EGEE-II INFSO-RI-031688 Enabling Grids for E-sciencE www.eu-egee.org EGEE Security Coordination Group Dr Linda Cornwall CCLRC (RAL) FP6 Security workshop.

Slides:



Advertisements
Similar presentations
Grid Security Policy GridPP18, Glasgow David Kelsey 21sr March 2007.
Advertisements

GGF16, Athens AuthZ Interoperability Here and Now Workshop, 16 Feb 2006.
INFSO-RI Enabling Grids for E-sciencE Security (JRA3) Åke Edlund, JRA3 Manager, KTH David Groep, EUGridPMA chair, NIKHEF EGEE 1.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
INFSO-RI Enabling Grids for E-sciencE Operational Security OSCT JSPG March 2006 Ian Neilson, CERN.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks JRA2: Quality Assurance & Security Coordination.
The Grid Services Security Vulnerability and Risk Assessment Activity in EGEE-II Enabling Grids for E-sciencE EGEE-II INFSO-RI
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Handling Grid Security Vulnerabilities in.
EGEE ARM-2 – 5 Oct LCG Security Coordination Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Enabling Grids for E-sciencE EGEE III Security Training and Dissemination Mingchao Ma, STFC – RAL, UK OSCT Barcelona 2009.
INFSO-RI Enabling Grids for E-sciencE SA1: Cookbook (DSA1.7) Ian Bird CERN 18 January 2006.
GGF12 – 20 Sept LCG Incident Response Ian Neilson LCG Security Officer Grid Deployment Group CERN.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Related Projects Dieter Kranzlmüller Deputy.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Steven Newhouse EGEE’s plans for transition.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE – paving the way for a sustainable infrastructure.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Ake Edlund EGEE Sec Head 9th MWSG meeting, SLAC,
INFSO-RI Enabling Grids for E-sciencE Plan until the end of the project and beyond, sustainability plans Dieter Kranzlmüller Deputy.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and OSG: Common Security Policies? OSG.
INFSO-RI Enabling Grids for E-sciencE NA5 – Policy and International Cooperation Panagiotis Louridas, Fotis Karagiannis, GRNET Final.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Next steps with EGEE Gergely Sipos
INFSO-RI Enabling Grids for E-sciencE External Projects Integration Summary – Trigger for Open Discussion Fotis Karayannis, Joanne.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Linda Cornwall CCLRC (RAL) FP6 Security workshop.
LCG/EGEE Security Operations HEPiX, Fall 2004 BNL, 22 October 2004 David Kelsey CCLRC/RAL, UK
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
Apr 26, 20071/3 OSG Executive Board Meeting Gabriele Garzoglio OSG Executive Board Meeting Gabriele Garzoglio VO Services, PL Computing Division, Fermilab.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks SA1: Grid Operations Maite Barroso (CERN)
Grid Security Vulnerability Group Linda Cornwall, GDB, CERN 7 th September 2005
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
INFSO-RI Enabling Grids for E-sciencE EGEE SA1 in EGEE-II – Overview Ian Bird IT Department CERN, Switzerland EGEE.
EGEE-III-INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE-III All Activity Meeting Brussels,
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Operational Security Coordination Team Ian.
Security Operations David Kelsey GridPP Deployment Board 3 Mar 2005
INFSO-RI Enabling Grids for E-sciencE Security Summary Åke Edlund, JRA3 4 th EGEE Conference Pisa, Italy 28 th October 2005.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
INFSO-RI Enabling Grids for E-sciencE An overview of EGEE operations & support procedures Jules Wolfrat SARA.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Grid Services Security Vulnerability and.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
EGEE is a project funded by the European Union under contract IST Roles & Responsibilities Ian Bird SA1 Manager Cork Meeting, April 2004.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and JSPG activities David Kelsey CCLRC/RAL.
Security EGEE/SA1 ROC Managers ARM-3 meeting Lyon, 17 March 2005 David Kelsey CCLRC/RAL, UK
EGEE ARM-2 – 5 Oct LCG/EGEE Security Coordination Ian Neilson Grid Deployment Group CERN.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
18-May-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) Barcelona 18 May 2004 David Kelsey CCLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE Security (JRA3) Åke Edlund, JRA3 Manager, KTH David Groep, Security Expert, NIKHEF EGEE 1.
Recent lessons learned: Operational Security David Kelsey CCLRC/RAL, UK GDB Meeting, BNL, 5 Sep 2006.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Technical Overview EGEE-II’s achievements.
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
LCG User, Site & VO Registration in EGEE/LCG Bob Cowles OSG Technical Meeting Dec 15-17, 2004 UCSD.
EGEE is a project funded by the European Union under contract IST EGEE Security Åke Edlund Security Head EU IST-FP6 Concertation, 17 th September.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
Grid Deployment Technical Working Groups: Middleware selection AAA,security Resource scheduling Operations User Support GDB Grid Deployment Resource planning,
INFSO-RI Enabling Grids for E-sciencE EGEE general project update Fotis Karayannis EGEE South East Europe Project Management Board.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Ake Edlund for JRA3 EGEE EU Review (CERN) May 23-24, 2006.
INFSO-RI Enabling Grids for E-sciencE Policy and International Cooperation Fotis Karayannis EGEE Second EU Review 7 December 2005.
INFSO-RI Enabling Grids for E-sciencE JRA3 Åke Edlund On behalf of JRA3 EGEE 8th All-activity meeting January 18-19,
INFSO-RI Enabling Grids for E-sciencE NA5 – Policy and International Cooperation Panagiotis Louridas, Fotis Karagiannis, GRNET Final.
Bob Jones EGEE Technical Director
David Kelsey CCLRC/RAL, UK
JRA3 Introduction Åke Edlund EGEE Security Head
LCG Security Status and Issues
Ian Bird GDB Meeting CERN 9 September 2003
Romain Wartel EGEE08 Conference, Istanbul, 23rd September 2008
David Kelsey CCLRC/RAL, UK
Leigh Grundhoefer Indiana University
Presentation transcript:

EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Dr Linda Cornwall CCLRC (RAL) FP6 Security workshop at NEC, Sankt Augustin, Germany, 8-9 th June 2006

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE Security Coordination Group, June 8-9, SCG mandate The Security Coordination Group (SCG) is responsible for ensuring the overall EGEE security coordination, including -architecture, -operations, -deployment, -standardisation and -cross-project collaboration. The goal is to ensure the relationship between the various security related work items inside EGEE do not -adversely overlap (leading to duplication of effort) or -leave gaps that could be exploited.

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE Security Coordination Group, June 8-9, SCG involved groups EUGridPMA Joint Security Policy Group MiddleWare Security Group Policies Architecture gLite Security Trust anchor IGTF chair Grid Security Vulnerability Group Operational Security Coordination Team Operations

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE Security Coordination Group, June 8-9, Members of SCG Ake Edlund  Security Head EGEE, Chair SCG  Chair MWSG - together with Bob Cowles (OSG) Dave Kelsey  Chair Joint Security Policy Group (JSPG)  Security Head EGEE deputy David Groep  Chair EUGridPMA liaison (EUGridPMA) Linda Cornwall  Chair Grid Security Vulnerability Group (GSVG) Ian Neilson  Chair Operational Security Coordination Team (OSCT)

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE Security Coordination Group, June 8-9, MWSG The MiddleWare Security Group Main Objective –Co-ordinate the evolving and deployed security architectures with other grid initiatives and standardization efforts Chairs –Ake Edlund (EGEE) –Bob Cowles (Open Science Grid, OSG) Members –Core security representatives from EGEE, OSG, Fermilab (USA) and Stanford Linear Accelerator (USA) –Representatives from the Applications/Development Clusters in EGEE –Representatives from DILIGENT, SEEGRID and GRIDCC, DEISA, NAREGI, UINICORE

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE Security Coordination Group, June 8-9, MWSG output so far Middleware security issues and release plans in EGEE –Security Architecture –gLite (EGEE software) Security Module work and release planning Main forum for integration of security into other gLite Middleware EGEE and OSG interoperability EGEE/OSG/Naregi Meeting Interoperability work in GGF

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE Security Coordination Group, June 8-9, Ongoing and future work OSG, EGEE collaboration –GSI (Grid Security Infrastructure) /SSL Authentication interoperability –Delegation –Proxy renewal –Authorization Attributes –Authorization Policy statements –What is needed for auditing –What is needed for Accounting Service Specification –All service interfaces should have written specifications  Internal to service – documented with service  Internal to project – documented with project  Grid interoperation – GGF

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE Security Coordination Group, June 8-9, MWSG meetings so far MWSG1, May 5-6 ‘04, Gap Analysis - “MWSG kick-off” MWSG2, June ‘04, gLite Release Plan MWSG3, Aug 25 ‘04, Security Architecture v1.0 MWSG4, Oct 15 ‘04, gLite development focus MWSG5, Feb ‘05, Workplan update MWSG at 3rd EGEE, EGEE/OSG/Naregi meeting MWSG6, Sept ‘05, OSG and EGEE formalizing the collaboration on security MWSG at 4th EGEE, April ‘05 MWSG7, Dec ‘05, New members, UNICORE presentation, Shib in EGEE MWSG8, March 7-8 ‘06, GSVG, glexec on WN, VO naming, TONIC MWSG9 at SLAC, June 5-6 ‘06, 1st OSG held MWSG meeting Meetings are a mix of presentations, updates of current status, technical discussions aiming at solving security issues and to produce decisions regarding the evolving security architecture. All presentations available from

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE Security Coordination Group, June 8-9, Joint Security Policy Group The Joint Security Policy Group Creates/maintains security policy and procedures –For use in EGEE, Large Hadron Collider Grid (LCG) and elsewhere Strong participation by USA Open Science Grid Growing participation by other EU Grid projects –DEISA, Diligent, SEE-Grid, … –BalticGrid, EELA, EUMedGrid, EUChinaGrid Aim for short, simple, interoperable policy documents Membership includes –Site Security Officers –Site/Resource Managers/Security Contact –Security middleware experts/developer –Deployment experts –Application representatives/VO managers

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE Security Coordination Group, June 8-9, EGEE/LCG Policy Security & Availability Policy Grid Acceptable Use Policy Certification Authorities Audit Requirements Incident Response User Registration & VO Management Application Development & Network Admin Guide picture from Ian Neilson VO Acceptable Use Policy

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE Security Coordination Group, June 8-9, JSPG Meetings, Web etc Meetings - Agenda, presentations, minutes etc JSPG Web site Policy documents at All policy documents are currently being revised –To make simpler, more general and interoperable

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE Security Coordination Group, June 8-9, OSCT Operational Security Coordination Team –Members:  Security Coordinators from each of the Regional Operations Centres  Chaired by Ian Neilson –Roles:  Members coordinate Grid Security at sites within Regions Handling of Security tickets from the Global Grid User Support Security contact management  Coordination of Grid Incident Handling Process Incident Handling and Response Guide from JSPG Cooperation with peer Grids  Execution of Security Service Challenges SSC1 – Job audit, checked availability of sufficient information and communication channels to trace a job adequately for the incident response process (completed March 2006) SSC2 – data management security audit planned –Meetings:  First face to face meeting planned June 2006

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE Security Coordination Group, June 8-9, OSCT

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE Security Coordination Group, June 8-9, Current SCG activity -In parallel with the overall SCG work, the SCG is to coordinate a new security auditing activity This activity will monitor both operations and middleware for security issues and report periodically on status and progress of the issues identified -The security audit will coordinate with the work done by the Grid Security Vulnerability Group -In addtion to the ongoing collaborations (see table below) we have industrial partners installing gLite internally, applying internal security audits reporting back to EGEE. E.g. CNAF (French Space Agency). -Current status: agreed plan due end on June; ongoing discussions with partners ActivityPartner Security audits, tools, policy documents review BARC - India Ethical hacking auditsPriceWaterhouseCoopers - Switzerland Additional input on middleware security, policy and organization Non-EGEE members in the joint security groups (MWSG, JSPG - mainly OSG input) Security Service Challenges testing the ability to operationally respond to incidents EGEE: Pal Anderssen (SA1) is coordinating the Security Service Challenges

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE Security Coordination Group, June 8-9, Links and events SCG related links –SCG web page: –SCG and MWSG meetings: –JSPG: –EGEE web page: –gLite web page: SCG related events in June 2006 –9th MWSG meeting, June 5-6, SLAC, USA –EGEE Workshop on Management of Rights in Production Grids at HPDC-15, June 19, Paris, France –SCG meeting on Security Auditing coordination, June

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE Security Coordination Group, June 8-9, Questions/discussion