Andrew McNab - GGF Authz - 16 Dec 2003 GGF Authorization work Andrew McNab, University of Manchester

Slides:



Advertisements
Similar presentations
Federated Identity for Grid Architects Tom Scavo NCSA
Advertisements

© 2006 Open Grid Forum Security Area OGF19 Standard All Hands.
29 June 2006 GridSite Andrew McNabwww.gridsite.org VOMS and VOs Andrew McNab University of Manchester.
GT 4 Security Goals & Plans Sam Meder
Thoughts & Ideas on AuthZ Interoperability Christos Kanellopoulos AUTH/GRNET skanct at physics.auth.gr.
VOMS & SAML Valerio Venturi MWSG /6/07. EU project: RIO31844-OMII-EUROPE OMII-Europe OMII-Europe is an EU-funded project which has been established.
Andrew McNab - EDG Access Control - 14 Jan 2003 EU DataGrid security with GSI and Globus Andrew McNab University of Manchester
The GridSite Security Framework Andrew McNab University of Manchester.
Authorization WG Update David Kelsey EU Grid PMA, Copenhagen 27 May 2008.
Authz work in GGF David Chadwick
20 March 2007 VOMS etc Andrew McNabwww.gridsite.org VOMS etc Andrew McNab University of Manchester.
30-Jan-03D.P.Kelsey, GridPP Security1 Security GridPP6 30 Jan 2003 Coseners House David Kelsey CLRC/RAL, UK
BaBarGrid: Some UK developments Roger Barlow Imperial College 13th September 2002.
A Use Case for SAML Extensibility Ashish Patel, France Telecom Paul Madsen, NTT.
EGEE Security Area 13 May 2004 EGEE Security Area Stakeholders JRA3 middleware Architecture What we have for Unix and Java What.
Andrew McNab - GACL - 16 Dec 2003 Grid Access Control Language Andrew McNab, University of Manchester
Security Middleware and VOMS service status Andrew McNab Grid Security Research Fellow University of Manchester.
Andrew McNab - GridPP Security - 24 Feb 2003 GridPP Security Middleware Andrew McNab, University of Manchester
Andrew McNab - SlashGrid, HTTPS, fileGridSite SlashGrid, HTTPS and fileGridSite 30 October 2002 Andrew McNab, University of Manchester
OGSA SEC WG [OGSA= Open Grid Services Architecture] Co-chairs: Nataraj Nagaratnam, IBM, USA Marty Humphrey University of Virginia, USA GGF9.
Andrew McNab - GridSite/G-HTTPS - 17 Feb 2003 GridSite and G-HTTPS update Andrew McNab, University of Manchester
Grid Security work in 2006 Andrew McNab Grid Security Research Fellow University of Manchester.
The GridSite Security System Andrew McNab and Shiv Kaushal University of Manchester.
Apr 30, 20081/11 VO Services Project – Stakeholders’ Meeting Gabriele Garzoglio VO Services Project Stakeholders’ Meeting Apr 30, 2008 Gabriele Garzoglio.
Security Area in GridPP2 4 Mar 2004 Security Area in GridPP2 “Proforma-2 posts” overview Deliverables – Local Access – Local Usage.
SAML support in VOMS Valerio Venturi EGEE JRA1 AH Meeting, Amsterdam 20/23 February 2008.
EU DataGrid (EDG) & GridPP Authorization and Access Control User VOMS C CA 2. certificate dn, ca, key 1. request 3. certificate 4. VOMS cred: VO, groups,
OGSA Security Roadmap Discussion GGF5 – 7/24/02. Outline l Introduction l Architecture Goal l Roadmap Goal l Proposed Specs l Challenges l Next Steps.
EGEE is a project funded by the European Union under contract IST Gap analysis draft v2 Olle Mulmo, David Groep, Joni Hahkala JRA3 Gap, 10.
Andrew McNab - GridSite/EDG/GGF - 29 Sept 2003 GridSite, EDG and GGF Andrew McNab, University of Manchester
Grid Security in a production environment: 4 years of running Andrew McNab University of Manchester.
30-Sep-03D.P.Kelsey, SCG Summary1 Security Co-ordination Group (WP7 SCG) EDG Heidelberg 30 September 2003 David Kelsey CCLRC/RAL, UK
OGF22 25 th February 2008 OGF22 Demo Slides Prof. Richard O. Sinnott Technical Director, National e-Science Centre University of Glasgow, Scotland
GridSite Web Servers for bulk file transfers & storage Andrew McNab Grid Security Research Fellow University of Manchester, UK.
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
INFSO-RI Enabling Grids for E-sciencE LCAS/LCMAPS and WSS Site Access Control boundary conditions David Groep et al. NIKHEF.
Andrew McNab - EDG Access Control - 4 Dec 2002 EDG Access Control and User Management (ie Local Authorisation and Accounts) Andrew McNab, University of.
Andrew McNabSecurity Middleware, GridPP8, 23 Sept 2003Slide 1 Security Middleware Andrew McNab High Energy Physics University of Manchester.
Grid Authorization Landscape and Futures Von Welch NCSA
Authorization GGF-6 Grid Authorization Concepts Proposed work item of Authorization WG Chicago, IL - Oct 15 th 2002 Leon Gommans Advanced Internet.
Rights Management in Globus Data Services Ann Chervenak, ISI/USC Bill Allcock, ANL/UC.
Andrew McNabGrid in 2002, Manchester HEP, 7 Jan 2003Slide 1 Grid Work in 2002 Andrew McNab High Energy Physics University of Manchester.
EMI INFSO-RI Argus Policies in Action Valery Tschopp (SWITCH) on behalf of the Argus PT.
Andrew McNabGESA/Authz, GGF9, 7 Oct 2003Slide 1 Authorization status Andrew McNab High Energy Physics University of Manchester
Security Middleware Andrew McNab University of Manchester.
INFSO-RI Enabling Grids for E-sciencE - II SLCS, VASH, and LCAS/LCMAPS Plugins All-Hands Meeting Helsinki Placi Flury, SWITCH 19.
Ákos FROHNER – DataGrid Security n° 1 Security Group TODO
VOMS Attribute Authorities Michael Helm ESnet/LBNL 23 Feb 2007.
AuthZ WG Conceptual Grid Authorization Framework document Presentation of Chapter 2 GGF8 Seattle June 25th 2003 Document AID 222 draft-ggf-authz-framework pdf.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks OpenSAML extension library and API to support.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Study on Authorization Christoph Witzig,
11-May-01D.P.Kelsey, Security Update1 GRID Security Update David Kelsey CLRC/RAL, UK
DataGrid Security Wrapup Linda Cornwall 4 th March 2004.
EMI is partially funded by the European Commission under Grant Agreement RI Argus Policies Tutorial Valery Tschopp (SWITCH) – Argus Product Team.
OGSA Attributes: Requirements, Definitions, and SAML Profile Abstract This document specifies elements and vocabulary for expressing attribute assertions.
GGF - © Birds of a Feather - Policy Architecture Working Group.
GridSite status Andrew McNab University of Manchester.
INFSO-RI Enabling Grids for E-sciencE GUMS vs. LCMAPS Oscar Koeroo.
Virtual Organisations and the NGS Mike Jones Research Computing Services e-Science & “The Grid” for Bio/Health Informaticians, IT January 2008.
Trygve Aspelien and Yuri Demchenko
Obligations in the OGSA SAML Authorization Service Interface
David Kelsey CCLRC/RAL, UK
OGSA-WG Basic Profile Session #1 Security
Third Party Transfers & Attribute URI ideas
GGF8 Authorization Frameworks and Mechanisms Working Group
A gLite Authorization Framework
Grid Security Jinny Chien Academia Sinica Grid Computing.
University of Virginia, USA GGF9, Chicago, Illinois, US
OGF 21 Seattle Washington
GridShib: Grid/Shibboleth Integration Update GGF 18 Shibboleth Developers BoF September 10-11, 2006 Washington, DC Tom Barton, Tim Freeman, Kate Keahey,
Presentation transcript:

Andrew McNab - GGF Authz - 16 Dec 2003 GGF Authorization work Andrew McNab, University of Manchester

Andrew McNab - GGF Authz - 16 Dec 2003 GridPP / EDG / WP6 Outline u Authorization Frameworks WG u Site Authentication, Authorization and Accounting RG u OGSA Authorization WG u VOMS / XACML / GACL

Andrew McNab - GGF Authz - 16 Dec 2003 GridPP / EDG / WP6 Authorization Frameworks and Mechanisms WG u Authz WG set out the terminology and models (push / pull / agent) used in later groups. u Glossary n Brief definition of terms used in Authorization n For each term, includes reference to document that defines it (RFCs, WS-xx etc) u Frameworks document n Discussion of authorization models and classification of existing systems (VOMS etc) with those models u Documents at: n

Andrew McNab - GGF Authz - 16 Dec 2003 GridPP / EDG / WP6 Site Authentication, Authorization and Accounting Requirements RG u One document: n “Grid Authentication Authorization and Accounting Requirements Research Document” u Many, detailed requirements have been captured by this process: n For example is “Authorization policies may change over time. Mechanisms to manage policy specification across the sphere of control of the resource, site, VO, application manager, and user should be provided.“ u Document at: n

Andrew McNab - GGF Authz - 16 Dec 2003 GridPP / EDG / WP6 OGSA-Authz WG in GGF u Attribute format/structure document n Draft document now in mature state after much discussion n Defines vocabulary and profiles for SAML and X.509 attribute certs n (This would benefit from more VOMS input too!) u Assertion protocol document n Defines how to use SAML in authorization callouts u Requirements document n Simple use cases and authorization models (push / pull) u Expression n Assumed will be XACML, but this document not started yet. u Documents at: n

Andrew McNab - GGF Authz - 16 Dec 2003 GridPP / EDG / WP6 XACML subject matching <AttributeValue DataType=“ >John< /AttributeValue> u Some other data types: n urn:oasis:names:tc:xacml:1.0:data-type:x500Name n n urn:oasis:names:tc:xacml:1.0:subject:authn-locality:ip-address u Obviously could add u But need a unique string representation of VOMS attributes too

Andrew McNab - GGF Authz - 16 Dec 2003 GridPP / EDG / WP6 Suggestions for VOMS representation u Use the Fully Qualified Attribute Name (FQAN) u This makes the string opaque - this means repeating parent groups n /VO.name/group n /VO.name/group/subgroup n (VOMS attribute certificates already do this anyway) u Can then use simple string matching n (maybe even regular expressions for wildcard enthusiasts) u But may still want to define a VOMS FQAN data type so can do syntax checking in any validation stage?

Andrew McNab - GGF Authz - 16 Dec 2003 GridPP / EDG / WP6 GACL vs XACML? /vo.org/group <AttributeValue DataType=“ >/vo.org/group/Role=admin< /AttributeValue>

Andrew McNab - GGF Authz - 16 Dec 2003 GridPP / EDG / WP6 Summary u Several relevant documents have been produced by original GGF authorization groups u Very relevant ongoing work in OGSA-Authz n especially in Attribute format document u XACML document in OGSA-Authz not started n some ideas for how to migrate from GACL to XACML