INFSO-RI-508833 Enabling Grids for E-sciencE www.eu-egee.org Security Summary Åke Edlund, JRA3 4 th EGEE Conference Pisa, Italy 28 th October 2005.

Slides:



Advertisements
Similar presentations
2 nd APGrid PMA F2F Meeting Osaka University Convention Center October 15 09: :20 # Participants: 26.
Advertisements

Updates of the APGrid PMA Catania March 3, 2009 Yoshio Tanaka APGridPMA Chair, AIST, Japan.
Grid Security Policy GridPP18, Glasgow David Kelsey 21sr March 2007.
GGF16, Athens AuthZ Interoperability Here and Now Workshop, 16 Feb 2006.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
INFSO-RI Enabling Grids for E-sciencE Operational Security OSCT JSPG March 2006 Ian Neilson, CERN.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE-III Program of Work Erwin Laure EGEE-II / EGEE-III Transition Meeting CERN,
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks JRA2: Quality Assurance & Security Coordination.
EGI: A European Distributed Computing Infrastructure Steven Newhouse Interim EGI.eu Director.
The Grid Services Security Vulnerability and Risk Assessment Activity in EGEE-II Enabling Grids for E-sciencE EGEE-II INFSO-RI
EGEE ARM-2 – 5 Oct LCG Security Coordination Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Enabling Grids for E-sciencE EGEE III Security Training and Dissemination Mingchao Ma, STFC – RAL, UK OSCT Barcelona 2009.
INFSO-RI Enabling Grids for E-sciencE SA1: Cookbook (DSA1.7) Ian Bird CERN 18 January 2006.
LCG/EGEE Security Update HEPiX, Fall 2004 BNL, 18 October 2004 David Kelsey CCLRC/RAL, UK
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
INFSO-RI Enabling Grids for E-sciencE NA5 – Policy and International Cooperation Fotis Karayannis, Joanne Lawson, NA5 EGEE 4 th.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Ake Edlund EGEE Sec Head 9th MWSG meeting, SLAC,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
INFSO-RI Enabling Grids for E-sciencE NA5 – Policy and International Cooperation Panagiotis Louridas, Fotis Karagiannis, GRNET Final.
TAGPMA & the Bridge WG (Scott Rea – Dartmouth College) Internet2 Member Meeting, Dec 2006 PKI Activities and Applications Update - Chicago, IL.
INFSO-RI Enabling Grids for E-sciencE External Projects Integration Summary – Trigger for Open Discussion Fotis Karayannis, Joanne.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Linda Cornwall CCLRC (RAL) FP6 Security workshop.
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks SA1: Grid Operations Maite Barroso (CERN)
International Grid Trust Federation Session GGF 20 Manchester, UK Wednesday, May CAOPS-WG session #2.
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
INFSO-RI Enabling Grids for E-sciencE EGEE SA1 in EGEE-II – Overview Ian Bird IT Department CERN, Switzerland EGEE.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Dr Linda Cornwall CCLRC (RAL) FP6 Security workshop.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
JRA2: Quality Assurance Overview EGEE is proposed as a project funded by the European Union under contract IST JRA.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
Updates from the EUGridPMA David Groep, May 9 st, 2007.
Security Operations David Kelsey GridPP Deployment Board 3 Mar 2005
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
INFSO-RI Enabling Grids for E-sciencE JRA3 Security Åke Edlund, JRA3 Manager, KTH On behalf of JRA3 EGEE 2 nd EU Review.
INFSO-RI Enabling Grids for E-sciencE An overview of EGEE operations & support procedures Jules Wolfrat SARA.
Opening Remarks and Updates of the APGrid PMA 5 th APGridPMA September 16, 2008 Yoshio Tanaka APGridPMA Chair, AIST, Japan.
INFSO-RI Enabling Grids for E-sciencE Policy and International cooperation Fotis Karayannis, NA5 activity leader All Activity Meeting.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
Additional Services: Security and IPv6 David Kelsey STFC-RAL.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and JSPG activities David Kelsey CCLRC/RAL.
Security EGEE/SA1 ROC Managers ARM-3 meeting Lyon, 17 March 2005 David Kelsey CCLRC/RAL, UK
LHC Computing, SPC-FC-CC-C; H F Hoffmann1 CERN/2379/Rev: Proposal for building the LHC computing environment at CERN (Phase 1) Goals of Phase.
18-May-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) Barcelona 18 May 2004 David Kelsey CCLRC/RAL, UK
EGEE is a project funded by the European Union under contract INFSO-RI NA5 M. Heikkurinen NA5 Activity Manager All Activity Meeting, 13 th September.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks NA5: Policy and International Cooperation.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Technical Overview EGEE-II’s achievements.
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
EGEE is a project funded by the European Union under contract IST EGEE Security Åke Edlund Security Head EU IST-FP6 Concertation, 17 th September.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks NA5: Policy and International Cooperation.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
INFSO-RI Enabling Grids for E-sciencE Operational Security Coordination Team OSCT report EGEE-4, Pisa Ian Neilson, CERN.
INFSO-RI Enabling Grids for E-sciencE EGEE general project update Fotis Karayannis EGEE South East Europe Project Management Board.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Ake Edlund for JRA3 EGEE EU Review (CERN) May 23-24, 2006.
INFSO-RI Enabling Grids for E-sciencE Policy and International Cooperation Fotis Karayannis EGEE Second EU Review 7 December 2005.
INFSO-RI Enabling Grids for E-sciencE JRA3 Åke Edlund On behalf of JRA3 EGEE 8th All-activity meeting January 18-19,
Updates of APGrid PMA 18 th EUGridPMA Meeting 18 th EUGridPMA Meeting 18 January, 2010 Eric Yen ASGCCA Taiwan.
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE NA5 – Policy and International Cooperation Panagiotis Louridas, Fotis Karagiannis, GRNET Final.
Bob Jones EGEE Technical Director
JRA3 Introduction Åke Edlund EGEE Security Head
Grids & PKI: TAGPMA & Bridges (Scott Rea – Dartmouth College) Internet2 Member Meeting, Dec 2006 PKI Implementers Workshop - Chicago, IL.
LCG Security Status and Issues
Ian Bird GDB Meeting CERN 9 September 2003
Romain Wartel EGEE08 Conference, Istanbul, 23rd September 2008
David Kelsey CCLRC/RAL, UK
Presentation transcript:

INFSO-RI Enabling Grids for E-sciencE Security Summary Åke Edlund, JRA3 4 th EGEE Conference Pisa, Italy 28 th October 2005

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October Recap, Erwin’s summary on Monday - what have we done since Athens? Revised global security architecture. Secure credential storage procedures/recommendations document Middleware security group (MWSG) setting example for security interoperability between grid initiatives (EGEE, OSG, NAREGI) –To be used for GGF work. Official MWSG meeting at GGF16 Actively contributing to the gLite middleware EUGridPMA continued work and was instrumental to IGTF launched, –Chaired by David Groep (JRA3) –Coordinating European, Asian, and American GridPMAs Vulnerability analysis database created For remaining 2005 –Reinforce middleware security component development and interoperability –Overview and recommendation document on accounting techniques –Second revision of security operational procedures document. –Assessment of security infrastructure – Security Challenge

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October Security Summary Security related meetings in Pisa: - Operational Security (OCST) - SA1 - Security training - NA3 - Quality Assurance Group (QAG) - JRA2 - Biomedical meeting - NA4 - Joint Security Policy Group (JSPG) - SA1 - Middleware Security Group (MWSG) - JRA3 - Encrypted Storage Demo - NA4, JRA1, (JRA3) and many informal meetings, e.g. with Teragrid security and DILIGENT security. Focus in this presentation: - IGTF - MWSG - OSCT - “JRA3” in EGEE-II

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October Extending Trust: IGTF – the International Grid Trust Federation EUGridPMA All EU 6 th framework e-Infrastructure projects –EGEE –DEISA –SEE-GRID LHC Computing Grid Project (“LCG”) Open Science Grid (US) National projects, like (non-exhaustive): –UK eScience programme –Virtual Lab e-Science, NL –… Next slides: the rest of the world

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October Extending Trust: IGTF – the International Grid Trust Federation APGridPMA 13 members from the Asia-Pacific Region, chaired by Yoshio Tanaka (AIST) Launched June 1 st, ‘production-quality’ CAs Pioneered ‘experimental’ profile AIST (.jp) APAC (.au) BMG (.sg) CMSD (.in) HKU CS SRG (.hk) KISTI (.kr) NCHC (.tw) NPACI (.us) Osaka U. (.jp) SDG (.cn) USM (.my) IHEP Beijing (.cn) ASGCC (.tw)

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October Extending Trust: IGTF – the International Grid Trust Federation TAGPMA 10 members to date, chaired by Darcy Quesnel (Canarie) Launched June 28th, 2005 Pioneered new “SLCGS” (Kerberos CA & al.) Canarie (.ca) OSG (.us) TERAGRID (.us) Texas H.E. Grid (.us) DOEGrids (.us) SDSC (.us) FNAL (.us) Dartmouth (.us) Umich (.us) Brazil (.br)

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October Timeline March 2005: IGTF Draft Federation Document GGF13 June 28 th : TAGPMA founded at GGF14 July 27 th : APGridPMA approved draft 0.7 September: EUGridPMA meeting on approval October 3-4: formal foundation of the IGTF!

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October Extending Trust: IGTF – the International Grid Trust Federation TAGPMA APGridPMA common, global best practices for trust establishment better manageability and response of the PMAs The America’s Grid PMA Asia-Pacific Grid PMA European Grid PMA

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October MWSG MWSG have had 6 two day meetings so far, the outcome have been very useful, esp. with regards to the OSG relationship: - A good mix of people -Middleware developers - Security specialists - Operations - Applications -A good mix of presentations and hands-on technical discussions - Quite good spread of representatives -Europe: EGEE, DEISA(new), DILIGENT(new), GN2(invited), GRIDCC(new), SEEGRID(new) - US: OSG, FNAL, SLAC - Asia: NAREGI At the Pisa meeting we had representatives from EGEE, OSG, DEISA, SEEGRID and D-GRID

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October MWSG At Pisa we had some technical discussions regarding Delegation glexec Service authZ for Enctryped Storage Planning for the GGF16, where EGEE security will have a more visible role than ever before: –Authz workshop  “Interop here and now”, planning for the next ~2 years  Dave Kelsey (lead), Von Welch and Ake Edlund –MWSG info session  Outreach & dissemination (Ake Edlund) The 7th (2-day) MWSG meeting will be held at NIKHEF, Amsterdam, December 14-15

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October OSCT The Operational security Coordination Team (OSCT), lead by Ian Neilson (SA1), intends to offer common actions, documents and procedures for ROCs, that are applicable also to sites. Security Service Challenges by Pål Anderssen Described results and lessons from the Security Service Challange 1 and planned more regional specific incident events tracking by ROC's and sites. Grid Security Monitoring by Romain Wartel Described about currently added simple SFT (security functional tests) and rised the following questions: 1) How to extend SFT? What other SFT ext would be useful? 2) How to force convince site to do sec tests? Common opinion - very diffficult to add new items to Site FT One suggestions - introduce security metrics and grade sites by security features. This may be important for some sensitive jobs/tasks. ROC can force sites but need good description of critical problems 3) How to implement check of patching status of Grid nodes? - no commonly agreed solution suggested.

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October OSCT (cont.) Grid Incident Response presented by Ian Neilson Requested more comments on the recently posted document. Meeting agreed that this work should be continued. OSCT/ROC's incident response can not be outsourced to ordinary CSIRT (as somebody asked) because Grid Incident handling involves contacting ROC's and grid sites. JRA3 can contribute to: 1 - Incident response document 2 - defining new items for Security Functional Test based on vulnerabilities analysis 3 - providing feedback from Security challange 2 to MWSG and JRA3 NOTE: These minutes and comments by Yuri Demchenko, JRA3

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October EGEE-II Security EGEE-I Security is already a distributed activity: - Middleware security in JRA1 - Operational security in SA1 - EUGridPMA work, in SA1 - Possible external security audit work The changes in EGEE-II are not very big: -The EGEE-I/JRA3 developers will become EGEE-II/JRA1 developers -The EGEE-I/JRA3/Security Architect will become EGEE-II/JRA1/Security Architect -The operational security work will continue to be handled by SA1(JSPG, OSCT) New: Security Coordination Group, lead by the Security Head. Described on the next slide. New: Shibboleth project (JRA1), lead by SWITCH (*). (*)Interoperability of Shibboleth-based Authentication and Authorization Infrastructures with EGEE Security Framework (Christoph Witzig )

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October EGEE-II Overall security coordination The Security Coordination Group (SCG) is responsible for ensuring overall EGEE-II security coordination, includes architecture, deployment, standardisation and cross-project concertation. The goal is to ensure the relationship between the various security-related work items inside the project do not: - adversely overlap (leading to duplication of effort) or - leave gaps that could be exploited. In addition, the SCG is to coordinate a new security auditing activity. This activity will monitor both operations and middleware for security issues and report periodically on status and progress of the issues identified. The security audit will leverage the work of the Grid vulnerability issues group. The Security Head (JRA2) - will lead the Security Coordination Group (SCG) and the security audit task. - responsible for representing the security aspects of the project in EU security concertation bodies and, ultimately in collaborations with other projects. - will have a continue to have a position on the Project Execution Board (PEB) to ensure security aspects are represented at the project management level.

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October EGEE-II Overall security coordination Security Coordination Group (SCG) members: The Security Head, chair of the SCG (JRA2) The chair of the Middleware Security Group (JRA1) The chair of the Joint Security Policy Group (SA1) The EUGridPMA liaison (SA1) The chair of the Grid vulnerability issues group (SA1) EUGridPMA liaison Middleware security group Joint security policy group Grid Vulnerability issues group

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October What else to report from Pisa? Well

Enabling Grids for E-sciencE INFSO-RI th EGEE conference - 24 th October We did a lot of knowledge transfer! OSG MWSG JRA3 CSC JSPG OSCT (behind Dave) SA1