OSG Area Coordinators Meeting Security Team Report Mine Altunay 02/13/2012.

Slides:



Advertisements
Similar presentations
OSG PKI RA Training Mine Altunay, Jim Basney OSG PKI Team October 1, 2012.
Advertisements

OSG Area Coordinators Meeting Security Team Report Mine Altunay 04/02/2014.
DoD Information Technology Security Certification and Accreditation Process (DITSCAP) Phase III – Validation Thomas Howard Chris Pierce.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 05/15/2013.
Jan 2010 Current OSG Efforts and Status, Grid Deployment Board, Jan 12 th 2010 OSG has weekly Operations and Production Meetings including US ATLAS and.
Secure System Administration & Certification DITSCAP Manual (Chapter 6) Phase 4 Post Accreditation Stephen I. Khan Ted Chapman University of Tulsa Department.
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
Key Accomplishments and Work Plans OSG Security Team July 11, 2012.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 01/29/2014.
OSG Area Coordinators Meeting Operations Rob Quick 2/22/2012.
OSG Area Coordinators Meeting Cross-ProjectArea Report Ruth Pordes 2/8/2011.
Key Project Drivers - FY11 Ruth Pordes, June 15th 2010.
CILogon OSG CA Mine Altunay Jim Basney TAGPMA Meeting Pittsburgh May 27, 2015.
OSG Area Coordinators Meeting Operations Rob Quick 2/22/2012.
OSG Area Coordinators Meeting Security Team Report Kevin Hill 08/14/2013.
OSG Operations Rob Quick July 10th, 2012 OSG Staff Retreat.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Future support of EGI services Tiziana Ferrari/EGI.eu Future support of EGI.
OSG Security Review Mine Altunay June 19, June 19, Security Overview Current Initiatives  Incident response procedure – top priority (WBS.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 12/21/2011.
Deliverable Readiness Review LexEVS 5.1 December 17, 2009.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 06/25/2014.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
EMI is partially funded by the European Commission under Grant Agreement RI Post EMI Plans and MeDIA Alberto DI MEGLIO, CERN Project Director WLCG.
May 8, 20071/15 VO Services Project – Status Report Gabriele Garzoglio VO Services Project – Status Report Overview and Plans May 8, 2007 Computing Division,
OSG Security Kevin Hill. Goals Operational Security – Identify software vulnerabilities – observing the practices of our VOs and sites, and sending alerts.
Blueprint Meeting Notes Feb 20, Feb 17, 2009 Authentication Infrastrusture Federation = {Institutes} U {CA} where both entities can be empty TODO1:
PanDA Multi-User Pilot Jobs Maxim Potekhin Brookhaven National Laboratory Open Science Grid WLCG GDB Meeting CERN March 11, 2009.
JSPG: User-level Accounting Data Policy David Kelsey, CCLRC/RAL, UK LCG GDB Meeting, Rome, 5 April 2006.
J OINING OSG Suchandra Thapa Computation Institute University of Chicago.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 04/3/2013.
Evolution of the Open Science Grid Authentication Model Kevin Hill Fermilab OSG Security Team.
OSG Security Review Mine Altunay December 4, 2008.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay OSG Security Officer.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 8/15/2012.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
OSG PKI Contingency and Recovery Plans Mine Altunay, Von Welch OSG Council August 23, 2012.
OSG PKI Contingency and Recovery Plans Mine Altunay, Von Welch October 16, 2012.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 11/02/2011.
Mine Altunay July 30, 2007 Security and Privacy in OSG.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 6/6/2012.
Meeting Minutes and TODOs TG has no distributed monitoring. During incident response, use a manual twiki page to distribute information TG monitors the.
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
G Z LIGO's Physics at the Information Frontier Grant and OSG: Update Warren Anderson for Patrick Brady (PIF PI) OSG Executive Board Meeting Caltech.
Status Organization Overview of Program of Work Education, Training It’s the People who make it happen & make it Work.
OSG RA, DOEGrids CA features Doug Olson, LBNL August 2006.
Jan 2010 OSG Update Grid Deployment Board, Feb 10 th 2010 Now having daily attendance at the WLCG daily operations meeting. Helping in ensuring tickets.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 4/11/2012.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
Security Policy Update WLCG GDB CERN, 8 Dec 2010 David Kelsey STFC/RAL david.kelsey AT stfc.ac.uk.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay, James Basney,
User Support of WLCG Storage Issues Rob Quick OSG Operations Coordinator WLCG Collaboration Meeting Imperial College, London July 7,
LCG Pilot Jobs + glexec John Gordon, STFC-RAL GDB 7 December 2007.
WLCG Operations Coordination report Maria Alandes, Andrea Sciabà IT-SDC On behalf of the WLCG Operations Coordination team GDB 9 th April 2014.
OSG Security: Updates on OSG CA & Federated Identities Mine Altunay, PhD OSG Security Team OSG AHM March 24, 2015.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
Open Science Grid Security Activities D. Olson, LBNL OSG Deputy Security Officer For the OSG Security Team: M. Altunay, FNAL, OSG Security Officer, D.O.,
OSG PKI Transition Mine Altunay OSG Security Officer
OSG Area Coordinators Meeting Security Team Report Mine Altunay 8/15/2012.
Ruth Pordes, March 2010 OSG Update – GDB Mar 17 th 2010 Operations Services 1 Ramping up for resumption of data taking. Watching every ticket carefully.
Running User Jobs In the Grid without End User Certificates - Assessing Traceability Anand Padmanabhan CyberGIS Center for Advanced Digital and Spatial.
Certificate Security For Users Obtaining and Using Your Personal Certificate using the OSG PKI Kyle Gross – OSG Operations Support Lead Elizabeth Prout.
News from EUGridPMA EGI OMB, 22 Jan 2013 David Kelsey (STFC) Using notes from David Groep 22/01/20131EUGridPMA News.
New OSG Virtual Organization Security Training OSG Security Team.
IGTF Risk Assessment Team 5/11/091.
OSG Security Review Mine Altunay March 12, Jan Security Overview Current Initiatives  OSG Security roadmap  Technical and operational.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI SA1.2 Plans 2013 Security Operations David Kelsey (STFC) 26/02/2013 Operations.
OSG Security Kevin Hill.
Open Science Grid Consortium Meeting
Leigh Grundhoefer Indiana University
Presentation transcript:

OSG Area Coordinators Meeting Security Team Report Mine Altunay 02/13/2012

Key Initiatives Increasing CILogon Basic CA Adoption in OSG – Two facets of work: 1) work with sites to help them understand why and how to accept CILogon Basic CA. – MWT2, Purdue, Sprace, Nebraska, BNL agreed to accept the CILogon CA certs for access to grid resources. – OSG IT services was in testing mode the last time I reported. Tests are completed and now CILogon Basic Cas are acceted by production IT services. Had a small hiccup with Fermilab. Originally the policy change was accepted, but then I was asked to take this to CIO for official approval. Approval is obtained.

Key Initiatives Enhancing Site Security – Pakiti service – Software is released in January. – Now working on publicizing the work. A tutorial and demo session at AHM. An OSG Newsletter article to sites. Survey of How OSG Resource Providers consume Identity Information – What type of identity information RPs are interested in and currently are looking at. Why? How they use it? – Need guidance about the next steps. Should we revisit our answers from interviewed sites or reach out to new sites? – Or should we close the work item? Identity Management Roadmap – Finished the first draft with Von. Only received feedback from Lothar so far. Need feedback from area coordinators. New Key Work Item – Traceability Requirements for end user jobs without certificates. – Goal is to work in collaboration with Fermilab to accept these requirements so as to allow certificate-less jobs at Fermilab. The future goal is to publicize this document to other sites and to seek their acceptance. – Finished the policy document and gained personal approval from Fermilab CISO. – Still a long process to go to obtain official approvals from Fermilab Security Board. Lothar will sponsor the request as a Fermilab resource manager for CMS.

Concerns OSG PKI transition. – Team contribution increases as the DigiCert deadlines approach. – Kevin in particular dedicated 60% of his time to Fermilab PKI. – He was earlier supposed to help with Cilogon Basic (reaching out to more sites) and CVMFS review. But with extra effort spent on Fermilab PKI, Cilogon Basic will slow down and I will complete CVMFS work. – Not sure how long more we will keep providing extra effort to Fermilab PKI project. Will ask the project lead.

WBS Ongoing Activities 1Incident response and vulnerability assessment Minimizing the end-end response time to an incident, 1 day for a severe incident, 1 week for a moderate incident, and 1 month for a low-risk incient. 2Troubleshooting; processing security tickets including user requests, change requests from stakeholders, technical problems Goal is to acknowledge tickets within one day of receipt. 3Maintaining security scripts (vdt-update-certs, vdt-ca-manage, cert-scripts, etc) Maintain and provide bug fixes according to the severity of bugs. For urgent problems, provide an update in one week; For moderate severity, provide an update in a month; For low risk problems, provide an update in 6 months. 4XSEDE Operational Security Interface Meet weekly 5Supporting OSG RA in processing certificate requests Each certificate request is resolved within one week; requests for GridAdmin and RA Agents are served within 3 days. 6Preparing CA releases (IGTF), modifying OSG software as the changes in releases require CA release for every two months 7Security Policy work with IGTF, TAGPMA, JSPG and EGI Meet with IGTF and TAGPMA twice a year. Attend JSPG and EGI meteings remotely and face-face once a year. Track security policy changes and report to OSG management. 8Security Test and Controls Execute all the controls included in the Security Plan and prepare a summary analysis. 9 Incident Drills and Training Drill Tier3 sites 10Weekly Security Team Meeting to review work items Coordinate weekly work it ems. 11Weekly reporting to OSG-Production Report important items that will affect production; incidents, vulnerabilities, changes to PKI infrastructure 12Monthly reporting to OSG-ET Meet with ET once a month to discuss work items 13Quarterly reporting to Area Coordinator meeting Meet with area coordinators to discuss work items.

Operational Security 1.Checking sites against Condor Vulnerabilities. 75+ gatekeepers have been tested by security team. 2 tickets are open. Good progress made by site admins 2.SHA-2 tests completed for DOEgrids CA. I want to repeat the tests for DigiCert. We agreed to start in April at the latest production call. Digicert agreed to provide test certs. 3.In relation to sha-2 transition, we started a risk assessment of md5 and sha-1 user proxies. Need to understand how the proxies will be affected by the security vulnerabilities of SHA-1. 4.Security assessment of fetch-crl v3 is completed and recommended for SL5.

Operational Security 5.CVMFS/Oasis evaluation. Security evaluation started this week. In addition to GOC services, I am also evaluating the CVMFS service ran at Fermilab. This work will take at least two more weeks or more depending on GOC availability and the effort to investigate and implement the security team’s feedback. 6.Preparing for a GlideinWMS drill. Only OSG-security team, no EGI or WLCG involvement. Completely internal security exercise. 1.Will send jobs to OSG VO frontend and measure the traceability capability. Plan to start once Mats Rynge is back from vacation (two weeks from now).