Sep 25, 20071/5 Grid Services Activities on Security Gabriele Garzoglio Grid Services Activities on Security Gabriele Garzoglio Computing Division, Fermilab.

Slides:



Advertisements
Similar presentations
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Advertisements

Dec 14, 20061/10 VO Services Project – Status Report Gabriele Garzoglio VO Services Project WBS Dec 14, 2006 OSG Executive Board Meeting Gabriele Garzoglio.
Role Based VO Authorization Services Ian Fisk Gabriele Carcassi July 20, 2005.
CMS Applications Towards Requirements for Data Processing and Analysis on the Open Science Grid Greg Graham FNAL CD/CMS for OSG Deployment 16-Dec-2004.
Implementing Finer Grained Authorization in the Open Science Grid Gabriele Carcassi, Ian Fisk, Gabriele, Garzoglio, Markus Lorch, Timur Perelmutov, Abhishek.
Open Science Grid Use of PKI: Wishing it was easy A brief and incomplete introduction. Doug Olson, LBNL PKI Workshop, NIST 5 April 2006.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 01/29/2014.
Open Science Grid Software Stack, Virtual Data Toolkit and Interoperability Activities D. Olson, LBNL for the OSG International.
Status of the Adoption of a SAML-XACML Profile for Authorization Interoperability across Grid Middleware 1/17 Status of the Adoption of a SAML-XACML Profile.
OSG Services at Tier2 Centers Rob Gardner University of Chicago WLCG Tier2 Workshop CERN June 12-14, 2006.
OSG Middleware Roadmap Rob Gardner University of Chicago OSG / EGEE Operations Workshop CERN June 19-20, 2006.
VOX Project Status T. Levshina. Talk Overview VOX Status –Registration –Globus callouts/Plug-ins –LRAS –SAZ Collaboration with VOMS EDG team Preparation.
May 8, 20071/15 VO Services Project – Status Report Gabriele Garzoglio VO Services Project – Status Report Overview and Plans May 8, 2007 Computing Division,
2005 © SWITCH Perspectives of Integrating AAI with Grid in EGEE-2 Christoph Witzig Amsterdam, October 17, 2005.
Apr 30, 20081/11 VO Services Project – Stakeholders’ Meeting Gabriele Garzoglio VO Services Project Stakeholders’ Meeting Apr 30, 2008 Gabriele Garzoglio.
Mine Altunay OSG Security Officer Open Science Grid: Security Gateway Security Summit January 28-30, 2008 San Diego Supercomputer Center.
SAMGrid as a Stakeholder of FermiGrid Valeria Bartsch Computing Division Fermilab.
Security Area in GridPP2 4 Mar 2004 Security Area in GridPP2 “Proforma-2 posts” overview Deliverables – Local Access – Local Usage.
Mar 28, 20071/9 VO Services Project Gabriele Garzoglio The VO Services Project Don Petravick for Gabriele Garzoglio Computing Division, Fermilab ISGC 2007.
OSG Security Review Mine Altunay December 4, 2008.
VOMRS/VOMS-Admin Convergence and VO Services Project Status Tanya Levshina Computing Division, Fermilab.
May 11, 20091/17 VO Services Project – Stakeholders’ Meeting Gabriele Garzoglio VO Services Project Stakeholders’ Meeting May 11, 2009 Gabriele Garzoglio.
Mar 28, 20071/18 The OSG Resource Selection Service (ReSS) Gabriele Garzoglio OSG Resource Selection Service (ReSS) Don Petravick for Gabriele Garzoglio.
Grid User Management System Gabriele Carcassi HEPIX October 2004.
Jan 10, 20091/16 VO Services Project – Stakeholders’ Meeting Gabriele Garzoglio VO Services Project Stakeholders’ Meeting Jan 10, 2009 Gabriele Garzoglio.
Global Grid Forum GridWorld GGF15 Boston USA October Abhishek Singh Rana and Frank Wuerthwein UC San Diegowww.opensciencegrid.org The Open Science.
Status of the Adoption of a SAML-XACML Profile for Authorization Interoperability across Grid Middleware 1/18 Status of the Adoption of a SAML-XACML Profile.
Partnerships & Interoperability - SciDAC Centers, Campus Grids, TeraGrid, EGEE, NorduGrid,DISUN Ruth Pordes Fermilab Open Science Grid Joint Oversight.
OSG Area Coordinator’s Report: Workload Management Maxim Potekhin BNL
Mine Altunay July 30, 2007 Security and Privacy in OSG.
Status of the Adoption of a SAML-XACML Profile for Authorization Interoperability across Grid Middleware 1/17 Status of the Adoption of a SAML-XACML Profile.
Ruth Pordes November 2004TeraGrid GIG Site Review1 TeraGrid and Open Science Grid Ruth Pordes, Fermilab representing the Open Science.
Overview of Privilege Project at Fermilab (compilation of multiple talks and documents written by various authors) Tanya Levshina.
Role Based VO Authorization Services Ian Fisk Gabriele Carcassi July 20, 2005.
US LHC OSG Technology Roadmap May 4-5th, 2005 Welcome. Thank you to Deirdre for the arrangements.
Apr 26, 20071/3 OSG Executive Board Meeting Gabriele Garzoglio OSG Executive Board Meeting Gabriele Garzoglio VO Services, PL Computing Division, Fermilab.
Oct 19, 20101/16 Adoption of a SAML-XACML Profile for Authorization Interoperability across Grid Middleware in OSG and EGEE CHEP 2010 Oct 19, 2010 Gabriele.
OSG Integration Activity Report Rob Gardner Leigh Grundhoefer OSG Technical Meeting UCSD Dec 16, 2004.
VO Privilege Activity. The VO Privilege Project develops and implements fine-grained authorization to grid- enabled resources and services Started Spring.
OSG AuthZ components Dane Skow Gabriele Carcassi.
Open Science Grid & its Security Technical Group ESCC22 Jul 2004 Bob Cowles
April 26, Executive Director Report Executive Board 4/26/07 Things under control Things out of control.
VO Membership Registration Workflow, Policies and VOMRS software (VOX Project) Tanya Levshina Fermilab.
Jun 12, 20071/17 AuthZ Interoperability – Status and Plan Gabriele Garzoglio AuthZ Interoperability Status and Plans June 12, 2007 Middleware Security.
AstroGrid-D Meeting MPE Garching, M. Braun VO Management.
Virtual Organization Membership Service eXtension (VOX) Ian Fisk On behalf of the VOX Project Fermilab.
Eileen Berman. Condor in the Fermilab Grid FacilitiesApril 30, 2008  Fermi National Accelerator Laboratory is a high energy physics laboratory outside.
OSG Area Coordinator’s Report: Workload Management Maxim Potekhin BNL May 8 th, 2008.
Jun 18, 20071/26 Security Policies and Middleware in OSG Gabriele Garzoglio Security Policies and Middleware in OSG June 18, 2007 JRA1 All Hands Meeting.
Parag Mhashilkar Computing Division, Fermi National Accelerator Laboratory.
Открытая решетка науки строя открытое Cyber- инфраструктура для науки GRID’2006 Dubna, Россия Июнь 26, 2006 Robertovich Gardner Университет Chicago.
Sep 17, 20081/16 VO Services Project – Stakeholders’ Meeting Gabriele Garzoglio VO Services Project Stakeholders’ Meeting Sep 17, 2008 Gabriele Garzoglio.
VOX Project Status T. Levshina. 5/7/2003LCG SEC meetings2 Goals, team and collaborators Purpose: To facilitate the remote participation of US based physicists.
Feb 15, 20071/6 OSG EB Meeting – VO Services Status Gabriele Garzoglio VO Services Status OSG EB Meeting Feb 15, 2007 Gabriele Garzoglio, Fermilab.
Site Authorization Service Local Resource Authorization Service (VOX Project) Vijay Sekhri Tanya Levshina Fermilab.
The Resource Selection Service (ReSS) Activity Gabriele Garzoglio Fermilab, Computing Division March 14, 2006.
1 Open Science Grid.. An introduction Ruth Pordes Fermilab.
Towards deploying a production interoperable Grid Infrastructure in the U.S. Vicky White U.S. Representative to GDB.
1 Open Science Grid: Project Statement & Vision Transform compute and data intensive science through a cross- domain self-managed national distributed.
OSG Status and Rob Gardner University of Chicago US ATLAS Tier2 Meeting Harvard University, August 17-18, 2006.
VO Management Tanya Levshina Computing Division, Fermilab.
Grid Deployment Technical Working Groups: Middleware selection AAA,security Resource scheduling Operations User Support GDB Grid Deployment Resource planning,
Parag Mhashilkar Computing Division, Fermilab.  Status  Effort Spent  Operations & Support  Phase II: Reasons for Closing the Project  Phase II:
April 18, 2006FermiGrid Project1 FermiGrid Project Status April 18, 2006 Keith Chadwick.
Abhishek Singh Rana and Frank Wuerthwein UC San Diegowww.opensciencegrid.org The Open Science Grid ConsortiumCHEP 2006 Mumbai INDIA February gPLAZMA:
VOX Project Status Report Tanya Levshina. 03/10/2004 VOX Project Status Report2 Presentation overview Introduction Stakeholders, team and collaborators.
Grid Colombia Workshop with OSG Week 2 Startup Rob Gardner University of Chicago October 26, 2009.
OSG User Group August 14, Progress since last meeting OSG Users meeting at BNL (Jun 16-17) –Core Discussions on: Workload Management; Security.
Gene Oleynik, Head of Data Storage and Caching,
AuthZ Interop report out
Presentation transcript:

Sep 25, 20071/5 Grid Services Activities on Security Gabriele Garzoglio Grid Services Activities on Security Gabriele Garzoglio Computing Division, Fermilab Grid Coordination Meeting Sep 25, 2007 Overview Grid Services Tactical Plan VO Services Activities ReSS and Other Activities

Sep 25, 20072/5 Grid Services Activities on Security Gabriele Garzoglio Grid Services Tactical Plan 1.Develop features and improve robustness of the VO Services infrastructure […]. 2.Extend deployment of and support the VO Services infrastructure […] 3.Integrate standard authorization call-out libraries, […] in order to enable interoperability […]. 4.Integrate support for emerging standards and increasingly complex use cases in the VO Service infrastructure. […] 5.Provide maintenance and support for the ReSS WMS […]. Understand operational needs for the infrastructure. Support and Improvement of the “base” infrastructure Authorization Interoperability Next Generation Storage AuthZ Models Privilege Policy Management Other Activities Tactical PlanThis Talk

Sep 25, 20073/5 Grid Services Activities on Security Gabriele Garzoglio VO Services VO user membership management and fine-grained authorization to Grid resources Vision / Driving Forces for Phase III ( Status report at ) –keeping the pace with new security paradigms –providing excellent support for the current infrastructure –reducing overall maintenance Stakeholders –USCMS, OSG, FNAL VOs (Astronomy, Run II, …), FermiGrid, Storage at FNAL –Representatives contacted: Burt Holzman, Ian Fisk, Mine Altunay, John Weigand, Doug Benjamin, Jim Annis, Timur Perelmutov Base Infrastructure –PRIMA, GUMS, VOMRS – VO Services proj. –gLexec – VO Services proj. See Igor’s talk –gPlazma – Interfacing with dCache proj. Effort –FNAL 1.1 FTE (0.6 CD CMS); Total 1.6 FTE (FNAL BNL)

Sep 25, 20074/5 Grid Services Activities on Security Gabriele Garzoglio VO Services Activities 1 Support and Improvement of the “base” infrastructure (High Priority) –Ongoing. FNAL 0.6 FTE –Foci: (1) Robustness and Usability; (2) VOMRS vital features –Stakeholders: FermiGrid, BNL, USCMS, OSG VO’s, OSG Facility ? Authorization Interoperability (Medium Priority) –Enables Middleware developed in the US (e.g. SRM) to use EU Authorization infrastructure and vice versa. Collaboration with EGEE and Globus –Stakeholders: USCMS, Software Providers (Globus, OSG group, dCache, Condor ?, …) –Milestones: Date (activity) (FTE) Aug 07 (alpha; met) (0.1) – Dec 07 (beta) (0.2) – Feb 08 (beta Integration) (0.5) – Apr 08 (v1) (0.2) – Jun 08 (v1 Int.) (0.5)

Sep 25, 20075/5 Grid Services Activities on Security Gabriele Garzoglio VO Services Activities 2 Support Storage Groups in Defining Next Generation Storage AuthZ Models (Medium Priority) –Interaction with storage projects at FNAL (SRM/dCache, OSG Ext. and VDT) –Stakeholders: OSG, USCMS –VO Service 0.1 FTE (Consulting Role) upon request Privilege Policy Management (Medium Priority) –Allows VO’s to express privileges directly; Sites to implement and verify privileges. Evaluation and prototypical work. Collaboration with TechX, funded via SBIR Phase I –Stakeholders: OSG –FNAL ~ 0.1 FTE from VO Service Proj. (Customer / Stakeholder role) –Plan in progress. Duration 9 months. –Deliverables: Policy schema/language (3 0.2? FNAL) Policy tools (6 0.1? FNAL)

Sep 25, 20076/5 Grid Services Activities on Security Gabriele Garzoglio Other Activities Requests from VO Service Proj. Stakeholders. May lack available effort. (Low Priority) –Attribute Certificate Validation at Resource Gateway Depends on acceptance and deployment of new VOMS –Broaden / Standard AuthZ call-out Interfaces Needed for Accounting. May lower overall maintenance. –Site Validation Service (Authentication Service) –Integrating Shibboleth Attribute Authority –End-to-end security / Epensys (see Igor) Authenticate Client Access to ReSS central services (Low Priority) –Once a user community is formed (during OSG 0.8.0), restrict access to providers and requesters of information