7-May-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Issues and Planning or Report from the Security Group CERN, 8 May 2003 David Kelsey CCLRC/RAL, UK.

Slides:



Advertisements
Similar presentations
5-Dec-02D.P.Kelsey, GridPP Security1 GridPP Security UK Security Workshop 5-6 Dec 2002, NeSC David Kelsey CLRC/RAL, UK
Advertisements

29 June 2006 GridSite Andrew McNabwww.gridsite.org VOMS and VOs Andrew McNab University of Manchester.
11-Dec-01D.P.Kelsey, Authentication1 Authentication 11 Dec 2001 David Kelsey CLRC/RAL, UK
Andrew McNab - EDG Access Control - 14 Jan 2003 EU DataGrid security with GSI and Globus Andrew McNab University of Manchester
Authorization WG Update David Kelsey EU Grid PMA, Copenhagen 27 May 2008.
5-Sep-02D.P.Kelsey, Security Summary, Budapest1 WP6/7 Security Summary Budapest 5 Sep 2002 David Kelsey CLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
National Center for Supercomputing Applications Integrating MyProxy with Site Authentication Jim Basney Senior Research Scientist National Center for Supercomputing.
Grid Security in EGEE/LCG ISGC 2005, Taipei, Taiwan 29 April 2005 David Kelsey CCLRC/RAL, UK
Open Science Grid Use of PKI: Wishing it was easy A brief and incomplete introduction. Doug Olson, LBNL PKI Workshop, NIST 5 April 2006.
30-Jan-03D.P.Kelsey, GridPP Security1 Security GridPP6 30 Jan 2003 Coseners House David Kelsey CLRC/RAL, UK
Authentication Policy David Kelsey CCLRC/RAL 15 April 2004, Dublin
Security Mechanisms The European DataGrid Project Team
\ Grid Security and Authentication1. David Groep Physics Data Processing group Nikhef.
The EU Grid PMA David Kelsey CCLRC/RAL 16 April 2004, Dublin
Joining the Grid Andrew McNab. 28 March 2006Andrew McNab – Joining the Grid Outline ● LCG – the grid you're joining ● Related projects ● Getting a certificate.
C. Loomis – Testbed: Status… – Sep. 5, 2002 – 1 Testbed: Status & Plans Charles Loomis (CNRS) Sept. 5, th Project Conference (Budapest)
RomeWorkshop on eInfrastructures 9 December LCG Progress on Policies & Coming Challenges Ian Bird IT Division, CERN LCG and EGEE Rome 9 December.
Andrew McNab - Manchester HEP - 5 July 2001 WP6/Testbed Status Status by partner –CNRS, Czech R., INFN, NIKHEF, NorduGrid, LIP, Russia, UK Security Integration.
13-May-03D.P.Kelsey, WP8 CA and VO organistion1 CA’s and Experiment (VO) Organisation WP8 Meeting EDG Barcelona, 13 May 2003 David Kelsey CCLRC/RAL, UK.
12-May-03D.P.Kelsey, SCG Online Authentication1 Online Authentication SCG Meeting EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
20-May-03D.P.Kelsey, LCG-1 Security, HEPiX1 Grid Security for LCG-1 HEPiX, NIKHEF, 20 May 2003 David Kelsey CCLRC/RAL, UK
LCG/EGEE Security Update HEPiX, Fall 2004 BNL, 18 October 2004 David Kelsey CCLRC/RAL, UK
DataGrid WP6 CA meeting, CERN, 12 December 2002 IISAS Certification Authority Jan Astalos Department of Parallel and Distributed Computing Institute of.
9-May-02D.P.Kelsey, Security Plans, GridPP41 Security: Plans 9 May 2002 GridPP4 meeting, Manchester David Kelsey CLRC/RAL, UK
Security Area in GridPP2 4 Mar 2004 Security Area in GridPP2 “Proforma-2 posts” overview Deliverables – Local Access – Local Usage.
DOE Grids New subordinate CP/CPS v2.3 New subordinate CP/CPS v2.3 New name DOEGrids.org New name DOEGrids.org Old name DOESciencegrid.org Old name DOESciencegrid.org.
TERENA TF-EMC2 Workshop David Groep,
EU DataGrid (EDG) & GridPP Authorization and Access Control User VOMS C CA 2. certificate dn, ca, key 1. request 3. certificate 4. VOMS cred: VO, groups,
10-Jun-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 10 June 2003 David Kelsey CCLRC/RAL, UK
DataGrid WP6/CA CA Trust Matrices Trinity College Dublin (TCD) Brian Coghlan CERN DEC-2002.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
9-Sep-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 9 September 2003 David Kelsey CCLRC/RAL, UK
23-Oct-03D.P.Kelsey, LCG Security Update, HEPiX1 LCG Security Update HEPiX-HEPNT, TRIUMF, 23 October 2003 David Kelsey CCLRC/RAL, UK
8-Jul-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) RAL, 8 July 2003 David Kelsey CCLRC/RAL, UK
3-Nov-00D.P.Kelsey, HEPiX, JLAB1 Certificates for DataGRID David Kelsey CLRC/RAL, UK
Ákos FROHNER – DataGrid Security n° 1 Security Group D7.6 Design Ideas
10-May-01D.P.Kelsey, Security Workshop Summary1 DataGrid Security Workshop 29/30 March 2001 SUMMARY David Kelsey CLRC/RAL, UK
3-Jul-02D.P.Kelsey, Security1 Security meetings Report to EDG PTB 3 Jul 2002 David Kelsey CLRC/RAL, UK
Security Mechanisms The European DataGrid Project Team
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
9-Oct-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) FNAL 9 October 2003 David Kelsey CCLRC/RAL, UK
23-Oct-02D.P.Kelsey, Grid Security, HEPiX, FNAL1 LCG/EDG Security - update and plans HEPiX/HEPNT - FNAL 23 Oct 2002 David Kelsey CLRC/RAL, UK
2-Sep-02D.P.Kelsey, WP6 CA, Budapest1 WP6 CA report Budapest 2 Sep 2002 David Kelsey CLRC/RAL, UK
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
11-Dec-00D.P.Kelsey, Certificates, WP6 meeting, Milan1 Certificates for DataGrid Testbed0 David Kelsey CLRC/RAL, UK
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and JSPG activities David Kelsey CCLRC/RAL.
8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
12-Jun-03D.P.Kelsey, CA meeting1 CA meeting Minimum Requirements CERN, 12 June 2003 David Kelsey CCLRC/RAL, UK
18-May-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) Barcelona 18 May 2004 David Kelsey CCLRC/RAL, UK
The GRIDS Center, part of the NSF Middleware Initiative Grid Security Overview presented by Von Welch National Center for Supercomputing.
15-May-03D.P.Kelsey, SCG Summary1 Security Coord Group (SCG) EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
10-May-01D.P.Kelsey, WP6 Security1 Certificates/Authorisation for DataGrid Testbeds David Kelsey CLRC/RAL, UK
11-May-01D.P.Kelsey, Security Update1 GRID Security Update David Kelsey CLRC/RAL, UK
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI VOMS Proxy Lifetime UCB 21 Aug 2012 David Kelsey STFC.
DataGrid Security Wrapup Linda Cornwall 4 th March 2004.
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
David Kelsey CLRC/RAL, UK
Testbed: Status & Plans
David Kelsey CCLRC/RAL, UK
LCG Security Status and Issues
David Kelsey CCLRC/RAL, UK
David Kelsey CCLRC/RAL, UK
The EU DataGrid Security Services
The EU DataGrid Security Services
Presentation transcript:

7-May-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Issues and Planning or Report from the Security Group CERN, 8 May 2003 David Kelsey CCLRC/RAL, UK Draft for discussion at LCG SEC meeting 7 May

7-May-03D.P.Kelsey, LCG-GDB-Security2 Authentication - Trust Two main issues –Who defines the list of trusted CA’s? LCG or other Grid projects? –How to introduce new types of CA (online)? E.g. Kerberos CA at FNAL LCG-1 and EDG Application testbed –closely linked –Common approach desirable (for this year) For Jan 2004 onwards –Need to consider when fate of EGEE proposal known

7-May-03D.P.Kelsey, LCG-GDB-Security3 Background EDG WP6 CA managers group –DataGrid, CrossGrid, US (DOE), Canada –Growing to include new LCG-1 CA’s So now really a joint EDG/LCG group –Taiwan, Tokyo, Belgium, Israel, … CA’s must meet minimum requirements –Operational and Policy (CP/CPS) “Catch-all” CA operated by CNRS (France) –With appropriate registration procedures CA RPM’s distributed with EDG software Sites still free to decide their own trust list –Not generally used. Scaling problems – GGF looking into this area (PMA) –EDG Acceptance Matrix tools could help

2nd Annual EU Review – Feb – Software Integration, … – n° 4 Application Testbed Users VOUsers CMS106 WP687 ALICE63 ATLAS55 Earth Obs.29 BaBar29 LHCb28 ITeam22 Genomic22 TSTG16 Medical Img. 6 D03 CAUsers INFN (IT)113 CNRS (FR)71 UK58 CERN (CH)44 NIKHEF (NL)19 Russia15 US DOE10 Spain8 FZK (D)5 Czech Rep.3 Portugal3 NorduGrid2 Poland1 Canada0 Greece0 Slovakia0 TOTAL352 Certificate Authorities Group Evaluates & approves new CAs 16 currently approved. Collaborating w/ other grid proj. More on the way… Cyprus US FNAL (KCA) Belgium Taiwan Virtual Organizations Also for Storage Elements Guidelines (EDG rules) Course-grained Authorization.

7-May-03D.P.Kelsey, LCG-GDB-Security5 Issues FNAL propose Kerberos CA (KCA) (CERN also interested) –User authenticates via Kerberos mechanisms –KCA issues short-lived certificate for Grid Key Management Concerns –User-held private keys – security concerns MyProxy online Certificate repository –Concerns over key management VSC proposal from SLAC (holds user private keys) EDG CA min requirements say –CA must be offline or have a secure disk module (HSM) –Why should KCA follow this? short-lived certs only

7-May-03D.P.Kelsey, LCG-GDB-Security6 LCG Security Group Proposals Consider Long-lived (12 months) certificates and short-lived (12 hours or few days) certificates separately Long-lived certs (traditional CA’s) –More severe consequences of compromise –Continue with strong minimum requirements –Recommend the EDG/LCG group continues in its current form during 2003 (chaired by DPK) Appropriate membership of new LCG-1 CA’s LCG inputs its requirements –This process defines the list of trusted CA’s –Plan for 2004 – strong input from LCG Need to work with EGEE

7-May-03D.P.Kelsey, LCG-GDB-Security7 LCG Security Group Proposals (2) Short-Lived certificates (max life – few days, 2 weeks?) –User generated proxy certificates –KCA’s –MyProxy online credential repository –VSC? (will this be used in 2003?) –And indeed AuthZ services (VOMS) VO membership, Groups/roles in attribute cert Less severe implications on compromise Don’t require HSM during 2003 (at least) The certificate of the short-lived service should be signed by a trusted traditional CA (to ease revocation) Work with EDG, US projects to –Document and evaluate risk –Propose the way forward for 2004

7-May-03D.P.Kelsey, LCG-GDB-Security8 Recommendations to GDB GDB is asked to agree (at June meeting?) for LCG-1 operations during 2003 that… 1.The list of trusted traditional CA’s (long-lived certificates, i.e. more than 2 weeks) is defined by the joint EDG/LCG CA group 2.The list of trusted online (short-lived certificates, i.e. less than 2 weeks) authentication and authorization services and servers is defined by the LCG-1 Security Group 3.That all LCG-1 sites install and trust the 2 lists.