E-NMR (RI-213010) is funded by the European Commission under the Research Infrastructure Programme www.e-nmr.eu Introduction to e-NMR hands-on e-NMR gLite.

Slides:



Advertisements
Similar presentations
Introduction of Grid Security
Advertisements

EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks MyProxy and EGEE Ludek Matyska and Daniel.
INFSO-RI Enabling Grids for E-sciencE EGEE and gLite Slides by: Erwin Laure EGEE Deputy Middleware Manager.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Introduction to EGEE hands-on Gergely Sipos.
FP7-INFRA Enabling Grids for E-sciencE EGEE Induction Grid training for users, Institute of Physics Belgrade, Serbia Sep. 19, 2008.
It’s not about security... it’s about access! Grid Security Pieter van Beek.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Tutorial Getting started with GILDA.
INFSO-RI Enabling Grids for E-sciencE EGEE Middleware The Resource Broker EGEE project members.
The EPIKH Project (Exchange Programme to advance e-Infrastructure Know-How) gLite Grid Services Abderrahman El Kharrim
The LHC Computing Grid – February 2008 The Worldwide LHC Computing Grid Dr Ian Bird LCG Project Leader 15 th April 2009 Visit of Spanish Royal Academy.
DataGrid Kimmo Soikkeli Ilkka Sormunen. What is DataGrid? DataGrid is a project that aims to enable access to geographically distributed computing power.
Makrand Siddhabhatti Tata Institute of Fundamental Research Mumbai 17 Aug
Enabling Grids for E-sciencE Security on gLite middleware Matthieu Reichstadt CNRS/IN2P3 ACGRID School, Hanoi (Vietnam) November 5th, 2007.
08/11/908 WP2 e-NMR Grid deployment and operations Technical Review in Brussels, 8 th of December 2008 Marco Verlato.
INFSO-RI Enabling Grids for E-sciencE Practicals on VOMS and MyProxy Emidio Giorgio INFN Retreat between GILDA and ESR VO, Bratislava,
FP6−2004−Infrastructures−6-SSA E-infrastructure shared between Europe and Latin America Luciano Díaz ICN-UNAM Based on Domenico.
INFSO-RI Enabling Grids for E-sciencE Logging and Bookkeeping and Job Provenance Services Ludek Matyska (CESNET) on behalf of the.
Enabling Grids for E-sciencE ENEA and the EGEE project gLite and interoperability Andrea Santoro, Carlo Sciò Enea Frascati, 22 November.
DataGrid WP1 Massimo Sgaravatto INFN Padova. WP1 (Grid Workload Management) Objective of the first DataGrid workpackage is (according to the project "Technical.
Nadia LAJILI User Interface User Interface 4 Février 2002.
E-science grid facility for Europe and Latin America E2GRIS1 Raúl Priego Martínez – CETA-CIEMAT (Spain)‏ Itacuruça (Brazil), 2-15 November.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security and Job Management.
Exporting User Certificate from Internet Explorer.
EGEE-II INFSO-RI Enabling Grids for E-sciencE An Introduction to the EGEE Project Presented by Min Tsai ISGC 2007, Taipei With thanks.
E-infrastructure shared between Europe and Latin America Security Hands-on Christian Grunfeld, UNLP 8th EELA Tutorial, La Plata, 11/12-12/12,2006.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Introduction to GILDA and gaining access.
June 24-25, 2008 Regional Grid Training, University of Belgrade, Serbia Introduction to gLite gLite Basic Services Antun Balaž SCL, Institute of Physics.
INFSO-RI Enabling Grids for E-sciencE GILDA Practicals : Security systems GILDA Tutors Singapore, 1st South East Asia Forum -- EGEE.
E-infrastructure shared between Europe and Latin America FP6−2004−Infrastructures−6-SSA Hands-on on security Pedro Rausch IF - UFRJ.
EGEE-III INFSO-RI Enabling Grids for E-sciencE Feb. 06, Introduction to High Performance and Grid Computing Faculty of Sciences,
EGEE-III INFSO-RI Enabling Grids for E-sciencE Apr. 25, Grid Computing Hands On Training for Users Faculty of Sciences, University.
INFSO-RI Enabling Grids for E-sciencE Security in gLite Gergely Sipos MTA SZTAKI With thanks for some slides to.
EGEE-II INFSO-RI Enabling Grids for E-sciencE The GILDA training infrastructure.
Glite. Architecture Applications have access both to Higher-level Grid Services and to Foundation Grid Middleware Higher-Level Grid Services are supposed.
INFSO-RI Enabling Grids for E-sciencE Αthanasia Asiki Computing Systems Laboratory, National Technical.
4th EELA TUTORIAL - USERS AND SYSTEM ADMINISTRATORS E-infrastructure shared between Europe and Latin America Security Hands-on Vanessa.
EGEE-0 / LCG-2 middleware Practical.
FP6−2004−Infrastructures−6-SSA E-infrastructure shared between Europe and Latin America Alexandre Duarte CERN IT-GD-OPS UFCG LSD 1st EELA Grid School.
Tier 3 Status at Panjab V. Bhatnagar, S. Gautam India-CMS Meeting, July 20-21, 2007 BARC, Mumbai Centre of Advanced Study in Physics, Panjab University,
FP6−2004−Infrastructures−6-SSA E-infrastructure shared between Europe and Latin America Practicals on Security Miguel Cárdenas Montes.
E-infrastructure shared between Europe and Latin America Security Hands-on Alexandre Duarte CERN Fifth EELA Tutorial Santiago, 06/09-07/09,2006.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Grid2Win : gLite for Microsoft Windows Roberto.
FP6−2004−Infrastructures−6-SSA E-infrastructure shared between Europe and Latin America Moisés Hernández Duarte UNAM FES Cuautitlán.
Further aspects of EGEE middleware components INFN, Catania EGEE is funded by the European Union under contract IST
INFSO-RI Enabling Grids for E-sciencE VOMS & MyProxy interaction Emidio Giorgio INFN NA4 Generic Applications Meeting 10 January.
Enabling Grids for E-sciencE Sofia, 17 March 2009 INFSO-RI Introduction to Grid Computing, EGEE and Bulgarian Grid Initiatives –
EGEE-II INFSO-RI Enabling Grids for E-sciencE Practical using WMProxy advanced job submission.
13th EELA Tutorial, La Antigua, 18-19, October E-infrastructure shared between Europe and Latin America FP6−2004−Infrastructures−6-SSA
LCG2 Tutorial Viet Tran Institute of Informatics Slovakia.
Hands-on security Carlos Fuentes RedIRIS Madrid,26 – 30 de Octubre de 2008.
Hands on Security, Authentication and Authorization Virginia Martín-Rubio Pascual RedIRIS/Red.es Curso Grid y e-Ciencia.
EGI-InSPIRE RI Grid Training for Power Users EGI-InSPIRE N G I A E G I S Grid Training for Power Users Institute of Physics Belgrade.
Grid security Enrico Fattibene INFN-CNAF 26 Settembre 20111Calcolo Parallelo su Grid e CSN4cluster.
The EPIKH Project (Exchange Programme to advance e-Infrastructure Know-How) 马兰馨 IHEP, CAS Hands on gLite Security.
1 Grid Security Jinny Chien Academia Sinica Computing Centre Deployment team.
1 Grid Security Alessandro Paolini INFN-CNAF IV Scuola della GRID per utenti.
Enabling Grids for E-sciencE gLite security pratical tutorial Dario Russo INFN Catania Catania,
EGEE-II INFSO-RI Enabling Grids for E-sciencE Overview of gLite, the EGEE middleware Mike Mineter Training Outreach Education National.
First South Africa Grid Training June 2008, Catania (Italy) OVERVIEW of the gLite COMPONENTS Marcello Iacono Manno FIRST.
Authentication Services Grid security concepts and tools D. Cesini (INFN-CNAF), V.Ciaschini (INFN-CNAF), A.Paolini (INFN-CNAF) INFN Grid School, CNAF,
GRID commands lines Original presentation from David Bouvet CC/IN2P3/CNRS.
Antonio Fuentes RedIRIS Barcelona, 15 Abril 2008 The GENIUS Grid portal.
The EPIKH Project (Exchange Programme to advance e-Infrastructure Know-How) gLite Grid Introduction Salma Saber Electronic.
Enabling Grids for E-sciencE Work Load Management & Simple Job Submission Practical Shu-Ting Liao APROC, ASGC EGEE Tutorial.
EGEE is a project funded by the European Union under contract IST Job Submission Giuseppe La Rocca EGEE NA4 Generic Applications INFN Catania.
(Exchange Programme to advance e-Infrastructure Know-How) The EPIKH Project Hailong Yang
Authentication, Authorisation and Security
Practicals on VOMS and MyProxy
Introduction to Grid Technology
gLite The EGEE Middleware Distribution
Presentation transcript:

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme Introduction to e-NMR hands-on e-NMR gLite Training Firenze, June 2009 Marco Verlato

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme The Grid Metaphor

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme Key concepts “A computational grid is a hardware and software infrastructure that provides dependable, consistent, pervasive and inexpensive access to high-end computational capabilities” From “The Grid: Blueprint for a New Computing Infrastructure” (1999) “Flexible, secure, coordinated resource sharing among dynamic collections of individuals, institutions, and resources - what we refer to as Virtual Organizations (VOs)” From “The Anatomy of the Grid: Enabling Scalable Virtual Organizations” (2001) Example of Virtual Organisations: the 4 LHC experiments, the community of biomedical researchers, the bio-NMR community, etc.

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme The middleware The Grid relies on advanced software, called middleware Middleware automatically finds the data the scientist needs, and the computing power to analyse it Middleware balances the load on different resources. It also handles security, accounting, monitoring and much more

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme Enabling Grid for E-sciencE project Archeology Astronomy Astrophysics Civil Protection Comp. Chemistry Earth Sciences Finance Fusion Geophysics High Energy Physics Life Sciences Multimedia Material Sciences … 267 sites 54 countries >110,000 CPUs >20 PetaBytes >16,000 users >200 VOs >150,000 jobs/day Flagship Grid infrastructure project co-funded by the European Commission starting from April 2004 is completing now its 3° phase

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme The EGEE middleware: gLite Applications have access both to Higher-level Grid Services and to Foundation Grid Middleware Higher-Level Grid Services are supposed to help the users building their computing infrastructure but should not be mandatory Foundation Grid Middleware will be deployed on the EGEE infrastructure –Must be complete and robust –Should allow interoperation with other major grid infrastructures –Should not assume the use of Higher-Level Grid Services

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme 7 gLite Services Decomposition API Access Job Mgmt. Services Computing Element Workload Management Metadata Catalog Data Services Storage Element Data Movement File & Replica Catalog Authorization Security Services Authentication Information & Monitoring Information & Monitoring Services Service Discovering Accounting Auditing Job Provenance Package Manager CLI Network Monitoring

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme 8 gLite services orchestration Computing Element Storage Element Site X Information System submit query retrieve Workload Management Logging & Bookkeeping User Interface publish state File and Replica Catalogs AuthN/AuthZ Service query update credential publish state discover services

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme e-NMR Grid in June 2009 CEs, SEs and UIs at sites: 236 CPU-cores 2.9 TB storage dedicated CPU-cores 35.2 TB storage shared with IGI and BigGRID

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme Security Services GSI Authentication based on PKI X.509 SSL infrastructure Certificate Authorities (CA) issue (long lived) certificates identifying individuals (much like a passport) to reduce vulnerability, on the Grid user identification is done by using (short lived) proxies of their certificates (they can be stored on MyProxy servers) users belong to VO’s, to groups inside a VO and may have special roles VOMS provides a way to add attributes to a certificate proxy

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme An X.509 Certificate contains:  owner’s public key;  identity of the owner;  info on the CA;  time of validity;  Serial number;  digital signature of the CA Public key Subject:C=IT, O=INFN, OU=Personal Certificate, L=Padova CN=Marco Verlato Issuer: C=IT, O=INFN, CN=INFN Certification Authority Expiration date: Apr 21 12:22: GMT Serial number: 33CF CA Digital signature Structure of a X.509 certificate X.509 Certificates

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme Which CA are trusted in EGEE?

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme Obtaining a certificate 13

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme Certificate management 14 – You receive typically a PKCS12 certificate (can import it directly into the web browser) – For future use, you will need usercert.pem and userkey.pem in a directory ~/.globus on your UI – Export the PKCS12 cert to a local dir on UI and use again openssl: $ openssl pkcs12 -nocerts -in my_cert.p12 -out userkey.pem $ openssl pkcs12 -clcerts -nokeys -in my_cert.p12 –out usercert.pem $ cat.globus/usercert.pem -----BEGIN CERTIFICATE----- MIIF1zCCBL+gAwIBAgICCA4wDQYJKoZIhvcNAQEEBQAwQzELMAkGA1UEBhMCSVQx DTALBgNVBAoTBElORk4xJTAjBgNVBAMTHElORk4gQ2VydGlmaWNhdGlvbiBBdXRo b3JpdHkwHhcNMDQwNTEwMTMxNTIyWhcNMDUwNTEwMTMxNTIyWjCBjzELMAkGA1UE BhMCSVQxDTALBgNVBAoTBElORk4xHTAbBgNVBAsTFFBlcnNvbmFsIENlcnRpZmlj YXRlMQ0wCwYDVQQHEwRDTkFGMRcwFQYDVQQDEw5EYW5pZWxlIENlc2luaTEqMCgG CSqGSIb3DQEJARYbZGFuaWVsZS5jZXNpbmlAY25hZi5pbmZuLml0MIIBIjANBgkq hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnEvVPBpTjKLA4F0K+Zgc8pWyEPGDnwLW glktBI6+mYTLuemPzgkZ4CTyrZL7bw5ywXUe717e1Rmg6wDfPANRLkxxRNKNaron kS19eNKjPYpklEKNq2gSGsK0/SsYB2YUG4kWLqtFC93x1Ffdc1Tz0xgrXH3kC0jq NqHImDrbpB7VtvAGC7/e/EJhy9MvlPA4W2vbUnwBocjMA/en3GXs2KY19tbFA3Tg jyIpCMbIeu3GlyTnbSJFoy3eeHkNLsf9c29RAJ5gWxMF7arM++NyURQ9qaEdMINj Cqb7dHJEj8E/AwSsYeWmWHfaPXnjj5aP23UlRTc31nSwh+5y0bMnFwIDAQABo4IC hjCCAoIwDAYDVR0TAQH/BAIwADAOBgNVHQ8BAf8EBAMCBPAwNgYDVR0fBC8wLTAr oCmgJ4YlaHR0cDovL3NlY3VyaXR5LmZpLmluZm4uaXQvQ0EvY3JsLmNybDAXBgNV HSAEEDAOMAwGCisGAQQB0SMKAQQwHQYDVR0OBBYEFCM+8mfoaenmQ76tHy+7hX+5 RKJ6MGsGA1UdIwRkMGKAFMoR710dBwSYqaW1WBpmTgoWK+BJoUekRTBDMQswCQYD VQQGEwJJVDENMAsGA1UEChMESU5GTjElMCMGA1UEAxMcSU5GTiBDZXJ0aWZpY2F END CERTIFICATE----- $ grid-cert-info -file.globus/usercert.pem Certificate: Data: Version: 3 (0x2) Serial Number: (0x33cf) Signature Algorithm: sha1WithRSAEncryption Issuer: C=IT, O=INFN, CN=INFN CA Validity Not Before: Apr 21 12:22: GMT Not After : Apr 21 12:22: GMT Subject: C=IT, O=INFN, OU=Personal Certificate, L=Padova, CN=Marco Verlato

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme Registering with enmr.eu VO 15 Bare certificates are not enough for defining user capabilities on the grid Users belong to VO’s, to groups inside a VO and may have special roles You need your certificate uploaded into your browser

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme voms-proxy-init $ voms-proxy-init -voms enmr.eu Cannot find file or dir: /users/grid/verlato/.glite/vomses Enter GRID pass phrase: Your identity: /C=IT/O=INFN/OU=Personal Certificate/L=Padova/CN=Marco Verlato Creating temporary proxy Done Contacting voms-02.pd.infn.it:15014 [/C=IT/O=INFN/OU=Host/L=Padova/CN=voms-02.pd.infn.it] "enmr.eu" Done Creating proxy Done Your proxy is valid until Mon Feb 16 08:02: $ voms-proxy-info -all subject : /C=IT/O=INFN/OU=Personal Certificate/L=Padova/CN=Marco Verlato/CN=proxy issuer : /C=IT/O=INFN/OU=Personal Certificate/L=Padova/CN=Marco Verlato identity : /C=IT/O=INFN/OU=Personal Certificate/L=Padova/CN=Marco Verlato type : proxy strength : 1024 bits path : /tmp/x509up_u3801 timeleft : 11:55:54 === VO enmr.eu extension information === VO : enmr.eu subject : /C=IT/O=INFN/OU=Personal Certificate/L=Padova/CN=Marco Verlato issuer : /C=IT/O=INFN/OU=Host/L=Padova/CN=voms-02.pd.infn.it attribute : /enmr.eu/Role=NULL/Capability=NULL attribute : /enmr.eu/cirmmp/Role=NULL/Capability=NULL timeleft : 11:55:54 uri : voms-02.pd.infn.it:15014 VO Attributes

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme Long term proxy - myproxy Grid tasks may need a time longer than the proxy lifetime (short for security reasons)‏ A MyProxy server is used to create and store a long term proxy which is used to renew short term proxies when they are going to expire $ myproxy-init -s myproxy.cnaf.infn.it -d Your identity: /C=IT/O=INFN/OU=Personal Certificate/L=Padova/CN=Marco Verlato Enter GRID pass phrase for this identity: Creating proxy Done Proxy Verify OK Your proxy is valid until: Mon Feb 23 16:48: Enter MyProxy pass phrase: Verifying - Enter MyProxy pass phrase: A proxy valid for 168 hours (7.0 days) for user /C=IT/O=INFN/OU=Personal Certificate/L=Padova/CN=Marco Verlato now exists on myproxy.cnaf.infn.it. A dedicated service on the WMS can renew automatically the proxy on your behalf contacting the MyProxy server (the MyProxy server should be indicated in the job description)‏

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme 18 User Interface (UI) The access point to the EGEE Grid is the User Interface (UI) It provides the CLI tools to access the functionalities offered by the gLite Services They allow to perform some basic Grid operations: –create the user proxy needed for authentication/authorization –retrieve the status of different resources from the Information System –copy, replicate and delete files from the Grid –list all the resources suitable to execute a given job –submit jobs for execution –cancel jobs –retrieve the output of finished jobs –show the status of submitted jobs –retrieve the logging and bookkeeping information of jobs It provides the APIs to allow the development of Grid-enabled applications

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme 19 Job Submission Workflow JDL Logging & Book-keeping Resource Broker Job Submission Service Storage Element ComputingElement Information Service Job Status Replica Catalog Job Submit Event Input Sandbox JDL Job Input Sandbox Output Sandbox User Interface Auth. Service voms-proxy-init glite-job-submit myjob.jdl Myjob.jdl Executable = "$(CMS)/exe/sum.exe"; InputData = "lfn:/testbed "; DataCatalogType="DLI”; DataAccessProtocol = "gsiftp"; InputSandbox = {"/home/user/WP1testC","/home/ file1” }; OutputSandbox = {“sim.err”, “test.out”, “sim.log"}; Requirements = other.GlueCEArchitecture == "INTEL"; Rank = other.FreeCPUs; GSI data acc/transf

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme References

e-NMR (RI ) is funded by the European Commission under the Research Infrastructure Programme Hands-on set up 21 In this course all security stuffs have already been setup for you you have an account on a linux machine you have a proxy certificate in /tmp/cert_proxy I’ll show you how to install and use a UI Access: 40 accounts enmr1  enmr40 passwd meetingf ssh enmr1 