Www.egi.eu EGI-InSPIRE RI-261323 EGI-InSPIRE www.egi.eu EGI-InSPIRE RI-261323 Policy Issues for Identity Management (and other attributes) EGI Technical.

Slides:



Advertisements
Similar presentations
National Institute of Advanced Industrial Science and Technology Asia Pacific Grid PMA Yoshio Tanaka APGrid PMA, Chair Grid Technology Research Center,
Advertisements

2 nd APGrid PMA F2F Meeting Osaka University Convention Center October 15 09: :20 # Participants: 26.
Usage of PGP in TACAR 19th OGF Meeting Chapel Hill, USA February 1, 2007 Licia Florio Project Development Officer
Updates of the APGrid PMA Catania March 3, 2009 Yoshio Tanaka APGridPMA Chair, AIST, Japan.
TAGPMA Update OGF28, 15 March 2010 David Kelsey Slides from Roger Impey With some recent updates from Scott Rea.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Grid Computing in Higher Education (Scott Rea) EDUCAUSE PKI Deployment Forum Madison, WI - April 15, 2008.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI - Identity Management Steven Newhouse Director, EGI.eu Federated Identity.
Authorization WG Update David Kelsey EU Grid PMA, Copenhagen 27 May 2008.
4 th APGrid PMA F2F Meeting Academia Sinica, Taipei, Taiwan April 8, 2008 Agendahttp:// Call for note takers!
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
2 nd APGrid PMA F2F Meeting Osaka University Convention Center October 15 Wireless LAN SSID: PRAGMA11 Wep key: PRAGMA11JAPAN.
NRENs supporting Grids using current Grid technology TERENA NREN-GRID Workshop Amsterdam Milan Sova CESNET.
Authentication Policy David Kelsey CCLRC/RAL 15 April 2004, Dublin
The EU Grid PMA David Kelsey CCLRC/RAL 16 April 2004, Dublin
Updates from the EUGridPMA David Groep, Oct 11 th, 2011.
Grid Trust Fabric TNC 2006, Catania 16 May 2006 David Kelsey CCLRC/RAL, UK
Updates from the EUGridPMA David Groep, Apr 8 nd, 2008.
Updates of APGrid PMA 22 June, Members (15 + 1) 15 Accredited CAs AIST (JP) APAC (AU) ASGC (TW) CNIC (CN), SDG IGCA (IN) IHEP (CN) KEK (JP) KISTI.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
GRID middleware and security, the missing bits David Kelsey TAC, Malaga 8 Jun 2009.
5 th APGrid PMA Meeting An Update from the TAGPMA Vinod Rebello Taipei, Taiwan 20th April 2009 The Americas Grid Policy Management Authority.
CAOPS-IGTF Session An Update from the TAGPMA Vinod Rebello given by Scott Rea OGF 25, Catania, Italy March 2, 2009 The Americas Grid Policy Management.
TERENA TF-EMC2 Workshop David Groep,
Updates from the EUGridPMA David Groep, July 16 st, 2007.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay OSG Security Officer.
TAGPMA & the Bridge WG (Scott Rea – Dartmouth College) Internet2 Member Meeting, Dec 2006 PKI Activities and Applications Update - Chicago, IL.
European Grid Policy Management Authority. Event - 2/total Speaker Name – Coverage of the EUGridPMA Green: Countries with an accredited.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
Federating the Grid David Kelsey TNC2010, Vilnius 2 Jun 2010.
International Grid Trust Federation Session GGF 20 Manchester, UK Wednesday, May CAOPS-WG session #2.
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
The Americas Grid Policy Management Authority (TAGPMA) Derek Simmel, TAGPMA Chair June 23, 2015.
E-science grid facility for Europe and Latin America Task TSA1.3 - Authentication Services and Policies Acheivements Jacques Alves da Silva.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
Updates from the EUGridPMA David Groep, May 9 st, 2007.
NRENs, Grids and Integrated AAI In Search For the Utopian Solution Christos Kanellopoulos AUTH/GRNET October 17 th, 2005 skanct at physics.auth.gr 2nd.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
INFSO-RI Enabling Grids for E-sciencE Security Summary Åke Edlund, JRA3 4 th EGEE Conference Pisa, Italy 28 th October 2005.
Opening Remarks and Updates of the APGrid PMA 5 th APGridPMA September 16, 2008 Yoshio Tanaka APGridPMA Chair, AIST, Japan.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
TAGPMA Update Taipei, 8 March 2010 David Kelsey Slides from Roger Impey As shown at EUGridPMA, Dublin, 18 Jan 2010.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Update of APGridPMA APGridPMA Meeting Academia Sinica, Taiwan 22 March,
APGridPMA Update Eric Yen APGridPMA August, 2014.
The Americas Grid Policy Management Authority TAGPMA Update Derek Simmel 35 th EUGridPMA Meeting Amsterdam, Netherlands.
Summary of Poznan EUGridPMA32 September EUGridPMA Poznan 2014 meeting – 2 David Groep – Welcome back at PSNC.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Enabling SSO capabilities in the EGI Cloud services Peter Solagna – EGI.eu.
15 th EUGridPMA Plenary Meeting Update from the TAGPMA Vinod Rebello Nicosia, Cyprus January 26 – 28, 2009 The Americas Grid Policy Management Authority.
Update of APGridPMA Eric Yen 25 th EUGridPMA & IGTF All Hands Meeting KIT, Germany 7 May, 2012.
The Americas Grid Policy Management Authority TAGPMA Update Derek Simmel (delivered by David [Groep|Kelsey]) 31 th EUGridPMA Meeting Tartu, Estonia May.
Welcome to Amsterdam EUGridPMA35 September EUGridPMA Amsterdam 2015 meeting – 2 David Groep – Welcome back in Amsterdam.
14 th EUGridPMA Meeting Update from TAGPMA Jim Basney Lisbon, Portugual October 6-8, 2008 The Americas Grid Policy Management Authority.
The Americas Grid Policy Management Authority TAGPMA Update Derek Simmel 27 th EUGridPMA Meeting Rome, Italy January 14-16, 2013.
APGridPMA Update Eric Yen 35 th Amsterdam, NL September 7, 2015.
EGI-InSPIRE RI EGI (IGTF Liaison Function) EGI-InSPIRE RI IGTF & EUGridPMA status update SHA-2 – and more (David Groep,
An Update from the TAGPMA Scott Rea EuGridPMA Mtg, Berlin, DE Sept 13, 2009 The Americas Grid Policy Management Authority.
Updates of APGrid PMA 18 th EUGridPMA Meeting 18 th EUGridPMA Meeting 18 January, 2010 Eric Yen ASGCCA Taiwan.
Updates from the EUGridPMA David Groep, Oct 17 st, 2007.
The Americas Grid Policy Management Authority TAGPMA Update Derek Simmel, Scott Rea
16 th EUGridPMA Meeting An Update from the TAGPMA Vinod Rebello Zurich, Switzerland 11th May 2009 The Americas Grid Policy Management Authority.
TAGPMA Update Riga, 19 April 2010 David Kelsey Input from Roger Impey & Scott Rea.
IGTF in 10 years enabling the interoperable global trust federation Nikhef, Amsterdam supported the Dutch national e-Infrastructure funded and coordinated.
EUGridPMA CAOPS-WG and IGTF Issues March 2013 Charlottesville, VA, USA David Groep, Nikhef, EUGridPMA, and EGI.
Grids & PKI: TAGPMA & Bridges (Scott Rea – Dartmouth College) Internet2 Member Meeting, Dec 2006 PKI Implementers Workshop - Chicago, IL.
EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.
EUGridPMA 41 and IGTF All-Hands Meeting
Presentation transcript:

EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Policy Issues for Identity Management (and other attributes) EGI Technical Forum (Sep 2010) NRENs & Grids workshop David Kelsey

EGI-InSPIRE RI Outline Identity Management for Grids The Grid security model - history The PMA approach (Some) Lessons learned Recent developments How can Grids and NRENs/Federations work together? 15 Sep 2010 Kelsey/Policy for Identity Management2

EGI-InSPIRE RI The Grid security model Started to build an X.509 PKI in 2001 –The only feasible solution at the time –EU DataGrid, CrossGrid, LCG, EGEE, USA, Asia... Single electronic ID to be used everywhere –All Grids, All VOs (needs Trust) Single registration at VO (AuthN independent) Single Login (per session) –Require (identity) Delegation AuthZ attributes come from a VO authority Shared security policies (JSPG -> EGI SPG) 15 Sep Kelsey/Policy for Identity Management

EGI-InSPIRE RI The PMA model Policy Management Authority –Started as “The CA Coordination Group” – and already global in scope EUGridPMA started in 2004 International Grid Trust Federation (IGTF) – Oct 2005 –3 PMAs (EU, Asia and Americas) Minimum standards for operating a CA –And the various Registration Authorities Peer review (accreditation) by other CA operators PMAs include Relying Parties (important aspect) Regular self audit and peer review 15 Sep Kelsey/Policy for Identity Management

OGF28 CAOPS/IGTF – Mar David Groep – Geographical coverage of the EUGridPMA  25 of 27 EU member states (all except LU, MT)  +AM, CH, HR, IL, IR, IS, MA, ME, MK, NO, PK, RO, RS, RU, TR, UA, SEE-GRID + CERN (int), DoEGrids(US)* Pending or in progress  SY, ZA, SN

6 TAGPMA Membership ANSP - Brazil NRC – Canada ESnet (DOEGrids) – USA EELA – International Fermi National Accelerator Laboratory - USA HEBCA/USHER/Dartmouth College – USA IBDS (ANSP) - Brazil WLCG – International NCSA – USA NCSA CILogon NERSC – USA NICS UT/ORNL– USA NIH Dorian - USA Open Science Grid – International Purdue University – USA REUNA – Chile San Diego Supercomputer Center – USA SENAMHI – Peru TACC – USA TeraGrid (PSC) – USA Texas High Energy Grid – USA University of Virginia – USA UFF – Brazil ULA – Venezuela UNAM – Mexico UNIANDES - Colombia UNLP – Argentina IGTF Accredited CA Operators CA Accreditation in progress Interested in accreditation Relying Party

APGridPMA Members (15 + 1) 15 Accredited CAs AIST (JP) APAC (AU) ASGC (TW) CNIC (CN), SDG IGCA (IN) IHEP (CN) KEK (JP) KISTI (KR) NAREGI (JP) NCHC (TW) NECTEC (TH) NGO/Netrust (SG) PRAGMA-UCSD (US) HKU (HK) Mongolia - under accreditation Coverage by RAs Philippine, Vietnam, Malaysia, Indonesia, New Zealand & Sri Lanka (soon) CA: 9 Countries RA: + 6 Countries New: +1 Country

EGI-InSPIRE RI (some) Lessons learned Grids multi-national right from the start –And meeting needs of many communities Impossible to agree to a single root CA Which level of assurance should we aim for? –But had to satisfy e.g. Life Sciences Decided on one level with face-to-face identity vetting with photo ID (like NIST level 2) No way we could use bilateral contracts between IDPs and relying parties –Trust must come from the IGTF & Grid sec policies 15 Sep Kelsey/Policy for Identity Management

EGI-InSPIRE RI Recent work Scale-up by building on other Identity Management systems Does not make sense to duplicate work done by others –Identity is best managed by the home institute “Member Integrated Credential Services” and “Short-Lived Credential Services” issue Grid certificates on the basis of other well-managed IDPs –Kerberos, Active Directory, Academic federations, Sep 2010 Kelsey/Policy for Identity Management9

EGI-InSPIRE RI Policy issues - federations E.g. New TERENA eScience Personal Certificate Service –Issues Grid certificates on basis of membership of national federation IGTF can no longer audit all identity vetting processes and RAs We need to be sure that the “Level of Assurance” is as expected –Addressed by contract TERENA/NREN/Inst 15 Sep 2010 Kelsey/Policy for Identity Management10

EGI-InSPIRE RI Other attributes? Identity best managed by Home Institute Authorisation Attributes (VO groups, roles, rights...) must be managed by the appropriate application community (VRC) Attributes need to come from multiple authorities and then should be “merged” All-round Trust is needed Standards are needed for AuthZ attributes too (work started) 15 Sep 2010 Kelsey/Policy for Identity Management11

EGI-InSPIRE RI NRENs & Grids? Or “Academic Federations” and “Grids” Some personal thoughts We should encourage more Grid participation in the Federations activities (e.g.“REFEDS”) –Co-location of meetings in Prague May 2011 We could jointly work on best practices for Registration Authorities (identity management) More work also required in: –LoA: should IGTF align with NIST ? – merging attributes, audit procedures 15 Sep Kelsey/Policy for Identity Management

EGI-InSPIRE RI Questions? 15 Sep 2010 Kelsey/Policy for Identity Management13

EGI-InSPIRE RI Links EUGridPMA IGTF REFEDS EGI SPG 15 Sep Kelsey/Policy for Identity Management