CRIC ・ Authentication & Authorization

Slides:



Advertisements
Similar presentations
Lesson 3: Managing User Access and Security (Cache Administrators only)
Advertisements

Site Authorization Service (SAZ) at Fermilab Vijay Sekhri and Igor Mandrichenko Fermilab CHEP03, March 25, 2003.
OSG AuthZ Architecture AuthZ Components Legend VO Management Services Grid Site GUMS Site Services SAZ CE Gatekeeper Prima Is Auth? Yes / No SE SRM gPlazma.
VOMRS/VOMS-Admin 2.0.x 2.5.x comparison Mar 28, 2008 Middleware Security Group Meeting Tanya Levshina and Gabriele Garzoglio Computing Division, Fermilab.
30-Jan-03D.P.Kelsey, GridPP Security1 Security GridPP6 30 Jan 2003 Coseners House David Kelsey CLRC/RAL, UK
Membership, Role Manager and Profile Membership, Role Manager and Profile Matt Gibbs ASP.NET Development Manager.
Operating Systems & Information Services CERN IT Department CH-1211 Geneva 23 Switzerland t OIS Open source web analytics.
Chapter 7 WORKING WITH GROUPS.
VOX Project Status T. Levshina. Talk Overview VOX Status –Registration –Globus callouts/Plug-ins –LRAS –SAZ Collaboration with VOMS EDG team Preparation.
Ákos FROHNER – DataGrid Security Requirements n° 1 Security Group D7.5 Document and Open Issues
The Future of Fields or, How Snow and Flu in Chicago Clarified What Drupal is Good For.
Intro to Grouper There’s nothing fishy about Identity Management with Grouper.
VOMRS/VOMS-Admin Convergence and VO Services Project Status Tanya Levshina Computing Division, Fermilab.
Grid User Management System Gabriele Carcassi HEPIX October 2004.
Author - Title- Date - n° 1 Partner Logo WP5 Summary Paris John Gordon WP5 6th March 2002.
EduGain Federation – Web SSO
Maarten Litmaath (CERN), GDB meeting, CERN, 2006/02/08 VOMS deployment Extent of VOMS usage in LCG-2 –Node types gLite 3.0 Issues Conclusions.
Ákos FROHNER – DataGrid Security n° 1 Security Group D7.6 Design Ideas
Roles 1. Your Role: End User End Users use Inside NCDOT and Connect NCDOT for basic browsing and reading Typical tasks can include: Open or download files.
Placeholder ES 1 CERN IT Experiment Support group Authentication and Authorization (AAI) issues concerning Storage Systems and Data Access Pre-GDB,
$100 $200 $300 $400 $500 $100 $200 $300 $400 $500 $100 $200 $300 $400 $500 $100 $200 $300 $400 $500 $100 $200 $300 $400 $500 $100 $200 $300.
Mine Altunay July 30, 2007 Security and Privacy in OSG.
WP3 Authorization and R-GMA Linda Cornwall WP3 workshop 2-4 April 2003.
VO. VOMS 1. Authentication2. Credentials 3. Authentication Client Resource.
Eine Einführung ins Grid Andreas Gellrich IT Training DESY Hamburg
Copyright © 2006 Pilothouse Consulting Inc. All rights reserved. Security Overview Functional security – users, groups, and permissions for sites, lists,
Glite. Architecture Applications have access both to Higher-level Grid Services and to Foundation Grid Middleware Higher-Level Grid Services are supposed.
Ad Hoc VO Akylbek Zhumabayev Images. Node Discovery vs. Registration VO Node Resource User discover register Resource.
HLRmon accounting portal DGAS (Distributed Grid Accounting System) sensors collect accounting information at site level. Site data are sent to site or.
VO Membership Registration Workflow, Policies and VOMRS software (VOX Project) Tanya Levshina Fermilab.
Token TOKEN User Groups Roles Claims Authentication Provider Identities STSUser Authentication Method UserGroup Role Assignment Permission Level FD.
AstroGrid-D Meeting MPE Garching, M. Braun VO Management.
Virtual Organization Membership Service eXtension (VOX) Ian Fisk On behalf of the VOX Project Fermilab.
Auditing Project Architecture VERY HIGH LEVEL Tanya Levshina.
8 Copyright © 2004, Oracle. All rights reserved. Making the Model Secure.
Introducing Event handler Group Name: SEC & ARC Source: FUJITSU Meeting Date: Agenda Item: Device Configuration.
WP3 Security and R-GMA Linda Cornwall. WP3 UserVOMS service authr map pre-proc authr LCAS LCMAPS pre-proc LCAS Coarse-grained e.g. Spitfire WP2 service.
VOX Project Status T. Levshina. 5/7/2003LCG SEC meetings2 Goals, team and collaborators Purpose: To facilitate the remote participation of US based physicists.
Site Authorization Service Local Resource Authorization Service (VOX Project) Vijay Sekhri Tanya Levshina Fermilab.
The GridPP DIRAC project DIRAC for non-LHC communities.
EGEE is a project funded by the European Union under contract IST New VO Integration Fabio Hernandez ROC Managers Workshop,
VO Management Tanya Levshina Computing Division, Fermilab.
HLRmon Enrico Fattibene INFN-CNAF 1EGI-TF Lyon, France19-23 September 2011.
Use Outlook Task API to access tasks stored on user’s mailbox. These REST API’s are  Simple to use.  Supports CRUD.  JSON structured.  OAuth 2.0.
CERN IT Department CH-1211 Geneva 23 Switzerland t OIS Operating Systems & Information Services CERN IT Department CH-1211 Geneva 23 Switzerland.
Architectural Framework Presentation Vincenzo Ciaschini CNAF 15/5/06.
VOX Project Status Report Tanya Levshina. 03/10/2004 VOX Project Status Report2 Presentation overview Introduction Stakeholders, team and collaborators.
Virtual Organization Management Registration Service (VOMRS) T. Levshina J. Weigand S. White Co-Authors: L. Bauerdick, G. Carcassi, I. Fisk, A. Heavey,
Adxstudio Portals Training
Transportation Agenda 19. Transportation Your Role: Designer Designers organize SharePoint content and determine how to display that content Typical tasks.
sTGC production database design
Jean-Philippe Baud, IT-GD, CERN November 2007
UVOS and VOMS differences
R-GMA Security Principles and Plans
Downtime procedure.
Security Monitoring in a Nagios world
AMGA Web Interface Salvatore Scifo INFN sez. Catania
Job workflow Pre production operations:
Computing Resources Information Catalog
SAM Alarm Triggering and Masking
Digital Lobby.
NRMC HQ PUBLIC FACING INTERNET PORTAL Security Model

SharePoint Security for the Site Owner
NRMC HQ PUBLIC FACING INTERNET PORTAL Security Model
AMGA Web Interface Vincenzo Milazzo
LitwareHR v2: an S+S reference application
NRMC HQ PUBLIC FACING INTERNET PORTAL Security Model
TE-CRG-CE Controls and Electrical Support for cryogenics
Presentation transcript:

CRIC ・ Authentication & Authorization Aresh Vedaee CRIC ・ Authentication & Authorization

Authentication Sources (Role = List of permissions) MAPPING SCHEMA AUTHENTICATION Authentication Sources SSO CERN HR DB VOMS CRIC DB … Principals Users Groups (Group = Collection of individuals) Roles (Role = List of permissions) Site Admin Experiment Site Support Experiment Admin CRIC Admin

Authentication Sources (Role = List of permissions) MAPPING SCHEMA AUTHENTICATION AUTHORIZATION Authentication Sources SSO CERN HR DB VOMS CRIC DB … Principals Users Groups (Group = Collection of individuals) Roles (Role = List of permissions) Site Admin Experiment Site Support Experiment Admin CRIC Admin

Authentication sources (Role = List of permissions) MAPPING SCHEMA AUTHENTICATION AUTHORIZATION PERMISSIONS (Permission = Action + Entity) Authentication sources SSO CERN HR DB VOMS CRIC DB … Principals Users Groups (Group = Collection of individuals) Roles (Role = List of permissions) Site Admin Experiment Site Support Experiment Admin CRIC Admin Create Modify Delete Read Actions Object instances Object properties WEB UI / API Entities

Authentication Sources (Role = List of permissions) MAPPING SCHEMA AUTHENTICATION AUTHORIZATION PERMISSIONS (Permission = Action + Entity) Authentication Sources SSO CERN HR DB VOMS CRIC DB … Principals Users Groups (Group = Collection of individuals) Roles (Role = List of permissions) Site Admin Experiment Site Support Experiment Admin CRIC Admin Create Modify Delete Read Actions Object instances Object properties WEB UI / API Entities Restrictions

ROLES CORE Expert Experiment Expert Site A Site A Site B Site B Site C SEs CEs Site A SEs CEs Site A SEs CEs Site B SEs CEs Site B SEs CEs Site C

ROLES CORE Expert Experiment Expert Experiment Admin Site A Site A SEs CEs Site A SEs CEs Site A SEs CEs Site B SEs CEs Site B Experiment Admin + Restriction( VO = “CMS” ) SEs CEs Site C

ROLES CORE Expert Experiment Expert Experiment Admin SEs CEs Site A SEs CEs Site A SEs CEs Site B SEs CEs Site B Experiment Admin + Restriction( VO = “CMS” ) SEs CEs Site C Experiment Site Support + Restriction( VO = “CMS”, Site = “Site B” )

ROLES CORE Expert Experiment Expert Site Admin Experiment Admin SEs CEs Site A SEs CEs Site A Site Admin + Restriction( Site = “Site A” ) SEs CEs Site B SEs CEs Site B Experiment Admin + Restriction( VO = “CMS” ) SEs CEs Site C Experiment Site Support + Restriction( VO = “CMS”, Site = “Site B” )