LCG/EGEE Security Update HEPiX, Fall 2004 BNL, 18 October 2004 David Kelsey CCLRC/RAL, UK

Slides:



Advertisements
Similar presentations
INFSO-RI Enabling Grids for E-sciencE Security (JRA3) Åke Edlund, JRA3 Manager, KTH David Groep, EUGridPMA chair, NIKHEF EGEE 1.
Advertisements

INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
LCSC October The EGEE project: building a grid infrastructure for Europe Bob Jones EGEE Technical Director 4 th Annual Workshop on Linux.
Grid Security in EGEE/LCG ISGC 2005, Taipei, Taiwan 29 April 2005 David Kelsey CCLRC/RAL, UK
30-Jan-03D.P.Kelsey, GridPP Security1 Security GridPP6 30 Jan 2003 Coseners House David Kelsey CLRC/RAL, UK
Authentication Policy David Kelsey CCLRC/RAL 15 April 2004, Dublin
The EU Grid PMA David Kelsey CCLRC/RAL 16 April 2004, Dublin
Grid Trust Fabric TNC 2006, Catania 16 May 2006 David Kelsey CCLRC/RAL, UK
RomeWorkshop on eInfrastructures 9 December LCG Progress on Policies & Coming Challenges Ian Bird IT Division, CERN LCG and EGEE Rome 9 December.
13-May-03D.P.Kelsey, WP8 CA and VO organistion1 CA’s and Experiment (VO) Organisation WP8 Meeting EDG Barcelona, 13 May 2003 David Kelsey CCLRC/RAL, UK.
12-May-03D.P.Kelsey, SCG Online Authentication1 Online Authentication SCG Meeting EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
EGEE ARM-2 – 5 Oct LCG Security Coordination Ian Neilson LCG Security Officer Grid Deployment Group CERN.
GGF12 – 20 Sept LCG Incident Response Ian Neilson LCG Security Officer Grid Deployment Group CERN.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
Security Area in GridPP2 4 Mar 2004 Security Area in GridPP2 “Proforma-2 posts” overview Deliverables – Local Access – Local Usage.
TERENA TF-EMC2 Workshop David Groep,
EGEE is proposed as a project funded by the European Union under contract IST EU eInfrastructure project initiatives FP6-EGEE Fabrizio Gagliardi.
INFSO-RI Enabling Grids for E-sciencE EGEE/LCG Joint Security Policy Group David Kelsey, CCLRC/RAL, UK EGEE.
10-Jun-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 10 June 2003 David Kelsey CCLRC/RAL, UK
Security Policy Update LCG GDB Prague, 4 Apr 2007 David Kelsey CCLRC/RAL
13-Jul-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint LCG/EGEE Security Group) CERN 13 July 2004 David Kelsey CCLRC/RAL,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
9-Sep-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 9 September 2003 David Kelsey CCLRC/RAL, UK
23-Oct-03D.P.Kelsey, LCG Security Update, HEPiX1 LCG Security Update HEPiX-HEPNT, TRIUMF, 23 October 2003 David Kelsey CCLRC/RAL, UK
3-Jul-02D.P.Kelsey, Security1 Security meetings Report to EDG PTB 3 Jul 2002 David Kelsey CLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE External Projects Integration Summary – Trigger for Open Discussion Fotis Karayannis, Joanne.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Linda Cornwall CCLRC (RAL) FP6 Security workshop.
LCG/EGEE Security Operations HEPiX, Fall 2004 BNL, 22 October 2004 David Kelsey CCLRC/RAL, UK
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
Ian Bird LCG Deployment Area Manager & EGEE Operations Manager IT Department, CERN Presentation to HEPiX 22 nd October 2004 LCG Operations.
9-Oct-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) FNAL 9 October 2003 David Kelsey CCLRC/RAL, UK
23-Oct-02D.P.Kelsey, Grid Security, HEPiX, FNAL1 LCG/EDG Security - update and plans HEPiX/HEPNT - FNAL 23 Oct 2002 David Kelsey CLRC/RAL, UK
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
INFSO-RI Enabling Grids for E-sciencE EGEE SA1 in EGEE-II – Overview Ian Bird IT Department CERN, Switzerland EGEE.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Dr Linda Cornwall CCLRC (RAL) FP6 Security workshop.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
Security Operations David Kelsey GridPP Deployment Board 3 Mar 2005
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
INFSO-RI Enabling Grids for E-sciencE An overview of EGEE operations & support procedures Jules Wolfrat SARA.
Last update 29/01/ :01 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD CERN VOMS server deployment LCG Grid Deployment Board
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
EGEE is a project funded by the European Union under contract IST EGEE Summary NA2 Partners April
EGEE is a project funded by the European Union under contract IST Roles & Responsibilities Ian Bird SA1 Manager Cork Meeting, April 2004.
EGEE is a project funded by the European Union under contract IST EGEE Security Åke Edlund Security Head EU IST-FP6 Concertation, 17 th September.
EGEE Project Review Fabrizio Gagliardi EDG-7 30 September 2003 EGEE is proposed as a project funded by the European Union under contract IST
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and JSPG activities David Kelsey CCLRC/RAL.
Security EGEE/SA1 ROC Managers ARM-3 meeting Lyon, 17 March 2005 David Kelsey CCLRC/RAL, UK
EGEE ARM-2 – 5 Oct LCG/EGEE Security Coordination Ian Neilson Grid Deployment Group CERN.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
12-Jun-03D.P.Kelsey, CA meeting1 CA meeting Minimum Requirements CERN, 12 June 2003 David Kelsey CCLRC/RAL, UK
18-May-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) Barcelona 18 May 2004 David Kelsey CCLRC/RAL, UK
15-May-03D.P.Kelsey, SCG Summary1 Security Coord Group (SCG) EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
Last update 13/03/ :11 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD Status of the Task Force for User Registration of LHC Experiment Users
INFSO-RI Enabling Grids for E-sciencE An introduction to EGEE Mike Mineter NeSC Edinburgh
Induction: What is EGEE? –April 26-28, EGEE organisation and procedures John Murison, EGEE Training Team EGEE is funded by the European Union.
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
7-May-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Issues and Planning or Report from the Security Group CERN, 8 May 2003 David Kelsey CCLRC/RAL, UK.
LCG User, Site & VO Registration in EGEE/LCG Bob Cowles OSG Technical Meeting Dec 15-17, 2004 UCSD.
DataGrid Security Wrapup Linda Cornwall 4 th March 2004.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
Bob Jones EGEE Technical Director
David Kelsey CCLRC/RAL, UK
LCG Security Status and Issues
David Kelsey CCLRC/RAL, UK
David Kelsey CCLRC/RAL, UK
Presentation transcript:

LCG/EGEE Security Update HEPiX, Fall 2004 BNL, 18 October 2004 David Kelsey CCLRC/RAL, UK

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX2 Outline Update since October 2003 (Vancouver HEPiX) Introduction Policy Procedures & Operations Technology Future work

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX3 Introduction LCG & EGEE

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX4 LCG today

AHM2004, Nottingham, September The next generation of grids: EGEE Enabling Grids for E-science in Europe Build a large-scale production grid service to: Underpin European science and technology Link with and build on national, regional and international initiatives Foster international cooperation both in the creation and the use of the e-infrastructure Network infrastructure ( GÉANT ) Operations, Support and training Collaboration Pan-European Grid

AHM2004, Nottingham, September EGEE Activities 48 % service activities (Grid Operations, Support and Management, Network Resource Provision) 24 % middleware re-engineering (Quality Assurance, Security, Network Services Development) 28 % networking (Management, Dissemination and Outreach, User Training and Education, Application Identification and Support, Policy and International Cooperation) 32 Million Euros EU funding over 2 years starting 1 st April 2004 Emphasis in EGEE is on operating a production grid and supporting the end-users

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX7 Security Activities in EGEE(LCG) JRA3JRA1 NA4 Middleware Security Group Joint Security Policy Group NA4 Solutions/Recommendations Req. SA1 “Joint Security Policy Group” defines policy and procedures and inputs requirements to MWSG (For LCG/GDB and EGEE/SA1) (Cross Membership of US OSG Sec Team) CA Coordination Security Middleware Applications Operations OSG LCG OSCT

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX8 Security Policy

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX9 LCG Security Policy During 2003/04, the LCG project agreed a first version of its Security Policy –Written by the Joint Security Policy Group –Approved by the Grid Deployment Board/PEB A single common policy for the whole project –But does not override local policies An important step forward for a production Grid The policy –Defines Attitude of the project towards security and availability –Gives Authority for defined actions –Puts Responsibilities on individuals and bodies Now being used by EGEE and (some) national Grids

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX10 LCG Policy Security & Availability Policy Usage Rules Certification Authorities Audit Requirements GOC Guides Incident Response User Registration & VO Management Application Development & Network Admin Guide picture from Ian Neilson New since Oct 2003

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX11 Security Procedures & Operations

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX12 Security Procedures Incident Response –Open Science Grid leading this area –See talks in Friday morning’s Operations session LCG/EGEE Operational Security –Operational Security Coordination Team (OSCT) –Again: see Friday’s talk User Registration & VO Management –Requirements for 4 LHC Experiments Presented at May 2004 (Edinburgh) HEPiX (M.Dimou)

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX13 User Registration and VO Membership Management Requirements document (V2.7) – –approved by GDB in May 2004 Task force created to propose the solution Many discussions with CERN HR, User Office, Experiment Secretariats, VO managers, … Recent Meeting at CERN –15-17 September, / –Technical solution now agreed

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX14 User Registration (1) Every user (4 LHC expts) must register in CERN HR db first –Already true for the majority Advantages of using existing procedures No duplication of effort or personal data –External users (e.g. people never coming to CERN) and short-term users (e.g. external summer students) Need a simple, speedy and robust procedure –Non-VO people e.g.testers/experiment independent people must register in CERN HR (e.g. via LCG/IT) Eventual aim is to use the experiment participation end-date in CERN HR to trigger immediate suspension from the VO

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX15 User Registration (2) VO registration expiry date –Not exceeding 1 year from date of VO registration –Less if institute-contract/CERN HR registration expires before then Personal User Data will only reside in CERN HR There is no automatic membership of VO –User has to complete a form and the VO manager has to approve Authorized personnel at resource centres will have read access to the VO registration info

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX16 User Registration (3) When VO expiry date is reached, the VO membership is immediately suspended –Advance warning will be sent to the user There will be other possible reasons for suspension –E.g. following security problems

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX17 Technical Solution agreed Sep meeting decisions: The VO registration database –Will be VOMRS component from US CMS VOX –VOMRS needs development to meet new requirements (FNAL working on this) –VOMRS manages the groups and roles -> VOMS CERN is working on VOMRS interconnection to the CERN HR DB (Oracle) The dynamic Authorization will be VOMS –Groups and roles Non-LHC VO’s may use the VOMS-admin component (an alternative admin UI) Time to implement not yet agreed –Aiming for early in 2005

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX18 Security Technology

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX19 Authentication: EU Grid PMA CAs  Green: Accredited  Yellow: Recent approvals or still under discussion  Slovenia just approved  Austria & Bulgaria soon? Other Accredited CAs:  DoEGrids (US)  GridCanada  ASCCG (Taiwan)  ArmeSFO (Armenia)  CERN  Russia (HEP)  FNAL Service CA (US)  Israel  Pakistan 27 Accredited CAs “Catch-all” CAs operated by CNRS (for EGEE) US DOE (for LCG) SEE-GRID (for SE Europe)

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX20 AuthZ – VOMS & LCAS VO-VOMS user service authentication & authorization info user cert (long life ) VO-VOMS CA low frequency high frequency host cert (long life ) authz cert (short life) service cert (short life) authz cert (short life) proxy cert (short life) voms-proxy-init crl update registration LCAS

AHM2004, Nottingham, September gLite security Aims at being Modular – add new modules later Agnostic – modules will evolve Standard – start with transport-level security but intend to move to WS-Security when it matures Interoperable - at least for AuthN & AuthZ Applied to Web-services hosted in containers and applications (Apache Axis & Tomcat) as additional modules Security architecture:

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX22 EGEE AuthZ Policy Graphics from Globus Alliance & GGF OGSA-WG Policy comes from many stakeholders

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX23 Future Work Policy –Working on more general policy (with OSG) No longer LCG-specific –EU eInfrastructure Reflection Group (18 Nov 04) Acceptable Use Policy and Authorization for EU eScience Procedures –Operational Security, including Incident Response –User Registration Technology –Authentication Asia/Pacific & Americas PMAs being created Credential Repositories –Authorization – dynamic role-based access control VOMRS & VOMS Local control and policy, e.g. via LCAS/LCMAPS Security requirements, Operational Constraints –Very important to get Site input to operations and middleware development (all feedback is very welcome!)

18-Oct-04David Kelsey, LCG/EGEE Security, HEPiX24 References LCG/EGEE Joint Security Policy Group EGEE JRA3 (Security) Open Science Grid Security EU DataGrid Security LCG Guide to Application, Middleware and Network Security EU eInfrastructure Reflection Group EU Grid PMA (CA coordination) TERENA Tacar (CA repository)