9-May-02D.P.Kelsey, Security Plans, GridPP41 Security: Plans 9 May 2002 GridPP4 meeting, Manchester David Kelsey CLRC/RAL, UK

Slides:



Advertisements
Similar presentations
24-May-01D.P.Kelsey, GridPP WG E: Security1 GridPP Work Group E Security Development David Kelsey CLRC/RAL, UK
Advertisements

5-Dec-02D.P.Kelsey, GridPP Security1 GridPP Security UK Security Workshop 5-6 Dec 2002, NeSC David Kelsey CLRC/RAL, UK
22-Apr-02D.P.Kelsey, Security, UKHEP Sysman1 Grid Security 22 Apr 2002 UK HEP Sysman Meeting David Kelsey CLRC/RAL, UK
Policy Based Dynamic Negotiation for Grid Services Authorization Infolunch, L3S Research Center Hannover, 29 th Jun Ionut Constandache Daniel Olmedilla.
MyProxy: A Multi-Purpose Grid Authentication Service
GRID Security Infrastructure: Overview and problems PKI-COORD Meeting, Amsterdam November 26, 2001 Yuri Demchenko.
GSI – Grid Security Infrastructure and the EU DataGrid Authentication Infrastructure For the EDG CACG: David Groep.
Military Technical Academy Bucharest, 2006 GRID SECURITY INFRASTRUCTURE (GSI) - Globus Toolkit - ADINA RIPOSAN Department of Applied Informatics.
Andrew McNab - EDG Access Control - 14 Jan 2003 EU DataGrid security with GSI and Globus Andrew McNab University of Manchester
Open Science Grid Use of PKI: Wishing it was easy A brief and incomplete introduction. Doug Olson, LBNL PKI Workshop, NIST 5 April
The Community Authorisation Service – CAS Dr Steven Newhouse Technical Director London e-Science Centre Department of Computing, Imperial College London.
5-Sep-02D.P.Kelsey, Security Summary, Budapest1 WP6/7 Security Summary Budapest 5 Sep 2002 David Kelsey CLRC/RAL, UK
Authorization Working Group Report WP6 Meeting 5 March 2002, Paris.
A conceptual model of grid resources and services Authors: Sergio Andreozzi Massimo Sgaravatto Cristina Vistoli Presenter: Sergio Andreozzi INFN-CNAF Bologna.
Dorian Grid Identity Management and Federation Dialogue Workshop II Edinburgh, Scotland February 9-10, 2006 Stephen Langella Department.
DGC Paris Community Authorization Service (CAS) and EDG Presentation by the Globus CAS team & Peter Kunszt, WP2.
Security NeSC Training Team International Summer School for Grid Computing, Vico Equense,
Open Science Grid Use of PKI: Wishing it was easy A brief and incomplete introduction. Doug Olson, LBNL PKI Workshop, NIST 5 April 2006.
30-Jan-03D.P.Kelsey, GridPP Security1 Security GridPP6 30 Jan 2003 Coseners House David Kelsey CLRC/RAL, UK
Authentication Policy David Kelsey CCLRC/RAL 15 April 2004, Dublin
Security Mechanisms The European DataGrid Project Team
12-May-03D.P.Kelsey, SCG Online Authentication1 Online Authentication SCG Meeting EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
Grid Security Issues Shelestov Andrii Space Research Institute NASU-NSAU, Ukraine.
JSPG: User-level Accounting Data Policy David Kelsey, CCLRC/RAL, UK LCG GDB Meeting, Rome, 5 April 2006.
National Computational Science National Center for Supercomputing Applications National Computational Science NCSA-IPG Collaboration Projects Overview.
EU DataGrid (EDG) & GridPP Authorization and Access Control User VOMS C CA 2. certificate dn, ca, key 1. request 3. certificate 4. VOMS cred: VO, groups,
23-Oct-03D.P.Kelsey, LCG Security Update, HEPiX1 LCG Security Update HEPiX-HEPNT, TRIUMF, 23 October 2003 David Kelsey CCLRC/RAL, UK
3-Nov-00D.P.Kelsey, HEPiX, JLAB1 Certificates for DataGRID David Kelsey CLRC/RAL, UK
Ákos FROHNER – DataGrid Security n° 1 Security Group D7.6 Design Ideas
10-May-01D.P.Kelsey, Security Workshop Summary1 DataGrid Security Workshop 29/30 March 2001 SUMMARY David Kelsey CLRC/RAL, UK
Security in DataGrid1 Security in DataGrid 12 Mar 2002 TERENA GRID-AN BoF David Groep NIKHEF, Amsterdam based on a presentation by David Kelsey.
3-Jul-02D.P.Kelsey, Security1 Security meetings Report to EDG PTB 3 Jul 2002 David Kelsey CLRC/RAL, UK
Security Mechanisms The European DataGrid Project Team
Oxford University e-Science Centre 1 Managing Access 4 Dec Managing Access to Resources on the Grid 4 December 2002.
User Management: Authentication & Authorization on the NorduGrid Balázs Kónya, AndersWäänänen 3 rd NorduGrid Workshop, 23 May, 2002 Helsinki.
National Computational Science National Center for Supercomputing Applications National Computational Science GSI Online Credential Retrieval Requirements.
23-Oct-02D.P.Kelsey, Grid Security, HEPiX, FNAL1 LCG/EDG Security - update and plans HEPiX/HEPNT - FNAL 23 Oct 2002 David Kelsey CLRC/RAL, UK
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
Andrew McNab - EDG Access Control - 4 Dec 2002 EDG Access Control and User Management (ie Local Authorisation and Accounts) Andrew McNab, University of.
VO management: Progress since Chicago Workshop Vincenzo Ciaschini 23/5/2002 CNAF – Bologna.
Andrew McNabSecurity Middleware, GridPP8, 23 Sept 2003Slide 1 Security Middleware Andrew McNab High Energy Physics University of Manchester.
Authorisation, Authentication and Security Guy Warner NeSC Training Team Induction to Grid Computing and the EGEE Project, Vilnius,
2-Sep-02D.P.Kelsey, WP6 CA, Budapest1 WP6 CA report Budapest 2 Sep 2002 David Kelsey CLRC/RAL, UK
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
1 AHM, 2–4 Sept 2003 e-Science Centre GRID Authorization Framework for CCLRC Data Portal Ananta Manandhar.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
11-Dec-00D.P.Kelsey, Certificates, WP6 meeting, Milan1 Certificates for DataGrid Testbed0 David Kelsey CLRC/RAL, UK
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
12-Jun-03D.P.Kelsey, CA meeting1 CA meeting Minimum Requirements CERN, 12 June 2003 David Kelsey CCLRC/RAL, UK
WP7 Security Coordination 23/24 Jan 2002 David Kelsey CLRC/RAL, UK
The GRIDS Center, part of the NSF Middleware Initiative Grid Security Overview presented by Von Welch National Center for Supercomputing.
15-May-03D.P.Kelsey, SCG Summary1 Security Coord Group (SCG) EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
10-May-01D.P.Kelsey, WP6 Security1 Certificates/Authorisation for DataGrid Testbeds David Kelsey CLRC/RAL, UK
7-May-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Issues and Planning or Report from the Security Group CERN, 8 May 2003 David Kelsey CCLRC/RAL, UK.
11-May-01D.P.Kelsey, Security Update1 GRID Security Update David Kelsey CLRC/RAL, UK
Current Globus Developments Jennifer Schopf, ANL.
DataGrid Security Wrapup Linda Cornwall 4 th March 2004.
9-Jul-02D.P.Kelsey, DataGrid Security1 EU DataGrid Security 9 July 2002 UK Security Task Force Meeting #2 David Kelsey CLRC/RAL, UK
Security and Delegation The Certificate Perspective Jens Jensen Rutherford Appleton Laboratory Workshop at NIKHEF, 27 April 2010.
Overview of the New Security Model Akos Frohner (CERN) WP8 Meeting VI DataGRID Conference Barcelone, May 2003.
7-Mar-01D.P.Kelsey, User access, WP6, Amsterdam1 WP6: GRID mapfiles and Users access policy David Kelsey CLRC/RAL, UK
David Kelsey CLRC/RAL, UK
CRC exercises Not happy with the way the document for testbed architecture is progressing More a collection of contributions from the mware groups rather.
Update on EDG Security (VOMS)
Grid Security M. Jouvin / C. Loomis (LAL-Orsay)
The GENIUS Security Services
Presentation transcript:

9-May-02D.P.Kelsey, Security Plans, GridPP41 Security: Plans 9 May 2002 GridPP4 meeting, Manchester David Kelsey CLRC/RAL, UK

9-May-02D.P.Kelsey, Security Plans, GridPP42 Overview Security Technology/Plans in (some) Grid projects –Globus –DataGrid (EDG) –PPDG –DataTAG/iVGDL/HICB Security Development/Issues –Authentication –Authorisation –Grid Deployment

9-May-02D.P.Kelsey, Security Plans, GridPP43 Grid Security Technology/Plans

9-May-02D.P.Kelsey, Security Plans, GridPP44 Globus Grid Security Infrastructure (GSI) today PKI (X.509 certificates) Users, hosts and services are authenticated (both directions) Single sign-on –Delegation via Proxy credential (limited lifetime) Authorisation via “Grid Mapfile” –Maps certificate DN to local user (Unix, Kerberos) –Authorisation via local security mechanisms Next 4 Slides shown by Bill Allcock (ANL) in Paris DataGrid meeting (8 Mar 02)

9-May-02D.P.Kelsey, Security Plans, GridPP45 Ongoing/Future GSI Work Protection against compromised resources –Restricted delegation, smartcards Standardization –Current certificates are not compliant with standards in front of GGF/IETF so will need to change. Scalability in numbers of users & resources –Credential management –Online credential repositories (“MyProxy”) –Account management Authorization –Policy languages –Community authorization

9-May-02D.P.Kelsey, Security Plans, GridPP46 Security Standardization Based on existing standards: –SSL/TLS, X.509 & CA, GSS-API Standards Documents in Progress –draft-ggf-gss-extensions-04.txt Being considered by GGF GSI working group. Not yet submitted to IETF. Credential import/export, delegation at any time in either direction, restricted delegation, better mapping of GSS to TLS (SSL) –draft-ietf-pkix-proxy-01.txt Being considered by IETF PKIX working group / GGF GSI working group Defines proxy certificate format, including restricted rights and delegation tracing –draft-ietf-tls-delegation-01.txt Being considered by IETF TLS working group / GGF GSI working group Defines how to remotely delegate an X.509 Proxy Certificate using extensions to the TLS (SSL) protocol

9-May-02D.P.Kelsey, Security Plans, GridPP47 Community Authorization Service Question: How does a large community grant its users access to a large set of resources? –Should minimize burden on both the users and resource providers Community Authorization Service (CAS) –Community negotiates access to resources –Resource outsources fine-grain authorization to CAS –Resource only knows about “CAS user” credential CAS handles user registration, group membership… –User who wants access to resource asks CAS for a capability credential Restricted proxy of the “CAS user” cred., checked by resource

9-May-02D.P.Kelsey, Security Plans, GridPP48 CAS 1. CAS request, with resource names and operations Community Authorization Service Does the collective policy authorize this request for this user? user/group membership resource/collective membership collective policy information Resource Is this request authorized for the CAS? Is this request authorized by the capability? local policy information 4. Resource reply User 3. Resource request, authenticated with capability 2. CAS reply, with and resource CA info capability

9-May-02D.P.Kelsey, Security Plans, GridPP49 DataGrid - Authentication 11 DataGrid (EDG) National Certificate Authorities –includes Registration Authorities – check identity CNRS (France) acts as “catch-all” CA Matrix of “Trust” (work ongoing) – much work! –WP6 CA Mgrs check each other against list of minimum requirements Started work on cross-Authentication between Grid projects –USA and CrossGrid

9-May-02D.P.Kelsey, Security Plans, GridPP410 EDG Authorisation grid-mapfile generation o=testbed, dc=eu-datagrid, dc=org CN=Franz Elmer ou=People CN=John Smith mkgridmap grid-mapfile VO Directory “Authorization Directory” CN=Mario Rossi o=xyz, dc=eu-datagrid, dc=org CN=Franz ElmerCN=John Smith Authentication Certificate ou=Peopleou=Testbed1ou=??? local usersban list

9-May-02D.P.Kelsey, Security Plans, GridPP411 PPDG Using Globus GSI US DOE Science Grid CA now in operation –Working on “trust” of EDG CA’s Download files to include EDG CA details –PPDG work in this area likely to be accepted by GriPhyN and iVDGL (April meeting) Authorisation –DataGrid VO LDAP system/tools –Globus CAS “Grid Site AAA” project (new proposal) - extension to PPDG –Examine/evaluate the impact of GSI on local site security –An important contribution – not yet tackled by DataGrid

9-May-02D.P.Kelsey, Security Plans, GridPP412 DataTAG/iVDGL/HICB HICB = “HENP Intergrid Collaboration Board” Transatlantic Testbed(s) –Interoperability essential for HEP applications! Cross project Authentication –US DOE SciGrid CA already “trusted” by EDG –US projects working on “trust” of EDG CA’s Cross project Authorisation –DataTAG WP4 has resources to work in this area

9-May-02D.P.Kelsey, Security Plans, GridPP413 EDG Security Development/Issues

9-May-02D.P.Kelsey, Security Plans, GridPP414 EDG security 4 Groups –WP6 CA, WP6 Auth, WP7 Security Co-ord (SCG) –ATF: Akos Frohner represents SCG Security Workshop – CERN, 17 th May 2002 –Authorisation plans for TB2 and beyond –Co-ordination of middleware security development –Is the design/architecture secure? D7.5 (Requirements and TB1) – M15 document D7.6 (Security design and TB2) – M25 document

9-May-02D.P.Kelsey, Security Plans, GridPP415 Authentication issues Don’t mix Authentication and Authorisation GSI/PKI issues –Management of private keys and update of revocation lists –Restricted delegation, credential repository, renewal,… How to define list of “trusted” CA’s? –Audit of CA procedures – 3 rd party? –GGF GridCP working group important here –Will sites “trust” the technology and procedures? Scaling problems - how many CA’s can we cope with? –Or should the experiments issue Authentication certs? –Or use Kerberos at the site and generate certs online Authorisation is where the real identity checks need to be made –We should avoid heavy-weight Authentication –Is MS.NET passport good enough?

9-May-02D.P.Kelsey, Security Plans, GridPP416 Authorisation issues (2) We need more functionality –“Dynamic policy-based Access control” –Users with more than one allowed role –Move away from Unix uid based security? (and grid mapfile?) –One mechanism for all Grid services (and callable from) Users may belong to multiple VO’s –Authorisation may need to be based on “joins” The development of new technology will take some years Global vs Local authorisation mechanisms –need to negotiate policy – Global/VO/Local

9-May-02D.P.Kelsey, Security Plans, GridPP417 DataGrid Authorisation Future plans (as of March 2002) Improve existing VO LDAP system –Better VO Directory management –Support of replicas of VO Directories –Users belonging to more than one VO can choose –Support for users’ attributes in the VO Directories e.g. the AUP signing information (with expiration date...) Evaluation of Globus CAS (see before) and PERMIS –n.b. CAS alpha – only for GridFTP – funded project) –Policy-based (XML) Role-based Access control Standards based PMI using Attribute certificates

9-May-02D.P.Kelsey, Security Plans, GridPP418 DataGrid Authorisation(2) Recent discussions following 1 st alpha release CAS Problems with Globus CAS –Resource ACL’s all stored centrally in CAS –CAS gives a “yes”/“no” answer to request for access –Needs modification to application EDG proposal (to be discussed next week) –ACL’s LOCAL to resource (scaling, consistency) –CAS acts as a VO membership service (and no ACL’s) Member of VO, group, role –Returns certificate with “capability” Format under discussion (XML vs list of DN’s) How to issue service certificates? –From national CA or signed by Host certificate

9-May-02D.P.Kelsey, Security Plans, GridPP419 Issues – Deployment Site legal issues – user single signing VO’s need to manage their members and sites/resource providers negotiate with VO’s –Only system which will scale Sites cannot manage large number of Grid users –Not just a technical problem! –Must develop procedures to allow this to happen –VO/experiments not used to managing resources –Will Computer Centres give up full control?

9-May-02D.P.Kelsey, Security Plans, GridPP420 Control via Restricted Delegation Will Computer Centres give up full control? Today –Computer centres register users (lots of rules and checks) but then allow them to do almost anything! In the GRID future –Computer centres will register VO’s VO’s manage their users –“Trust” established between VO’s and Sites –The applications will be tightly controlled Using e.g. Community restricted delegation and signed apps –The actual user does not matter (but must have audit trail) Control the “What” and not the “Who”