EGEE-III INFSO-RI-222667 Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,

Slides:



Advertisements
Similar presentations
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks MyProxy and EGEE Ludek Matyska and Daniel.
Advertisements

Grid Security Policy GridPP18, Glasgow David Kelsey 21sr March 2007.
Grid Security Policy David Kelsey (RAL) 1 July 2009 UK HEP SYSMAN Security workshop david.kelsey at stfc.ac.uk.
Grid Security Users, VOs, Sites OSG Collaboration Meeting University of Washington Bob Cowles August 23, 2006 Work supported.
Authorization WG Update David Kelsey EU Grid PMA, Copenhagen 27 May 2008.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
Information Security Policies and Standards
A Model for Grid User Management Rich Baker Dantong Yu Tomasz Wlodek Brookhaven National Lab.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group Summary EGI TF David Kelsey 6/28/
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
INFSO-RI Enabling Grids for E-sciencE Incident Response Policies and Procedures Carlos Fuentes
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group EGI Technical Forum Sep 2010 David Kelsey.
INFSO-RI Enabling Grids for E-sciencE SA1: Cookbook (DSA1.7) Ian Bird CERN 18 January 2006.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
JSPG: User-level Accounting Data Policy David Kelsey, CCLRC/RAL, UK LCG GDB Meeting, Rome, 5 April 2006.
EGEE-II / EGEE-III Transition Meeting 6-7 May 2008 EGEE-III INFSO-RI Enabling Grids for E-sciencE Registration procedure, Computer.
INFSO-RI Enabling Grids for E-sciencE EGEE/LCG Joint Security Policy Group David Kelsey, CCLRC/RAL, UK EGEE.
Responsibilities of ROC and CIC in EGEE infrastructure A.Kryukov, SINP MSU, CIC Manager Yu.Lazin, IHEP, ROC Manager
Security Policy Update LCG GDB Prague, 4 Apr 2007 David Kelsey CCLRC/RAL
8-Jul-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) RAL, 8 July 2003 David Kelsey CCLRC/RAL, UK
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and OSG: Common Security Policies? OSG.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Next steps with EGEE EGEE training community.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks JSPG Status and plans EGEE’06 Conference.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE-EGI Grid Operations Transition Maite.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Linda Cornwall CCLRC (RAL) FP6 Security workshop.
LCG/EGEE Security Operations HEPiX, Fall 2004 BNL, 22 October 2004 David Kelsey CCLRC/RAL, UK
Next Steps: becoming users of the NGS Mike Mineter
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks NA3 – Procedures for Training Event Robin.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks SA1: Grid Operations Maite Barroso (CERN)
Grid Security Vulnerability Group Linda Cornwall, GDB, CERN 7 th September 2005
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
INFSO-RI Enabling Grids for E-sciencE EGEE SA1 in EGEE-II – Overview Ian Bird IT Department CERN, Switzerland EGEE.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Dr Linda Cornwall CCLRC (RAL) FP6 Security workshop.
Trusted Virtual Machine Images a step towards Cloud Computing for HEP? Tony Cass on behalf of the HEPiX Virtualisation Working Group October 19 th 2010.
INFSO-RI Enabling Grids for E-sciencE EGEE is a project funded by the European Union under contract INFSO-RI Grid Accounting.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGI Operations Tiziana Ferrari EGEE User.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks NA3 – Procedures for Training Event Robin.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
June 6, 2006OSG - Draft VO AUP1 Open Science Grid Trust as a Foundation June 6, 2006 Keith Chadwick.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Resource Allocation in EGEEIII Overview &
EGI-InSPIRE RI EGI EGI-InSPIRE RI Service Operations Security Policy the new generalised site operations security policy.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
Last update 22/02/ :54 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD VO Registration procedure Presented by.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and JSPG activities David Kelsey CCLRC/RAL.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Ian Bird All Activity Meeting, Sofia
Security Policy Update WLCG GDB CERN, 8 Dec 2010 David Kelsey STFC/RAL david.kelsey AT stfc.ac.uk.
Why a Commercial Provider should Join the Academic Cloud Federation David Blundell Managing Director 100 Percent IT Ltd Simple, Flexible, Reliable.
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
LCG User, Site & VO Registration in EGEE/LCG Bob Cowles OSG Technical Meeting Dec 15-17, 2004 UCSD.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Study on Authorization Christoph Witzig,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks What all NGIs need to do: Helpdesk / User.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Grid is a Bazaar of Resource Providers and.
Security Bob Cowles
Grid Deployment Technical Working Groups: Middleware selection AAA,security Resource scheduling Operations User Support GDB Grid Deployment Resource planning,
OSG VO Security Policies and Requirements Mine Altunay OSG Security Team July 2007.
Grid Security Policy: EGEE to EGI David Kelsey (RAL) 16 Sep 2009 JSPG meeting, DFN Berlin david.kelsey at stfc.ac.uk.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
PRACE user authentication and vetting Vincent RIBAILLIER, 29 th EUGridPMA meeting, Bucharest, September 9 th, 2013.
Security Policy Update WLCG GDB CERN, 11 June 2008 David Kelsey STFC/RAL
Open Science Grid Consortium Meeting
Ian Bird GDB Meeting CERN 9 September 2003
Grid Security M. Jouvin / C. Loomis (LAL-Orsay)
Presentation transcript:

EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC, EGEE’08 Conference, Istanbul, 25th September 2008 VO Security Policy

Enabling Grids for E-sciencE EGEE-III INFSO-RI Security Policy Security Policy Site & VO Policies Certification Authorities Traceability and Logging Incident Response Accounting Data Privacy (draft) Pilot Jobs and other Grid Services Grid & VO AUPs 2 Kelsey VO Policy

Enabling Grids for E-sciencE EGEE-III INFSO-RI VO Operations Policy Presented early draft of this in EGEE’07 –Now complete and approved Similar aims to the Grid Site Operations Policy –But for VOs Documents the responsibilities of a VO –They must accept and sign during registration We need to define an acceptable procedure for EGEE –To inform all VOs of the policy –To collect “signatures” 3 Kelsey VO Policy

Enabling Grids for E-sciencE EGEE-III INFSO-RI VO Operations Policy By participating in the Grid as a Virtual Organisation (VO), you agree to the conditions laid down in this document and other referenced documents that may be revised from time to time. You shall provide and maintain, in a central repository provided by the Grid, accurate contact information as specified in the VO Registration Policy. These contacts satisfy the communication requirements for management decisions, security actions and operational issues relating to VO membership and Grid usage, as well as your software and services. The contacts shall respond to enquiries in a timely fashion as defined in the Grid operational procedures giving priority to security problems. Kelsey VO Policy 4

Enabling Grids for E-sciencE EGEE-III INFSO-RI VO Ops(2) You shall comply with the Grid security policies, the VO AUP and any archival, accounting and logging requirements. You shall periodically assess, at least once per year, your compliance with these policies and inform the Grid Security Officer of any violations encountered in the assessment, and correct such violations forthwith. You shall ensure that a VO membership service is provided in compliance with the VO Membership Management Policy. This shall include the appropriate interfaces and configuration details to allow the generation of authentication, authorization and other identity mapping data for the services running on the Sites. You shall take reasonable measures to ensure that the information recorded in the membership service is correct and up-to-date. Kelsey VO Policy 5

Enabling Grids for E-sciencE EGEE-III INFSO-RI VO Ops(3) You are responsible for ensuring that your software does not pose security threats, that access to your databases is secure and is sufficiently monitored, that your stored data are compliant with legal requirements, and that your VO services, including pilot job frameworks, are operated according to the applicable policy documents. You shall ensure that logged, archived and membership information is only used for administrative, operational, accounting, monitoring and security purposes. You shall ensure that due diligence is applied in maintaining the confidentiality of such information. You recognize that the Grid and the Sites may control your access to their resources for administrative, operational and security purposes. Kelsey VO Policy 6

Enabling Grids for E-sciencE EGEE-III INFSO-RI VO Ops(4) You shall ensure that any software used by you at a Site for its intended purposes, complies with applicable license conditions and you shall hold such Site free and harmless from any liability with respect thereto. Any software provided by the Grid is provided on an as-is basis only, and subject to its own license conditions. There is no guarantee that any service operated by the Grid is correct or sufficient for any particular purpose. The Grid, the Sites and other VOs are not liable for any loss or damage in connection with your participation in the Grid. Kelsey VO Policy 7

Enabling Grids for E-sciencE EGEE-III INFSO-RI VO Ops(5) You shall comply with the Grid incident response procedures and respond promptly to requests from Grid Security Operations. You shall inform users in cases where their access rights have changed. Disputes resulting from your participation in the Grid shall be resolved according to the Grid escalation procedures. This policy shall be signed for agreement by an Authorized Signatory of the Virtual Organisation. Kelsey VO Policy 8

Enabling Grids for E-sciencE EGEE-III INFSO-RI Current JSPG work New VO Registration Policy –Replaces old VO Security Policy –Similar to Site Registration Policy –Defines what needs to be collected during registration  For security-related reasons –Defines VO naming convention (DNS-style names) –Requires VO to define an AUP (gives template) New VO Membership Management Policy –Replaces old LCG User Registration and Membership Management –Defines policy requirements for various VO procedures  VO manager appointment, User registration, renewal, removal, suspension, audit requirements, data privacy, VO manager responsibilities, etc … –Likely to require VO to complete a template form on its approach 9 Kelsey VO Policy

Enabling Grids for E-sciencE EGEE-III INFSO-RI New JSPG documents Using new approach –Replaces the use of MS Word (with change tracking) –Collaborative editing via the JSPG wiki –Anyone with an IGTF certificate can register and contribute –Discussion pages allow for comments and presentation of ideas behind the policy –Please contribute! Two documents currently under revision Kelsey VO Policy 10

Enabling Grids for E-sciencE EGEE-III INFSO-RI VOs, EGI and scaling problems Today in EGEE we have more than 200 VOs –Do all VOs understand their responsibilities? –Even now it is difficult for Sites to understand each VOs procedures to “trust” them If a VO uses resources in several Grids –Will be very difficult to build trust between the VO and Site Even more problems once we have many NGIs A possible solution: –One Grid establishes Trust with the VO –Via an accreditation procedure following agreed international standards –Then easier for other Grids to accept (and trust) the VO  If it has been accredited 11 Kelsey VO Policy

Enabling Grids for E-sciencE EGEE-III INFSO-RI IGTF & JSPG Developments IGTF (EUGridPMA) is investigating minimum standards and best practice for the operation of VO attribute authorities (e.g. VOMS) –See draft JSPG is working on standards for VO procedures –See earlier reference to VO Membership Management COMMENTS welcome on all these documents –Use the wiki discussion (or send to me) Assuming we agree accreditation that scales –VOs will be able to get IGTF accreditation –To ease trust building (between VO and Sites) BUT we do need to balance the benefits of such an accreditation against the effort needed – make it easy! 12 Kelsey VO Policy

Enabling Grids for E-sciencE EGEE-III INFSO-RI JSPG Meetings, Web etc Meetings - Agenda, presentations, minutes etc JSPG web site(s) (the old web) IGTF web site Membership of the JSPG mail list is closed, BUT –Requests to join stating reasons to D Kelsey –Particularly keen to involve more ROCs, VOs, Grid, … 13 Kelsey VO Policy

Enabling Grids for E-sciencE EGEE-III INFSO-RI Questions? 14 Kelsey VO Policy