P-p-pick up a Pathfinder

Slides:



Advertisements
Similar presentations
Demonstrations at PRAGMA demos are nominated by WG chairs Did not call for demos. We will select the best demo(s) Criteria is under discussion. Notes.
Advertisements

29 June 2006 GridSite Andrew McNabwww.gridsite.org VOMS and VOs Andrew McNab University of Manchester.
ASPiS - Architecture for a Shibboleth-Protected iRODS System Mark Hedges, Tobias Blanke Centre for e-Research, Kings College London Adil Hasan, Jens Jensen.
Federated Access to Grids Daniel Kouřil, Sam Hartman, Josh Hewlet, Jens Jensen, Michal Procházka EGI User Forum 2011.
Implementing Federated Security with ConSec Jens Jensen, STFC OGF40, Oxford, 16 Jan 2014.
Contrail and Federated Identity Management
© Southampton City Council Sean Dawtry – Southampton City Council The Southampton Pathfinder for Smart Cards in public services.
Moonshot for Federated Identity Jens Jensen, STFC Daniel Kouřil, CESNET EGI CF, April 2013.
© Janet 2012 Project Moonshot Technology, use cases & pilot 17 January, 2012 Haka conference, Helsinki 1.
Technology on the NGS Pete Oliver NGS Operations Manager.
Project Moonshot TF-MNM. Use cases Project Moonshot 2.
Jens G Jensen CCLRC e-Science Single Sign-on to the Grid Federated Access and Integrated Identity Management.
Integrating HPC and the Grid – the STFC experience Matthew Viljoen, STFC RAL EGEE 08 Istanbul.
Federated A(A(A))I Jens Jensen hepsysman, RAL,
Tweaking the Certificate Lifecycle for the UK eScience CA John Kewley NGS Support Centre Manager & Service Manager for the UK e-Science CA
FIM-related activities and issues being discussed in Japan 1.GEO Grid Yoshio Tanaka (AIST) 2.HPCI, GakuNin Eisaku Sakane, Kento Aida (NII)
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
HPDC 2007 / Grid Infrastructure Monitoring System Based on Nagios Grid Infrastructure Monitoring System Based on Nagios E. Imamagic, D. Dobrenic SRCE HPDC.
2005 © SWITCH Perspectives of Integrating AAI with Grid in EGEE-2 Christoph Witzig Amsterdam, October 17, 2005.
Neil Witheridge APAN29 Sydney February 2010 ARCS Authorisation Services Neil Witheridge Manager, ARCS Authorisation Services APAN29, Sydney, February 2010.
ShibGrid: Shibboleth access to the UK National Grid Service University of Oxford and STFC.
Jens G Jensen CCLRC e-Science Single Sign-on at RAL (and DLS too) Authentication and Integrated Identity Management hepsysman Cambridge, 23 Oct 2006.
CertWizard: a New Certificate Tool for the UK NGI User Community John Kewley ( ), Jens Jensen, David Meredith and Akay Okcun 16/11/20151EGI.
Jens G Jensen CCLRC e-Science Single Sign-on to the Grid Authentication and Integrated Identity Management HEPiX, CASPUR, Rome 3-7 April 2006.
ESnet RAF and eduroam ™ Tony J. Genovese ATF Team ESnet/Lawrence Berkeley National Laboratory.
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
WebFTS File Transfer Web Interface for FTS3 Andrea Manzi On behalf of the FTS team Workshop on Cloud Services for File Synchronisation and Sharing.
New Developments in Access Management: Setting the Scene Alan Robiette JISC Development Group JISC-CNI Conference, June 2002.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Shibboleth & Grid Integration STFC and University of Oxford (and University of Manchester)
AAI Developments AAI for e-infrastructures UK T0 workshop, Milton Hill Park October 2015
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
EUDAT receives funding from the European Union's Horizon 2020 programme - DG CONNECT e-Infrastructures. Contract No B2ACCESS LSDMA.
EMI is partially funded by the European Commission under Grant Agreement RI Federated Grid Access Using EMI STS Henri Mikkonen Helsinki Institute.
The GRIDS Center, part of the NSF Middleware Initiative Grid Security Overview presented by Von Welch National Center for Supercomputing.
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
B2access.eudat.eu B2ACCESS User Training How to register with B2ACCESS Version 1 February 2016 This work is licensed under the Creative Commons.
Project Moonshot Daniel Kouřil EGI Technical Forum
EGI-Engage EGI-Engage WP3 e-Infrastructure Commons Diego Scardaci EGI.eu/INFN 6/18/2016 EGI-Engage – First.
Non Web-based Identity Federations - Moonshot Daniel Kouril, Michal Prochazka, Marcel Poul ISGC 2015.
News from EUGridPMA EGI OMB, 22 Jan 2013 David Kelsey (STFC) Using notes from David Groep 22/01/20131EUGridPMA News.
Soapbox (S-Series) Certificate Validation Jens Jensen, STFC.
Federated Access to Storage EGI CF 2012 Luke Howard, Daniel Kouril, Michal Prochazka.
ELIXIR AAI Michal Procházka, Mikael Linden, EGI VC 15 March 2016.
Authentication and Authorisation for Research and Collaboration On behalf of the MJRA1.2 scribes J Jensen.
eduroam-as-a-service
WLCG Update Hannah Short, CERN Computer Security.
Gridpp37 – 31/08/2016 George Ryall David Meredith
Project Facts Partners: DANTE (UK), GARR (IT), RedCLARA (UY), RedIRIS (ES), RENATA (CO), RNP (BR), TERENA (NL) Coordinator: RedCLARA Project Duration:
Jens Jensen EU Grid PMA, Berlin Jan 2015
Boosting AAI for research and collaboration
eduroam Managed IdP - Roadmap
EGI Updates Check-in Matthew Viljoen – EGI Foundation
AAI for a Collaborative Data Infrastructure
J Jensen, STFC hepsysman, June 2017
UK e-Science CA Update J Jensen, STFC 31 Jan 2017.
AAAI Pathfinder J Jensen, STFC 031 Oct,
Jens Jensen, STFC Sep EUGridPMA Manchester
Tweaking the Certificate Lifecycle for the UK eScience CA
Boosting AAI for research and collaboration
Jens Jensen, STFC 15 Sep GridPP39, Lancaster
Update on EDG Security (VOMS)
Dynamic DNS support for EGI Federated cloud
Thursday pilot session: 7-minutes
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
AARC Blueprint Architecture and Pilots
UK e-Science CA and JCS Migration Status
Community AAI with Check-In
AAI in EGI Status and Evolution
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

P-p-pick up a Pathfinder J Jensen, STFC GridPP38, U Sussex, Apr ‘17

Overview of Overview Overview of Pathfinder GridPP’s rôle and aims in the project Moonshot in action (well, pictures of) Where we are in GridPP’s task Future directions

Overview of Pathfinder

Executive Summary A national infrastructure pilot for authentication, authorisation, and accounting RC funded (EPSRC/STFC) Partners: UCL (lead), Edinburgh, JISC, Crick, Oxford, Durham, STFC, Leeds Resources DiRAC, GridPP, ARC, N8, eMedLab,… Budget £215K, 10 months, Oct ‘16 – Aug ‘17 (or thereabouts)

Technology Moonshot SAFE SAFE-SHARE IETF standard (ABFAB-WG, RFC 7831) JISC-led “eduRoam for higher level resources” (RFC 7832) Assent is the infrastructure running Moonshot services SAFE Acct mgmt used by ARCHER & others Developed at EPCC SAFE-SHARE Elevated LoA for medical/biosci, secure networks eMedLab

A pilot AAAI across xple sites Interoperability through X.509 gateway Main Deliverables A pilot AAAI across xple sites ARC, N8, DiRAC, eMedLab Interoperability through X.509 gateway This is GridPP’s contribution (in collab with JISC) This task March-April-May 2017 Future directions

DONE! WP details 0. Proj. mgmt Id mgmt pilots SAFE deployment Assent, homeless IdP, 2-factor for eMedLab SAFE deployment Integration VO/Assent (e.g. VOMS), Assent-X.509 (GridPP) Docs & writeups Architecture, business case DONE!

DONE! WP details 0. Proj. mgmt Id mgmt pilots SAFE deployment Assent, homeless IdP, 2-factor for eMedLab SAFE deployment Integration VO/Assent (e.g. VOMS), Assent-X.509 (GridPP) Docs & writeups Architecture, business case DONE!

GridPP’s rôle and aims in the project Task 3.2: Assent->X.509 gw … with JISC Instead of aiming for a test CA… Aiming for a full IGTF-approved MICS BIRCH profile … ensure that certificates are useful! Proper alternative to going to RA for personal certs (Once it’s in production) => WLCG, ELIXIR, EUDAT, PRACE, EGI

… in action, sort of: Moonshot

Experiences Learning curve? Support for OS? Lots of pieces… JISC’s documentation is much improved Support for OS? Native Debian, CentOS We are using RHEL for Pathfinder, no problem Windows supported Mac still being worked on Lots of pieces…

Moonshot Architecture (https://wiki.moonshot.ja.net/display/Moonshot/Overview+of+Moonshot+Components)

Windows Files Windows support: Moonshot-AMD64-full-1-0-86-0.msi Putty: putty-ms-rel.exe

Still needs to know username? ssh Still needs to know username?

Web Client - Browser This is the federal (= home org) id and password but it still needs it Works without credential manager but you need to type username/password When credential manager is used, it knows the username but still prompts for password You can ask the browser to remember the password … does need to use Internet Explorer

Web Server … REMOTE_ADDR = XXX.XXX.XXX.XXX REMOTE_USER = jj47 AUTH_TYPE = Negotiate GSS_NAME=jj47 GSS_SESSION_EXPIRATION=1491420326 GSS_NAME_ATTRS_JSON={"name":"jj47","attributes":…}

RFC 6680 attributes User-Name: jj47 Moonshot-Host-TargetedId: jj47 Moonshot-Realm-TargetedId: 1d536c5a-ff4c-5dfb-8ed0-08e618c22ab9@stfc.ac.uk Moonshot-TR-COI-TargetedId 108328f4-c077-51e2-9b0c-5ecb1c2403f2@stfc.ac.uk Should also carry Pathfinder authorisation attributes Task 3.1 looked at VOMS but only integrated SAFE attributes However, attributes easy to integrate at RADIUS level (and we plan something different for VOMS…)

Where we are in GridPP’s task

People Suleman Tariq STFC’s Moonshot admin (And also sysadmin for the CA…)

GridPP, EGI, PRACE, EUDAT, GlobusConnect DB Pathfinder T3.2 STFC/Facilities Portal sshd User Reg’n portal SCARF Public Authn MyProxy Online CA HSM GridPP, EGI, PRACE, EUDAT, GlobusConnect  VOMS

Front End(s) Red outline = Moonshot authenticated Moonshot (user) authenticated Account management Public Portal/server (no authentication required) Information Links to helpdesk (links to) JISC and service AUP CRL (links to) CP and CPS AUP Acceptance Name filter IdP check Attribute check Data Processing Acceptance Certificat e Interface Acct DB Status (Re)ne w Revok e Management Interface (X.509 authenticated) Service API Forget Red outline = Moonshot authenticated Black outline = certificate authenticated

Subtasks (high level view) (There are sub-sub-tasks as well) Get new CA into IGTF Write CP/CPS for new CA (ongoing) Submit for review before Ljubljana meeting Eval MyProxy || Implement CA Configure as Moonshot service Link to existing HSM User status interface Set up Community-of-Interest (CoI) Document requirement for IdP to meet BIRCH reqs Ensure IdPs publish the req’d attributes Add trusted IdPs into CoI More GridPP involvement? – add instr. to wiki

Open Questions Can we use MyProxy as a CA or credential store (or both)? => as CA, less work req’d => as CS, all certificates are delegated Whether (and when) to rekey the CA (MUST be done to go to production) What to do about account closure (BIRCH) Could link to RCauth if meeting BIRCH level fails Nevertheless, this would be a loss Filtering acceptable IdPs (through CoI)

Probably not much need for SAFE in GridPP? Build a real CA Conclusion Prototype AAAI Probably not much need for SAFE in GridPP? Build a real CA Albeit not quite production infrastructure Whether/How to do stuff across infrastructures?

Thanks