Daniel Kouril, EGI CSIRT meeting,


Similar presentations
LCG WLCG Operations John Gordon, CCLRC GridPP18 Glasgow 21 March 2007.

Mardi 30 mars 2010 Lavoisier : a way to integrate heteregeneous monitoring systems. Cyril LOrphelin IN2P3/CNRS Computing Centre, Lyon, France.
Canonical Producer CP API User Code CP Servlet Files CreateTable, Port, Protocol, Security, SQL Support, Multiple Query Support Security Insert Query Port.
EGI: SA1 Operations John Gordon EGEE09 Barcelona September 2009.
HPDC 2007 / Grid Infrastructure Monitoring System Based on Nagios Grid Infrastructure Monitoring System Based on Nagios E. Imamagic, D. Dobrenic SRCE HPDC.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks GStat 2.0 Joanna Huang (ASGC) Laurence Field.
MW Readiness Verification Status Andrea Manzi IT/SDC 21/01/ /01/15 2.
RI EGI-InSPIRE RI EGI Future activities Peter Solagna – EGI.eu.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE-EGI Grid Operations Transition Maite.
8 th CIC on Duty meeting Krakow /2006 Enabling Grids for E-sciencE Feedback from SEE first COD shift Emanoil Atanassov Todor Gurov.
INFSO-RI Enabling Grids for E-sciencE ARDA Experiment Dashboard Ricardo Rocha (ARDA – CERN) on behalf of the Dashboard Team.
SAM Sensors & Tests Judit Novak CERN IT/GD SAM Review I. 21. May 2007, CERN.
Update of SAM Implementation ALICE TF Meeting 18/10/07.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI How to integrate portals with the EGI monitoring system Dusan Vudragovic.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Ops Portal New Requirements.
Why a Commercial Provider should Join the Academic Cloud Federation David Blundell Managing Director 100 Percent IT Ltd Simple, Flexible, Reliable.
The GridPP DIRAC project DIRAC for non-LHC communities.
SAM Status Update Piotr Nyczyk LCG Management Board CERN, 5 June 2007.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Operations Portal Development Update on Requirements Cyril L'Orphelin IN2P3/CNRS.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Security Monitoring Daniel Kouřil EGI-TF 2011.
Probes Requirement Review OTAG-08 03/05/ Requirements that can be directly passed to EMI ● Changes to the MPI test (NGI_IT)
II EGEE conference Den Haag November, ROC-CIC status in Italy
NGI France-Grilles: Infrastructure evolution H. Cordier.
EGI Process Assessment and Improvement Plan – EGI core services – Tiziana Ferrari FedSM project 1EGI Process Assessment and Improvement Plan (Core Services)
Co-ordination & Harmonisation of Advanced e-Infrastructures for Research and Education Data Sharing Research Infrastructures Grant Agreement n
INFN/IGI contributions Federated Clouds Task Force F2F meeting November 24, 2011, Amsterdam.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Regionalisation summary Prague 1.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks The Dashboard for Operations Cyril L’Orphelin.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Questionnaires to Cloud technology providers and sites Linda Cornwall, STFC,
Logging and Monitoring. Motivation Attacks are common (see David's talk) – Sophisticated – hard to reveal, (still) quite limited in our environment –
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Status of ARGUS support Peter Solagna – EGI.eu.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Update on Service Availability Monitoring (SAM) Marian Babik, David Collados,
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Services for Distributed e-Infrastructure Access Tiziana Ferrari on behalf.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Release Process Michel Drescher, EGI Kostas Koumantaros, GRNET 7/5/2016.
WLCG Operations Coordination Andrea Sciabà IT/SDC GDB 11 th September 2013.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Operations Portal OTAG September, 21th 2011 Cyril L’Orphelin – CCIN2P3/CNRS.
Testing and Release Procedures/Tools Cristina Aiftimiei (INFN-CNAF) Mario David (LIP)
Test Administrator Interface Training Computer Based Administrations of: 8-10 & Retake ELA Writing 4-10 & Retake ELA Reading and Listening 5-8 Mathematics.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI COD activity in EGI-InSPIRE Marcin Radecki CYFRONET, Poland & COD Team 9/29/2016.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI SA1.2 Plans 2013 Security Operations David Kelsey (STFC) 26/02/2013 Operations.
Daniele Bonacorsi Andrea Sciabà
SharePoint 101 – An Overview of SharePoint 2010, 2013 and Office 365
Monitoring Evolution and IPv6
NGI and Site Nagios Monitoring
Investigation authentication using AAF for the CVL on NeCTAR
Andreas Unterkircher CERN Grid Deployment
GOCDB New Requirements
Key Activities. MND sections
FedCloud Blueprint Update
POW MND section.
PRACE-EGI helpdesk integration
Patricia Méndez Lorenzo ALICE Offline Week CERN, 13th July 2007
Tax Professional (CA) - Registration and Services
Security Monitoring in a Nagios world
Lavoisier : a way to integrate heteregeneous monitoring systems.
Advancements in Availability and Reliability computation Introduction and current status of the Comp Reports mini project C. Kanellopoulos GRNET.
Operations & Coordination Tools
Discussions on group meeting
Solutions for federated services management EGI
Leigh Grundhoefer Indiana University
Unsupported middleware migration update
Software Vulnerability Group Status update
Tax Professional (CA) - Registration and Services
Operations sustainability
EGI Ops Tools Advisory Group (GOCDB)
Tax Professional (CA) - Registration and Services
UMD 2 Decommissioning Status
EUDAT Site and Service Registry
Retirement calendar of gLite 3.2 and EMI 1 middleware
Presentation transcript:

Daniel Kouril, EGI CSIRT meeting, 9.9.2016 RT report Daniel Kouril, EGI CSIRT meeting, 9.9.2016

Current status Upgrade finished RTIR more invasive then expected DB retained (history, ticket numbers, etc.) Several artifacts, nothing serious Massticket adapted to use the new API RTIR more invasive then expected Dictates/expects workflows, handling tickets, etc. (bulk operations, naming of functions, …) Creating tickets improved (to be enabled) Adding of Site and NGI contacts from GOC DB Should allow for controlling access as discussed earlier Reporting – Sven?

Daniel Kouril, EGI CSIRT meeting, 9.9.2016 Security monitoring Daniel Kouril, EGI CSIRT meeting, 9.9.2016

Components Nagios – secmon Pakiti Security Dashboard Operated by GRNET (NGI_GR), security core task Pakiti Operated by CESNET (NGI_CZ), security core task Security Dashboard Operated by NGI_FRANCE, core task on operations portal Coordination – CESNET

Secmon status Issues with current instance Information from Pakiti not kept by Pakiti probe Failures of the submission system 2016-09-04: - 2016-09-05: 64 2016-09-06: 129 (expired certificate) 2016-09-07: 165 2016-09-08: 169 2016-09-09: 146 (ARC CE issues, certificate again?)

Secmon status Service based on SAM, not supported anymore Transition to ARGO difficult WN framework not supported on SL6 Implications on dashboard not clear atm No effort for development from GRNET Until a solution a find we can stick with current instance (based on SL5!)

Certification of sites Supporting infrastructure is gone BDII, WMS, registration portal We can’t send monitoring jobs to non-production sites anymore (we were the only ones) Suggested to join security tests with normal certification ones and use the same procedure NGI will make sure tests are performed Sites is put into production, with immediate downtime declared (3 days) If no issue appears, it’s in production NGIs are complaining about the manual work, EGI to find a solution

Leftovers IanN: wants more compact view Sophie: more query options/ views Toby: feature request for pakiti.egi.eu -redirect to https! Sven: change "Pakiti-Check" test name to the CVE Dashboards send notifications now Reports can be generated regularly

Secant – VM assessment Pilot ready, sandboxed environment prepared Verified on CESNET cloud Testing of EGI VA’s pending VM catcher development Manual tests of couple AppDB Vas Majority closed, only external tests possible To be investigated

<. xml version="1. 0" encoding="UTF-8" <?xml version="1.0" encoding="UTF-8"?> <SECANT> <NMAP_TEST status="OK"><ports><extraports state="closed" count="999"> <extrareasons reason="resets" count="999"/> </extraports> <port protocol="tcp" portid="22"><state state="open" reason="syn-ack" reason_ttl="64"/><service name="ssh" method="table" conf="3"/></port> </ports> </NMAP_TEST> <NTP_AMPLIFICATION_TEST status="FAIL"/> <SSH_AUTH_TEST status="OK">SSH password authentication is not allowed</SSH_AUTH_TEST> <LYNIS_TEST status="OK"> <WARNINGS> <LYNIS>Version of Lynis is very old and should be updated </LYNIS> <AUTH-9228>pwck found one or more errors/warnings in the password file </AUTH-9228> <PKGS-7390>apt-get check returned a non successful exit code. </PKGS-7390> <NETW-2705>Couldn't find 2 responsive nameservers </NETW-2705> </WARNINGS> <SUGGESTIONS> <BOOT-5122>Set a password on GRUB bootloader to prevent altering boot configuration (e.g. boot in single user mode without password) </BOOT-5122> …… </SUGGESTIONS> </LYNIS_TEST> <PAKITI_TEST status="OK">No vulnerable packages.</PAKITI_TEST> </SECANT>