Welcome to HEPNT Gian Piero Siroli, Physics Dept., Univ. of Bologna LAL, HEPiX-HEPNT 2001.

Slides:



Advertisements
Similar presentations
Single Sign-On with GRID Certificates Ernest Artiaga (CERN – IT) GridPP 7 th Collaboration Meeting July 2003 July 2003.
Advertisements

HEP Data Sharing … … and Web Storage services Alberto Pace Information Technology Division.
1.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 1: Introducing Windows Server.
UNIX & W2K A single sign-on solution for a Kerberos V based AFS cell Enrico M.V. Fasanelli & Fulvio Ricciardi I.N.F.N. – Sezione di Lecce.
Password? CLASP Project Update C5 Meeting, 16 June 2000 Denise Heagerty, IT/IS.
WIN.MIT.EDU  Where are we today  Related services  Current enhancements  Some future enhancements  SharePoint  Panel Discussion.
Password?. Project CLASP: Common Login and Access rights across Services Plan
Password?. Project CLASP: Common Login and Access rights across Services Plan
Lesson 18-Internet Architecture. Overview Internet services. Develop a communications architecture. Design a demilitarized zone. Understand network address.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
Chapter 4 Introduction to Active Directory and Account Management
Exporting NICE/NT to other Institutes: Bologna, INFN, CIEMAT Gian Piero Siroli, Dept. of Physics, Univ. of Bologna and INFN HEPNT Days, CERN, Geneva.
Firewall 2 * Essential Network Security Book Slides. IT352 | Network Security |Najwa AlGhamdi 1.
Understanding Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Windows 2000 and Active Directory Services at UQ Scott Sinclair Senior Systems Programmer Software Infrastructure Group
Brian Arkills Software Engineer, LDAP geek, AD bum, Senior Heckler, and Associate Troublemaking Officer State of Windows Services at the UW.
31/10/2000NT Domain - AD Migration - JLab 2000 NT DOMAIN - ACTIVE DIRECTORY MIGRATION Michel Jouvin LAL Orsay
Lesson 17. Domains and Active Directory. Objectives At the end of this Presentation, you will be able to:
Case for Multi-Domain/Forest Model
11 REVIEWING MICROSOFT ACTIVE DIRECTORY CONCEPTS Chapter 1.
Technology Overview. Agenda What’s New and Better in Windows Server 2003? Why Upgrade to Windows Server 2003 ?  From Windows NT 4.0  From Windows 2000.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Designing Active Directory for Security
A detailed look at the Microsoft Windows Infrastructure at UWE including Active Directory (AD), MIIS, Exchange, SMS, IIS, SQL Server, Terminal Services.
16-Mar-01D.P.Kelsey, HTASC report1 HTASC - Report to HEP-CCC David Kelsey, RAL rl.ac.uk 16 March 2001, CERN (
SMS 2003 Deployment and Managing Windows Security Rafal Otto Internet Services Group Department of Information Technology CERN 26 May 2016.
Module 5: Designing a Terminal Services Infrastructure.
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
Designing Authentication for a Microsoft Windows 2000 Network Designing Authentication in a Microsoft Windows 2000 Network Designing Kerberos Authentication.
26-Jun-99D.P.Kelsey, HTASC report1 HTASC - Report to HEP-CCC David Kelsey, RAL rl.ac.uk 26 June 1999, FNAL (
Windows 2000 University of Colorado. Background Limited enterprise services: MIT K5 in labs, modems and some desktops, starting directories now, no identifier.
DFS & Active Directory Joshua Hedges |Brandon Maxfield | Robert Rivera | Will Zilch.
HEPiX-HEPNT 2000 Report Enrico M.V. Fasanelli & Gian Piero Siroli.
Riva Managed Identity Integration for Active Directory and Novell ® GroupWise ® Aldo Zanoni CEO, Managing Director Omni Technology Solutions
W2K and Kerberos at FNAL Jack Mark
1 Windows 2008 Configuring Server Roles and Services.
Scaling NT To The Campus Integrating NT into the MIT Computing Environment Danilo Almeida, MIT.
Identity Management: A Technical Perspective Richard Cissée DAI-Labor; Technische Universität Berlin
15-Apr-1999D.P.Kelsey - HEPNT update - HEPiX/RAL1 HEPNT an update David Kelsey CLRC Rutherford Appleton Lab, UK rl.ac.uk
Secure Networking Windows 2000 Distributed Security Services Sandeep Joshi Group 4.
16-Jun-01D.P.Kelsey, HTASC report1 HTASC - Report to HEP-CCC David Kelsey, RAL rl.ac.uk 16 June 2001, CNAF/INFN/Bologna (
Password? CLASP Project FOCUS Meeting, 12 October 2000 Denise Heagerty, IT/IS.
W2K and Kerberos at FNAL Jack Schmidt Mark Kaletka.
Samba – Good Just Keeps Getting Better The new and not so new features available in Samba, and how they benefit your organization. Copyright 2002 © Dustin.
Single Sign-On across Web Services Ernest Artiaga CERN - OpenLab Security Workshop – April 2004.
Exchange Pilot as a new Messaging infrastructure at CERN Alberto Pace, for the IT/IS group - April 2002
W2K Integration in the Kerberos5 based AFS cell le.infn.it Enrico M. V. Fasanelli I.N.F.N. – Sezione di Lecce Catania,
Module 7: Configuring Terminal Services. Overview Describe how the components of Terminal Services work together Identify new Terminal Services core features.
Integrating Active Directory with eDirectory ™ Using Novell Account Manager Reid Oakes Technical Team Manager Novell, Inc.
Migrating to Windows 2000 Graham Titmus Computer Laboratory.
FROM MIT KERBEROS TO MICROSOFT ACTIVE DIRECTORY The Pennsylvania State University’s move from a lower case MIT Kerberos realm to a Standard Microsoft Active.
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
IN2P3 AD Forest Project Michel Jouvin LAL / IN2P3
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
12-Nov-99D.P.Kelsey, HTASC report1 HTASC - Report to HEP-CCC David Kelsey, RAL rl.ac.uk 12 November 1999, CERN (
Status of W2K at INFN Gian Piero Siroli, Dept. of Physics, Univ. of Bologna and INFN HEPiX-HEPNT 2000, Jefferson Lab.
Password? CLASP Phase 2: Revised Proposal FOCUS, 3 May 2001 Denise Heagerty, IT/IS.
Status of NICE/NT at INFN Gian Piero Siroli, Physics Dept. Univ. of Bologna and INFN HEPiX-HEPNT, SLAC, Oct.99.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Overview of Active Directory Domain Services Lesson 1.
Windows Active Directory – What is it? Definition - Active Directory is a centralized and standardized system that automates network management of user.
Few Highlights from HEPIX/HEPNT Alberto Pace. Warning  This is not a comprehensive report.  See Alan Silverman’s excellent summary if you need this.
Module 2: Implementing an Active Directory Forest and Domain Structure.
L’Oreal USA RSA Access Manager and Federated Identity Manager Kick-Off Meeting March 21 st, 2011.
State of Windows Services at the UW
Goals Introduce the Windows Server 2003 family of operating systems
CLASP Project AAI Workshop, Nov 2000 Denise Heagerty, CERN
Windows Active Directory Environment
Presentation transcript:

Welcome to HEPNT Gian Piero Siroli, Physics Dept., Univ. of Bologna LAL, HEPiX-HEPNT 2001

HEPiX-HEPNT 2001, LALGian Piero Siroli History u Windows 2000 Coordination subgroup created by HTASC/HEPCCC after the disbanding of HEPNT (mid98-mid99) u Meetings u Workshops: HEPNT Oct99 (CERN), joint HEPiX/NT Apr00 (Braunschweig), Oct00 (Jefferson Lab), Apr01 (LAL)

HEPiX-HEPNT 2001, LALGian Piero Siroli Mandate u To investigate and test the new features of Microsoft’s Windows 2000 operating system, with particular emphasis on those issues which may need coordination across HEP u To make recommendation to HTASC/HEPCCC on those areas where a coordinated migration plan is required. These plans should take into account any potential benefits, such as the integration with UNIX and improved access of shared resources across HEP u To share the expertise gained with other HEP windows system managers by organising an open windows 2000 workshop and/or by other appropriate means

HEPiX-HEPNT 2001, LALGian Piero Siroli Windows 2000 deployment u Almost a new op.sys. stable and reliable, scales; initial learning step; currently in deployment phase u Different deployment strategies, difficult inter-lab coordination u Single sign-on over HEP not feasible u HEP-wide forest almost impossible (shared common schema needed) u Recommendation: new W2K domain should be called “win” u Dynamic DNS (DDNS) useful and not necessary; no major interoperability problems with UNIX-based DNS

HEPiX-HEPNT 2001, LALGian Piero Siroli Common authentication u Unification of platform (W2K-UNIX) authentication via Kerberos u Precondition: common account database on UNIX and Windows u Investigations at the very beginning u a password synchronization mechanism between UNIX/AFS and Windows 2000 seems to be easy to implement u starting investigations in building a trust relationship between Kerberos 5 realm (MIT or Heimdal) and W2K AD

HEPiX-HEPNT 2001, LALGian Piero Siroli Security u Local issue for each lab u Access ports being closed u Which services need to be made available outside the lab? Currently Web is considered the primary technology for offering services outside the lab boundaries

HEPiX-HEPNT 2001, LALGian Piero Siroli Wide Area access across labs u Important feature for travelling users and optimized distribution of resources (both data and home directory folders) u Currently FTP only access mechanism; inadequate (FTP being closed and poor integration with Windows desktop) u Other mechanisms available: DFS, VPNs, web access (http or shhtp) have both advantages and disadvantages u No best solution recommended

HEPiX-HEPNT 2001, LALGian Piero Siroli Application support u Applications/tools deployment much better in W2K than previous platforms u Applications must be packaged and configured at the same time u Sharing packages across labs u preconditions and rules might be needed u lab specifics in MST u suggestion: create a common area to exchange a few packages and get some experience. Everybody is invited

HEPiX-HEPNT 2001, LALGian Piero Siroli Future? u W2K HTASC Coordination subgroup initial mandate terminated; very useful to exchange information and share experience u Further future needs for HEP-wide coordination? u UNIX-W2K integration/coexistence (e.g. Kerberos) u Data/home folder/resource sharing mechanisms, security related issues u Any other suggestion? u Agreed that the group should continue focusing on W2K issues; meetings should continue at least twice/year