Mapping ELIXIR projects to EGI VOs

Slides:



Advertisements
Similar presentations
Demonstrations at PRAGMA demos are nominated by WG chairs Did not call for demos. We will select the best demo(s) Criteria is under discussion. Notes.
Advertisements

Role Based VO Authorization Services Ian Fisk Gabriele Carcassi July 20, 2005.
Polish Infrastructure for Supporting Computational Science in the European Research Space EUROPEAN UNION Services and Operations in Polish NGI M. Radecki,
Haga clic para cambiar el estilo de título Haga clic para modificar el estilo de subtítulo del patrón DIRAC Framework A.Casajus and R.Graciani (Universitat.
Dorian Grid Identity Management and Federation Dialogue Workshop II Edinburgh, Scotland February 9-10, 2006 Stephen Langella Department.
CILogon OSG CA Mine Altunay Jim Basney TAGPMA Meeting Pittsburgh May 27, 2015.
VOMS Alessandra Forti HEP Sysman meeting April 2005.
All Unit Charter Renewals are due at the respective District’s Roundtable Meeting in November Last Updated 9/29/15.
AAI WG EMI Christoph Witzig on behalf of EMI AAI WG.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
WP3 Authorization and R-GMA Linda Cornwall WP3 workshop 2-4 April 2003.
VO. VOMS 1. Authentication2. Credentials 3. Authentication Client Resource.
Next Steps: becoming users of the NGS Mike Mineter
Role Based VO Authorization Services Ian Fisk Gabriele Carcassi July 20, 2005.
VO management: Progress since Chicago Workshop Vincenzo Ciaschini 23/5/2002 CNAF – Bologna.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
Ad Hoc VO Akylbek Zhumabayev Images. Node Discovery vs. Registration VO Node Resource User discover register Resource.
Last update 21/01/ :05 LCG 1Maria Dimou- cern-it-gd Current LCG User Registration, VO management and Authorisation Procedures VOMS workshop
1 AHM, 2–4 Sept 2003 e-Science Centre GRID Authorization Framework for CCLRC Data Portal Ananta Manandhar.
Last update 31/01/ :41 LCG 1 Maria Dimou Procedures for introducing new Virtual Organisations to EGEE NA4 Open Meeting Catania.
SCI-BUS is supported by the FP7 Capacities Programme under contract nr RI Accessing Cloud Systems from WS-PGRADE/gUSE Zoltán Farkas MTA SZTAKI LPDS.
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
0 SAT Online - Student Registration What You Will Need In order to register, you must have: –A working account –Several possible user names* –A unique.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
EGI Technical Forum Madrid COMPSs in the EGI Federated Cloud Daniele Lezzi – BSC EGI Technical Forum Madrid.
OSG PKI Transition Impact on CMS. Impact on End User After March , DOEGrids CA will stop issuing or renewing certificates. If a user is entitled.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Davide Vaghetti, et al. Topics for PY2 activities.
Registration StratusLab Tutorial (Orsay, France) 28 November 2012.
Authentication and Authorisation for Research and Collaboration Peter Solagna, Nicolas EGI AAI integration experiences AARC Project.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI solution for high throughput data analysis Peter Solagna EGI.eu Operations.
Virtual Organisations and the NGS Mike Jones Research Computing Services e-Science & “The Grid” for Bio/Health Informaticians, IT January 2008.
AUU Website Solution Purpose built for the AUU
WLCG Update Hannah Short, CERN Computer Security.
RCauth.eu CILogon-like service in EGI and the EOSC
EGI Updates Check-in Matthew Viljoen – EGI Foundation
HA CRER Portal - Quick User Guide
Partner Program Platform Training Partner Self Service
E-GRANT: EGI Resource Allocation Tool Current status
UVOS and VOMS differences
eduTEAMS – Current status & Future Plans
Christos Kanellopoulos
Grid accounting system
Assess Survey Invitations
CheckIn: the AAI platform for EGI
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
Check-in Nicolas Liampotis
The EGI Applications on Demand (AoDs) service
CRC exercises Not happy with the way the document for testbed architecture is progressing More a collection of contributions from the mware groups rather.
An AAI solution for collaborations at scale
ELIXIR Safeguarding the results of life science research in Europe
Status report of the LToS platform
Update on EDG Security (VOMS)
Dynamic DNS support for EGI Federated cloud
How to Register on Active Orders Trading Grid Company Registration
Assessing Combined Assurance
Assessing Combined Assurance
The New Virtual Organization Membership Service (VOMS)
Peter Solagna – EGI Foundation
Thursday pilot session: 7-minutes
Grid Security M. Jouvin / C. Loomis (LAL-Orsay)
Pilots in AARC Arnout Terpstra (AARC2) / Paul van Dijk (AARC1)
AARC Blueprint Architecture and Pilots
ELIXIR Competence Center
RCauth.eu CILogon-like service in EGI and the EOSC
Community AAI with Check-In
EGI FedCloud User Support coordination meeting
AAI in EGI Status and Evolution
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Operations Management Board March 26
Presentation transcript:

Mapping ELIXIR projects to EGI VOs

Current setup NB: For ELIXIR: VO = pool of cloud sites, each site with a pledge (dedicated or opportunistic) EGI secures pledges with a community SLA and matching resource provider OLAs See an example here: D4Science: https://documents.egi.eu/document/2875 Users can be Members of a VO  Access all sites Belong to specific VO group  Specific privileges So far “regular” and “VO manager” roles All EGI VOs: https://operations-portal.egi.eu/vo/search About 10 with SLA so far! For ELIXIR: 1 VO, but not yet SLA-OLA: vo.elixir-europe.org VO Manager: Steven Newhouse Configured at CESNET, EBI, GRNET. TBD: CSC, SURFSara, CNRS

Supporting multiple projects in ELIXIR How this could work… EGI and ELIXIR signs framework agreement This would be a special SLA-OLA: Leaving it open which project (VO) ELIXIR will allocate the committed sites to Sites do not enable any VO yet – they only reserve the capacity. Evaluation and setup of project-VOs ELIXIR: decides about projects; defines VO names; assigns VO Managers; maps VOs to sites, Inform EGI and the sites about the decision. ELIXIR: Registers VOs in the Operations Portal (fill online form) Cloud providers: configure VOs and allocate capacity according to the ELIXIR specification Adding users to projects Introduce ‘member of project X’ attribute in ELIXIR AAI and pass this to the EGI CheckIn as ‘VO membership’ attribute. Define ‘role A in project X’ attribute in ELIXIR AAI and pass this to the EGI CheckIn as ‘VO group’ attribute VO Manager role is important. This person will be able to approve project-VO members and VM images. Add these attributes to users in the ELIXIR AAI as appropriate

VOMS based flow (user with existing certificate) OFFLINE: User registers DN User request membership to VO Elixir Manager approves request ELIXIR AAI includes user DN in VOMS Web Portal/User Interface ELIXIR AAI 1. Request proxy certificate ELIXIR VOMS 2. Access resources with proxy VOMS configuration EGI resource

VOMS based flow (user without certificate) Generate unique user DN (during user registration) OFFLINE: User request membership to VO ELIXIR Manager approves request ELIXIR AAI includes user DN in VOMS Web Portal/User Interface ELIXIR AAI 1. Request proxy of project 2. Request user proxy to VOMS ELIXIR VOMS 3. Access resources with proxy VOMS configuration From Michal: Generally we don't want to give the certificates directly to the users. Nice example is the fedCloud. User access the VM portal which automatically requests the proxy certificate (using RCAuth.eu and ELIXIR AAI) for the user and the then VM portal uses the certificate on user's behalf. EGI resource Still unknown: what is the method for obtaining the proxy from the ELIXIR AAI? (See email [Perun #177791] PERUN for vo.elixir-europe.org)

EGI CheckIn based flow ELIXIR AAI EGI CheckIn EGI resource OFFLINE: User registers for ELIXIR account User request project-VO membership VO Manager approves request Web Portal/User Interface 3. User redirected to ELIXIR AAI, enters credentials ELIXIR AAI 4. EGI CheckIn requests attributes about the user (projects belonging to) 2. User redirected to EGI CheckIn, selects ELIXIR AAI EGI CheckIn 1. User request access to service 5. EGI CheckIn returns user OIDC claims with user information: User id, user email LoA Everything else (including projects from ELIXIR AAI) EGI resource Resources to map to the local elixir group users rom EGI CheckIn with any claim of the form : urn:mace:egi.eu:elixir-europe.org:*@vo.elixir-europe.org Other ELIXIR projects to define similar claims to be exported to the EGI AAI.