Security Policy Update WLCG GDB CERN, 11 June 2008 David Kelsey STFC/RAL

Slides:



Advertisements
Similar presentations
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks MyProxy and EGEE Ludek Matyska and Daniel.
Advertisements

Grid Security Policy GridPP18, Glasgow David Kelsey 21sr March 2007.
Grid Security Policy David Kelsey (RAL) 1 July 2009 UK HEP SYSMAN Security workshop david.kelsey at stfc.ac.uk.
Authorization WG Update David Kelsey EU Grid PMA, Copenhagen 27 May 2008.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group Summary EGI TF David Kelsey 6/28/
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
Trust and Security for FIM (Sirtfi/SCI) David Kelsey (STFC-RAL) FIM4R at CERN 4 Feb 2015.
Primavera Highlights During COLLABORATE  Primavera Key Note: Making the Most of Your Oracle Primavera Investment Dick Faris, Primavera Co-Founder & Oracle.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group EGI Technical Forum Sep 2010 David Kelsey.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Security Update WLCG GDB CERN, 12 June 2013 David Kelsey STFC/RAL.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
JSPG: User-level Accounting Data Policy David Kelsey, CCLRC/RAL, UK LCG GDB Meeting, Rome, 5 April 2006.
Security Policy Update LCG GDB Prague, 4 Apr 2007 David Kelsey CCLRC/RAL
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
8-Jul-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) RAL, 8 July 2003 David Kelsey CCLRC/RAL, UK
LCG Pilot Jobs + glexec John Gordon, STFC-RAL GDB 7 November 2007.
LCG/EGEE Security Operations HEPiX, Fall 2004 BNL, 22 October 2004 David Kelsey CCLRC/RAL, UK
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
9-Oct-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) FNAL 9 October 2003 David Kelsey CCLRC/RAL, UK
Grid Security Vulnerability Group Linda Cornwall, GDB, CERN 7 th September 2005
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) WLCG GDB, CERN 10 Jul 2013.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Security Vulnerability Identification and Reduction Linda Cornwal, JRA1, Brno 20 th June 2005
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
EGI-InSPIRE RI EGI EGI-InSPIRE RI Service Operations Security Policy the new generalised site operations security policy.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI SPG future work EGI Technical Forum Lyon, 21 Sep 2011 David Kelsey, STFC/RAL.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
12-Jun-03D.P.Kelsey, CA meeting1 CA meeting Minimum Requirements CERN, 12 June 2003 David Kelsey CCLRC/RAL, UK
18-May-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) Barcelona 18 May 2004 David Kelsey CCLRC/RAL, UK
Security Policy Update WLCG GDB CERN, 8 Dec 2010 David Kelsey STFC/RAL david.kelsey AT stfc.ac.uk.
Why a Commercial Provider should Join the Academic Cloud Federation David Blundell Managing Director 100 Percent IT Ltd Simple, Flexible, Reliable.
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
LCG Pilot Jobs + glexec John Gordon, STFC-RAL GDB 7 December 2007.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI CSIRT Procedure for Compromised Certificates and Central Security Emergency.
APGridPMA Update Eric Yen APGridPMA August, 2014.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Questionnaires to Cloud technology providers and sites Linda Cornwall, STFC,
Grid Deployment Technical Working Groups: Middleware selection AAA,security Resource scheduling Operations User Support GDB Grid Deployment Resource planning,
Grid Security Policy: EGEE to EGI David Kelsey (RAL) 16 Sep 2009 JSPG meeting, DFN Berlin david.kelsey at stfc.ac.uk.
News from EUGridPMA EGI OMB, 22 Jan 2013 David Kelsey (STFC) Using notes from David Groep 22/01/20131EUGridPMA News.
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
Cloud Security Session: Introduction 25 Sep 2014Cloud Security, Kelsey1 David Kelsey (STFC-RAL) EGI-Geant Symposium Amsterdam 25 Sep 2014.
PRACE user authentication and vetting Vincent RIBAILLIER, 29 th EUGridPMA meeting, Bucharest, September 9 th, 2013.
SCI & Sirtfi David Kelsey (STFC-RAL) EGI Conference, Lisbon 19 May 2015.
David Kelsey STFC-RAL 4th WISE workshop, Nikhef 27 March 2017
Club Administration PP Dave Taylor.
David Kelsey CCLRC/RAL, UK
Open Science Grid Consortium Meeting
ILD phone meeting September 5, 2017 K. Kawagoe (PSB chair)
Global Grid Forum GridForge
LCG Security Status and Issues
Ian Bird GDB Meeting CERN 9 September 2003
David Kelsey STFC-RAL 2nd WISE workshop, XSEDE16, Miami 18 July 2016
CRC exercises Not happy with the way the document for testbed architecture is progressing More a collection of contributions from the mware groups rather.
Romain Wartel EGEE08 Conference, Istanbul, 23rd September 2008
David Kelsey CCLRC/RAL, UK
Leigh Grundhoefer Indiana University
Updated (VO) Community Security Policies
Update - Security Policies
EGI support services Science gateway developers
Dr Linda Cornwall STFC/RAL EGI OMB 27th September 2013
Presentation transcript:

Security Policy Update WLCG GDB CERN, 11 June 2008 David Kelsey STFC/RAL

Overview JSPG meeting (29/30 May 08) Revised mandate for JSPG Policy approval (4 documents) JSPG Future plans 11 Jun 20082JSPG - D Kelsey

11 Jun 2008JSPG - D Kelsey3 JSPG meeting JSPG meeting was held at CERN –29/30 May 2008 Agenda included –Revised JSPG mandate –4 documents now ready for approval –Other policy documents VO Registration Policy (replaces VO Security Policy) VO Membership Management Policy (replaces User Registration…) Grid portals –Plans for the future During EGEE-III as we move towards EGI –Plans for JSPG web site, document repository and collaborative editing

Revised JSPG mandate (V3) JSPG is jointly owned by and makes recommendations to both WLCG and EGEE, its primary stakeholders. Policy prepared for WLCG is designed to be applied to all of its Grid infrastructures in so far as this relates to WLCG activities. In addition to EGEE, this means subsets of OSG, NDGF and other national Grids and/or individual Grid sites which participate in the WLCG collaboration. The most important JSPG activity is that it prepares and maintains security policies for its primary stakeholders. It is also able to provide policy advice on any security matter. The topics and issues can be specified either by the stakeholders or by JSPG itself. Priority will be given to issues relevant to the primary stakeholders. JSPG may create special focussed sub-groups to tackle specific issues. 11 Jun 20084JSPG - D Kelsey

JSPG Mandate (2) JSPG should, wherever possible, aim to prepare simple and general policies which are not only applicable to the primary stakeholders but that are also of use to other Grid infrastructures (NGI's etc). The adoption of common policies by multiple Grids can ease the problems of interoperability. JSPG deliberations happen by face to face meetings, phone/video conferences or by the JSPG mailing list. The membership of JSPG and its mailing list is determined by the chair of JSPG in consultation with the management of the primary stakeholders. JSPG should aim to have sufficient membership to include site security officers, site system administrators, Grid operational experts, middleware experts and members from the larger VOs. Members from other Grids are particularly welcome and are encouraged to request to join. 11 Jun 2008JSPG - D Kelsey5

JSPG Mandate (3) JSPG does not formally approve or adopt policies or advice. This is the responsibility of the stakeholder management bodies. The members of JSPG are treated as individual experts who do not formally represent any constituency. Individual members of JSPG agreeing to proposed policy does not imply automatic approval by their own Grid or organisation. 11 Jun 2008JSPG - D Kelsey6

Policy Approval 4 documents ready for WLCG and EGEE approval General comments –All have been widely distributed and discussed for months –All comments have been addressed –The current proposed versions were produced at the JSPG meeting (29/30 May) –Word documents with change tracking on –Not expecting any major changes at this point These can be addressed in the next policy review –But: a chance for final objections Each Grid should also provide a covering document per policy giving references, addresses and other implementation details 11 Jun 2008JSPG - D Kelsey7

General changes –Remove all footnotes and references References should be covered in the Grid-specific covering documents –Updated the names of referenced policy documents Particularly those related to VOs –Removed OSG logo (the revised JSPG mandate) –Removed direct references to LCG, EGEE etc. Documents should be general and simple –Consistent style –use of word “Grid” 11 Jun 2008JSPG - D Kelsey8

Virtual Organisation Operations Policy Version No major changes Change to names of VO policy documents Minor wording improvements 11 Jun 2008JSPG - D Kelsey9

Grid Security Traceability and Logging Policy Version 1.8a Only changed sections 4 and 5 Grid software MUST include the ability to collect logs centrally at a Site Make it clear who has to configure the logging –Service providers (including Sites) Logs MUST be collected centrally at service-provider level There may well be exceptions –There were SHOULDs before –Deal with these via the procedure for handling of exceptions Report to the Security Officer etc. 11 Jun 2008JSPG - D Kelsey10

Approval of Certification Authorities Version 2.7a Main aim was to add CAs accredited to the new IGTF MICS profile –X.509 certs issued following authentication by another Identity Management System E.g. CERN CA based on Active Directory Also added the ability for Sites to trust non-IGTF CA for local reasons –Must be allowed by local policy and they must deal with any potential non-unique names 11 Jun 2008JSPG - D Kelsey11

What is MICS? Abstract of the profile document This is an Authentication Profile of the International Grid Trust Federation describing the minimum requirements for Member Integrated X.509 Credential Services (MICS). MICS X.509 Public Key Certification Authorities (MICS PKI CAs) issue credentials to end-entities who themselves possess and control their key pair and activation data. These CAs will act as independent trusted third parties for both subscribers and relying parties within the infrastructure… 11 Jun 2008JSPG - D Kelsey12

MICS (2) Comment received… I do understand the sentence, but not what it is about. I don't know what sort of credentials are being issued to which sort of end-entities and I am not sure what activation data is. I am not sure who is subscribing to what nor which parties are relying on what. At least it is clear from the web page that whatever they are doing, they are doing it in a secure manner as defined in the Profile. It does sound really great, but not being able to understand what it is about, I feel reluctant to say that I agree with the change 11 Jun 2008JSPG - D Kelsey13

MICS (3) Section 2 (a better description!) A MICS is an automated system to issue X.509 formatted identity assertions (certificates) based on pre-existing identity data maintained by a federation or large organization – the end-entity certificate is thus based on a membership or authentication system maintained by the organization or federation. The CERN CA is a good example – X.509 certs based on Windows Active Directory MICS CAs are important to WLCG and EGEE!! 11 Jun 2008JSPG - D Kelsey14

Policy on Grid Multi-User Pilot Jobs Version 0.5a Rewording of the introduction –Make it clearer –Allow for pilot jobs submitted by a service VO has to name a real person responsible for this Reword point 1 –“Approval” rather than “trust relationship” Reword point 8 –Isolation should include inter-process comms Some other minor changes to words 11 Jun 2008JSPG - D Kelsey15

11 Jun 2008JSPG - D Kelsey16 Future JSPG plans Next face to face JSPG meeting –9/10 October 2008 at CERN –Phone conference(s) before then –Session also at EGEE’08 in September 08 (dissemination) Complete work on updated VO policies, accounting data and Grid portals Broaden the membership – include more NGIs Revise whole policy set (yet) again –More simple, general and consistent –More applicable to EGI world Improvements planned for web site –Use MediaWiki –Better collaborative editing and inclusion of discussion –Clearer presentation per Grid of current policy set

11 Jun 2008JSPG - D Kelsey17 JSPG Meetings, Web etc Meetings - Agenda, presentations, minutes etc JSPG Web site Membership of the JSPG mail list is closed, BUT –Requests to join stating reasons to D Kelsey –Volunteers to work with us are always welcome! Policy documents at security/documents.html