshop Data Management in Production Grids 2 nd of series of EGEE/OSG workshops – 1 st on security at HPDC 2006 (Paris) Goal: open discussion.
INFSO-RI Enabling Grids for E-sciencE NA5 – Policy and International Cooperation Panagiotis Louridas, Fotis Karagiannis, GRNET Final.
JRA1 Middleware re-engineering
JRA3 Introduction Åke Edlund EGEE Security Head
LCG Security Status and Issues
Ian Bird GDB Meeting CERN 9 September 2003
Presentation transcript:

INFSO-RI Enabling Grids for E-sciencE JRA3 Åke Edlund On behalf of JRA3 EGEE 8th All-activity meeting January 18-19, 2006 CERN, Switzerland

Enabling Grids for E-sciencE INFSO-RI th All-activity meeting, CERN - JRA3, Security 2 Outstanding work in EGEE-I Deliverables and milestones gLite Response to the reviewer’s recommendations Content

Enabling Grids for E-sciencE INFSO-RI th All-activity meeting, CERN - JRA3, Security 3 Deliverables DJRA3.4 (PM24-> PM22) KTH - Expected to be on time Assessment of security infrastructure report PM22, not PM24 as planned Milestones MJRA3.10 (PM24->PM21) UvA - Sent to reviewer on time. Security operational procedures (Second and third revision) Merged with MJRA3.8 No issues preventing successful project completion Outstanding work in EGEE-I Deliverables and milestones

Enabling Grids for E-sciencE INFSO-RI th All-activity meeting, CERN - JRA3, Security 4 LCMAPS/LCAS -Finer grained error codes; Implement globus C authZ callout interface to be able to plug lcas and lcmaps into gt3 and gt4 services; refine the proxy lifetime checking JobRepository -Integration into gLite 1.5 Java key handling for encrypted storage -Biomed DICOM server is in java: need for key generation and splitting in java Mutual authz for biomedical applications -The clients that store medical data want to be sure that the server they send the data to is authorized to store that data Double certs for glite IO -File access service gives assertion that the user is allowed to access a file, but the actual storage element also needs the user's credentials. So, the solution is to create a SAML assertion in FAS and embed that into the user's proxy. That way the storage element gets both glexec -Extended functionality; Finer grained error codes; Integration w Condor on the CE Outstanding work in EGEE-I gLite

Enabling Grids for E-sciencE INFSO-RI th All-activity meeting, CERN - JRA3, Security 5 Response to the reviewer’s recommendations “Prioritize the various security related tasks and requirements at the user and system level in order to come up with a list of intermediate goals towards a fortified Grid suitable for commercial deployment.” Applications: through the Technical Coordination Group (TCG) the long term, as well as the intermediate term, goals are prioritized according to applications requests. Industry: The final security assessment (DJRA3.4) will be presented to industry partners, for feedback.

Enabling Grids for E-sciencE INFSO-RI th All-activity meeting, CERN - JRA3, Security 6 “Spearhead the effort of prioritizing the security requirements via the industrial partners starting with their own requirements and with their experience interacting with others.” See previous slide. Input is today given by the EGEE Industry partners, DATAMAT, and the Industry Forum representative. In addition we participate in direct meeting with industrial interest groups, e.g. from Life Science, Finance, Biomed. Input from Life Sciences are given through the security knowledgeable NA4 representatives in the Middleware Security Group. In GGF16 EGEE security representatives will organize a half day workshop especially inviting the Life Sciences WG. Response to the reviewer’s recommendations

Enabling Grids for E-sciencE INFSO-RI th All-activity meeting, CERN - JRA3, Security 7 “Track and actively contribute to the activities of the newly established IGTF (International Grid Trust Federation), conveying their experiences about prioritization of the security requirements.” JRA3, through the EUGridPMA, was one of the main contributors in the launching of IGTF together with APGridPMA, TAGPMA David Groep (JRA3) is the first chair of IGTF. And will continue to be a member of IGTF. The current chair of IGTF is also a member of JRA3 and of MWSG and JSPG. Ensuring the feedback of IGTF experiences about prioritization of the security requirements. Response to the reviewer’s recommendations

Enabling Grids for E-sciencE INFSO-RI th All-activity meeting, CERN - JRA3, Security 8 “Outline and plan a series of stress tests of the security infrastructure.” The testing of the security infrastructure is divided into two parts, service attacks and the operational side’s response to the attacks. At this stage, and for the rest of the project, security analysis is our favoured method of testing security, with walk throughs and exercises for operational side. For the middleware input is given from the operational side, if logging etc is done properly or not. For actual holes in middleware security code reviews of the critical parts and basic smoke testing are part of these tests. For example we now have a set of test certificates, running the set against all the services gives us a valuable input whether the authentication works as it should. See also next slide, regarding external security audits. Response to the reviewer’s recommendations

Enabling Grids for E-sciencE INFSO-RI th All-activity meeting, CERN - JRA3, Security 9 “Conduct deliberate external attacks by 3 rd party contractors.” Not in EGEE-I. There is no place for this in the current plan. This is one of the deliverables of JRA2/Security Coordination in EGEE-II. First investigations and meetings with such 3 rd party contractors have been initiated, together with SA1/OSCT manager Ian Neilson. Response to the reviewer’s recommendations

Enabling Grids for E-sciencE INFSO-RI th All-activity meeting, CERN - JRA3, Security 10 “Address the interoperability of the various Grid security mechanisms, existent and planned, with established security procedures.” Interoperability is one of the main goals of the Middleware Security Group (MWSG). This has been very successful between EGEE and OSG, and has been promoted by GGF to be used as an example of pair-wise interoperability of Grids. To extend the interoperability effort, MWSG now includes DILIGENT, DEISA, SEEGRID and GRIDCC as members. Naregi Japan is also in close contact with MWSG and have met regularly the last year. New meeting focusing especially on Naregi needs is planned for beginning of March. Example of interoperability workshops co-organized respectively organized by EGEE:  GGF16, “Grid Authorization - Interoperability Here & Now”  HPDC15, “EGEE Workshop on Management of Rights in Production Grids” Response to the reviewer’s recommendations

Enabling Grids for E-sciencE INFSO-RI th All-activity meeting, CERN - JRA3, Security 11 The JRA3 outstanding work in EGEE-I is on time, both regarding Deliverables and milestones and gLite. So, no issues preventing successful project completion. Note: MJRA3.9 “Accounting” will be presented separably end of today by John White. Summary