10-Jun-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 10 June 2003 David Kelsey CCLRC/RAL, UK

Slides:



Advertisements
Similar presentations
22-Apr-02D.P.Kelsey, Security, UKHEP Sysman1 Grid Security 22 Apr 2002 UK HEP Sysman Meeting David Kelsey CLRC/RAL, UK
Advertisements

Last update 01/06/ :23 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD Site Registration policy & procedures
11-Dec-01D.P.Kelsey, Authentication1 Authentication 11 Dec 2001 David Kelsey CLRC/RAL, UK
Andrew McNab - EDG Access Control - 14 Jan 2003 EU DataGrid security with GSI and Globus Andrew McNab University of Manchester
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
5-Sep-02D.P.Kelsey, Security Summary, Budapest1 WP6/7 Security Summary Budapest 5 Sep 2002 David Kelsey CLRC/RAL, UK
30-Jan-03D.P.Kelsey, GridPP Security1 Security GridPP6 30 Jan 2003 Coseners House David Kelsey CLRC/RAL, UK
Authentication Policy David Kelsey CCLRC/RAL 15 April 2004, Dublin
LCG Milestones for Deployment, Fabric, & Grid Technology Ian Bird LCG Deployment Area Manager PEB 3-Dec-2002.
RomeWorkshop on eInfrastructures 9 December LCG Progress on Policies & Coming Challenges Ian Bird IT Division, CERN LCG and EGEE Rome 9 December.
CILogon OSG CA Mine Altunay Jim Basney TAGPMA Meeting Pittsburgh May 27, 2015.
Launch on 17 th March 2008 Open Media Fulfilment Re-engineering 1.
13-May-03D.P.Kelsey, WP8 CA and VO organistion1 CA’s and Experiment (VO) Organisation WP8 Meeting EDG Barcelona, 13 May 2003 David Kelsey CCLRC/RAL, UK.
12-May-03D.P.Kelsey, SCG Online Authentication1 Online Authentication SCG Meeting EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
20-May-03D.P.Kelsey, LCG-1 Security, HEPiX1 Grid Security for LCG-1 HEPiX, NIKHEF, 20 May 2003 David Kelsey CCLRC/RAL, UK
GGF12 – 20 Sept LCG Incident Response Ian Neilson LCG Security Officer Grid Deployment Group CERN.
LCG/EGEE Security Update HEPiX, Fall 2004 BNL, 18 October 2004 David Kelsey CCLRC/RAL, UK
DataGrid WP6 CA meeting, CERN, 12 December 2002 IISAS Certification Authority Jan Astalos Department of Parallel and Distributed Computing Institute of.
JSPG: User-level Accounting Data Policy David Kelsey, CCLRC/RAL, UK LCG GDB Meeting, Rome, 5 April 2006.
DOE Grids New subordinate CP/CPS v2.3 New subordinate CP/CPS v2.3 New name DOEGrids.org New name DOEGrids.org Old name DOESciencegrid.org Old name DOESciencegrid.org.
INFSO-RI Enabling Grids for E-sciencE EGEE/LCG Joint Security Policy Group David Kelsey, CCLRC/RAL, UK EGEE.
ESnet PKI Developed for the DOE Science Grid and SciDAC.
Database Administrator RAL Proposed Workshop Goals Dirk Duellmann, CERN.
Security Policy Update LCG GDB Prague, 4 Apr 2007 David Kelsey CCLRC/RAL
DataGrid WP6/CA CA Trust Matrices Trinity College Dublin (TCD) Brian Coghlan CERN DEC-2002.
13-Jul-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint LCG/EGEE Security Group) CERN 13 July 2004 David Kelsey CCLRC/RAL,
Ian Bird LCG Project Leader OB Summary GDB 10 th June 2009.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
9-Sep-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 9 September 2003 David Kelsey CCLRC/RAL, UK
23-Oct-03D.P.Kelsey, LCG Security Update, HEPiX1 LCG Security Update HEPiX-HEPNT, TRIUMF, 23 October 2003 David Kelsey CCLRC/RAL, UK
8-Jul-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) RAL, 8 July 2003 David Kelsey CCLRC/RAL, UK
3-Nov-00D.P.Kelsey, HEPiX, JLAB1 Certificates for DataGRID David Kelsey CLRC/RAL, UK
BNL VO Management and Grid Mapfile Generation Brookhaven National Lab.
3-Jul-02D.P.Kelsey, Security1 Security meetings Report to EDG PTB 3 Jul 2002 David Kelsey CLRC/RAL, UK
Security Mechanisms The European DataGrid Project Team
LCG/EGEE Security Operations HEPiX, Fall 2004 BNL, 22 October 2004 David Kelsey CCLRC/RAL, UK
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
9-Oct-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) FNAL 9 October 2003 David Kelsey CCLRC/RAL, UK
23-Oct-02D.P.Kelsey, Grid Security, HEPiX, FNAL1 LCG/EDG Security - update and plans HEPiX/HEPNT - FNAL 23 Oct 2002 David Kelsey CLRC/RAL, UK
Grid Security Vulnerability Group Linda Cornwall, GDB, CERN 7 th September 2005
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
National Safer Internet Center Bulgarian example for public private partnership.
2-Sep-02D.P.Kelsey, WP6 CA, Budapest1 WP6 CA report Budapest 2 Sep 2002 David Kelsey CLRC/RAL, UK
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Last update 21/01/ :05 LCG 1Maria Dimou- cern-it-gd Current LCG User Registration, VO management and Authorisation Procedures VOMS workshop
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
11-Dec-00D.P.Kelsey, Certificates, WP6 meeting, Milan1 Certificates for DataGrid Testbed0 David Kelsey CLRC/RAL, UK
8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK
12-Jun-03D.P.Kelsey, CA meeting1 CA meeting Minimum Requirements CERN, 12 June 2003 David Kelsey CCLRC/RAL, UK
18-May-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) Barcelona 18 May 2004 David Kelsey CCLRC/RAL, UK
15-May-03D.P.Kelsey, SCG Summary1 Security Coord Group (SCG) EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
10-May-01D.P.Kelsey, WP6 Security1 Certificates/Authorisation for DataGrid Testbeds David Kelsey CLRC/RAL, UK
7-May-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Issues and Planning or Report from the Security Group CERN, 8 May 2003 David Kelsey CCLRC/RAL, UK.
LCG User, Site & VO Registration in EGEE/LCG Bob Cowles OSG Technical Meeting Dec 15-17, 2004 UCSD.
LCG Pilot Jobs + glexec John Gordon, STFC-RAL GDB 7 December 2007.
Creating the environment for business Assessment of the Implementation by the Member States of the IPPC Directive Advisory Group Meeting Friday 13 th January.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI CSIRT Procedure for Compromised Certificates and Central Security Emergency.
11-May-01D.P.Kelsey, Security Update1 GRID Security Update David Kelsey CLRC/RAL, UK
Gilda certificates. Certification Authority
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
Grid Deployment Technical Working Groups: Middleware selection AAA,security Resource scheduling Operations User Support GDB Grid Deployment Resource planning,
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
EUDET Transnational Access: some administrative aspects
David Kelsey CLRC/RAL, UK
David Kelsey CCLRC/RAL, UK
Ian Bird GDB Meeting CERN 9 September 2003
David Kelsey CCLRC/RAL, UK
Presentation transcript:

10-Jun-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 10 June 2003 David Kelsey CCLRC/RAL, UK

10-Jun-03D.P.Kelsey, LCG-GDB-Security2 Overview Topics for agreement today (for 1 st July) Approval of CA’s User Registration – personal info User Registration – Registration Authorities – not finished Topics for 8 th July GDB – advance warning Experiment/VO Procedures (RA’s) User Rules/AUP Incident Response Audit logs Security Group meetings –28 th May (phone) and 5 th June (all day – CERN)

10-Jun-03D.P.Kelsey, LCG-GDB-Security3 Approval of LCG-1 CA’s See paper (2 nd June 2003) –As discussed at last GDB Procedure for approving and implementing –Modified as requested by May GDB meeting Initial list (may change after 12/13 June meeting) –Union of DataGrid and CrossGrid CA’s Includes North America Taiwan, FNAL and Hungary – CA meeting 12/13 June –Additional LCG-1 FNAL Kerberos CA GDB asked to approve procedure and initial list

10-Jun-03D.P.Kelsey, LCG-GDB-Security4 CA approval procedure For 2003 The LCG-1 Security Group proposes the list of accepted CA’s from two sources: –The list of “traditional” CA’s, issuing long-lived (12 months or more) certificates, comes from the EDG CA Group –The list of additional CA’s (online short-lived, special cases, etc.) is generated by the LCG-1 Security Group Proposed additions to these lists above will be circulated to the GDB and to the LCG-1 site security contacts for objection prior to implementation The LCG-1 operations team maintains the necessary information (certificates, signing policy, CRL’s) and distribution mechanisms for CA’s on both sub-lists All LCG-1 resources will install the full list of approved CA’s

10-Jun-03D.P.Kelsey, LCG-GDB-Security5 Initial CA list Canada, CERN, Cyprus, Czech Republic, France, Germany, Greece, Ireland, Italy, Netherlands, Nordic countries, Poland, Portugal, Russia, Slovakia, Spain, UK, and USA. “Catch-all” operated by CNRS/France Taiwan, FNAL and Hungary – under consideration Tokyo, Belgium, Israel, Pakistan –At various stages of preparation

10-Jun-03D.P.Kelsey, LCG-GDB-Security6 User Registration: Personal Info Many concerns about distribution of and access to personal data – discussed at last GDB meeting Action on GDB National Members (8 th May GDB) –What user info is required for registration? –Is this for pre-registration of accounts? –Why do you need the info? –Can your policy be changed? There was little response, so on 2 nd June –We made definite proposal See next slide –To date, I have heard from Switzerland, Russia, UK and USA No objections yet.

10-Jun-03D.P.Kelsey, LCG-GDB-Security7 User Personal Data (2) Proposal – for agreement today User registers on LCG-1 web site (one central) –Agrees to and “signs” Usage Rules –Agrees to personal data being distributed to all LCG-1 sites (Tier 0/1/2) For use of site/resource managers ONLY Last name, First name, Institution, address, telephone number, experiment Distributed to all LCG-1 sites (down to Tier 2) –Can be used for pre-registration if required Checks made by Expt/VO managers (see later) Comments: –USA: uncertainty as to whether also need “Nationality” –UK: require Expt/VO managers to check and maintain info

10-Jun-03D.P.Kelsey, LCG-GDB-Security8 User Registration Registration Authorities We need Registration Authorities to check –The user actually made the request –User is valid member of the experiment –User is at the listed institution –That all user data looks reasonable E.g. mail address The web form will warn that these checks will be made CERN team investigating feasibility of confirmation of registration request by user on the provided address We need to create and maintain lists (per experiment) of –Institutes and Contact names/details –For distribution to all LCG-1 sites

10-Jun-03D.P.Kelsey, LCG-GDB-Security9 VO Registration (2) Discussions with GDB Experiment Reps and current VO managers –Started by documenting the current procedures –But no firm proposal in time for this meeting Today’s VO managers (EDG) –ALICEDaniele MuraINFN –ATLASAlessandro De SalvoINFN –CMSAndrea SciabaINFN –LHCbJoel ClosierCERN Plan to continue to use the existing VO servers and services (run by NIKHEF) and the current VO managers (all agree to continue) Then plan for Jan 2004

10-Jun-03D.P.Kelsey, LCG-GDB-Security10 Current procedures (1) ALICE How to Check Request?All known Contact “Supervisor”?No Remove users?No Number of users today?49 New Requests/week?~1 Backup Mgr?? Willing to continue?Yes

10-Jun-03D.P.Kelsey, LCG-GDB-Security11 Current procedures (2) ATLAS How to Check Request?~80% well-known or check CERN DB or Supervisor or User Contact “Supervisor”?If necessary Remove users?No – cert expiry? Number of users today?78 New Requests/week?1-2 Backup Mgr?No Willing to continue?Yes

10-Jun-03D.P.Kelsey, LCG-GDB-Security12 Current procedures (3) CMS How to Check Request?Known or CMS web Contact “Supervisor”?No Remove users?No Number of users today?63 New Requests/week?<1 Backup Mgr?No Willing to continue?Yes

10-Jun-03D.P.Kelsey, LCG-GDB-Security13 Current procedures (4) LHCb How to Check Request?Known or PIE/and contact Institute rep Contact “Supervisor”?sometimes Remove users?no Number of users today?25 New Requests/week?<1 Backup Mgr?No Willing to continue?Yes

10-Jun-03D.P.Kelsey, LCG-GDB-Security14 Draft proposal – VO/RA For 1 st July – continue as today Work needed on more robust procedures –That can scale Distributed RA’s required Long-term aim –Make part of CERN Experiment/User Office registration procedures For discussion at 8 th July GDB –Paper 23rd June

10-Jun-03D.P.Kelsey, LCG-GDB-Security15 User Rules/AUP To be agreed to (signed via private key in browser) when User registers Still working on draft Based on current EDG Usage Rules Does not override sites rules and policies Only allows professional use For discussion at next GDB –Paper 23rd June

10-Jun-03D.P.Kelsey, LCG-GDB-Security16 Incident Response Draft document discussed on Security Contacts list Procedures for 1 st July (before GOC) –Incidents, communications, enforcement, escalation etc We have created an ops security list –Default site entry is the Contact person but an operational list would be better For discussion at next GDB Paper 23rd June

10-Jun-03D.P.Kelsey, LCG-GDB-Security17 Audit logs CERN team working on this Changes have been made to the Globus gatekeeper and jobmanager (LSF and probably PBS) to allow log rotation and access to batch jobid –Have been submitted to VDT –Integration into EDG release in due course We will propose a list of audit logs –To be kept for 3 months (100 days?) by all sites Paper to GDB on 23rd June –For discussion at next meeting –Details of what is needed N.b. We need audit logs from the RB –No real auditing until this exists