Managing our Grid Node, Involvement under Trust Fabric, External Collaboration, & In-House Projects Adeel-ur-Rehman on behalf of Advanced Scientific Computing.

Slides:



Advertisements
Similar presentations
Introduction of Grid Security
Advertisements

EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks MyProxy and EGEE Ludek Matyska and Daniel.
The LHC experiments AuthZ Interoperation requirements GGF16, Athens 16 February 2006 David Kelsey CCLRC/RAL, UK
Forschungszentrum Karlsruhe in der Helmholtz-Gemeinschaft Torsten Antoni – LCG Operations Workshop, CERN 02-04/11/04 Global Grid User Support - GGUS -
Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
Grid Computing, B. Wilkinson, 20045a.1 Security Continued.
High Performance Computing Course Notes Grid Computing.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
1 Software & Grid Middleware for Tier 2 Centers Rob Gardner Indiana University DOE/NSF Review of U.S. ATLAS and CMS Computing Projects Brookhaven National.
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
Dorian Grid Identity Management and Federation Dialogue Workshop II Edinburgh, Scotland February 9-10, 2006 Stephen Langella Department.
1-2.1 Grid computing infrastructure software Brief introduction to Globus © 2010 B. Wilkinson/Clayton Ferner. Spring 2010 Grid computing course. Modification.
Joining the Grid Andrew McNab. 28 March 2006Andrew McNab – Joining the Grid Outline ● LCG – the grid you're joining ● Related projects ● Getting a certificate.
LCG Milestones for Deployment, Fabric, & Grid Technology Ian Bird LCG Deployment Area Manager PEB 3-Dec-2002.
FP6−2004−Infrastructures−6-SSA E-infrastructure shared between Europe and Latin America Pilot Test-bed Operations and Support Work.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
NECTEC-GOC CA APGrid PMA face-to-face meeting. October, Sornthep Vannarat National Electronics and Computer Technology Center, Thailand.
NENA Development Conference | October 2014 | Orlando, Florida Security Certificates Between i3 ESInet’s and FE’s Nate Wilcox Emergicom, LLC Brian Rosen.
GT Components. Globus Toolkit A “toolkit” of services and packages for creating the basic grid computing infrastructure Higher level tools added to this.
GGF12 – 20 Sept LCG Incident Response Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Grid Security Issues Shelestov Andrii Space Research Institute NASU-NSAU, Ukraine.
Grid Security 1. Grid security is a crucial component Need for secure communication between grid elements  Authenticated ( verify entities are who they.
DataGrid WP6 CA meeting, CERN, 12 December 2002 IISAS Certification Authority Jan Astalos Department of Parallel and Distributed Computing Institute of.
GILDA testbed GILDA Certification Authority GILDA Certification Authority User Support and Training Services in IGI IGI Site Administrators IGI Users IGI.
Module 9: Fundamentals of Securing Network Communication.
The huge amount of resources available in the Grids, and the necessity to have the most up-to-date experimental software deployed in all the sites within.
Evolution of the Open Science Grid Authentication Model Kevin Hill Fermilab OSG Security Team.
Building Security into Your System Bill Major Gregory Ponto.
Developing & Managing A Large Linux Farm – The Brookhaven Experience CHEP2004 – Interlaken September 27, 2004 Tomasz Wlodek - BNL.
Module 9: Designing Public Key Infrastructure in Windows Server 2008.
SouthGrid SouthGrid SouthGrid is a distributed Tier 2 centre, one of four setup in the UK as part of the GridPP project. SouthGrid.
Responsibilities of ROC and CIC in EGEE infrastructure A.Kryukov, SINP MSU, CIC Manager Yu.Lazin, IHEP, ROC Manager
IHEP Grid CA Status Report Gongxing Sun F2F Meeting 20 Apr Computing Centre, IHEP,CAS,China.
National Computational Science National Center for Supercomputing Applications National Computational Science Credential Management in the Grid Security.
NA-MIC National Alliance for Medical Image Computing UCSD: Engineering Core 2 Portal and Grid Infrastructure.
GRIDS Center Middleware Overview Sandra Redman Information Technology and Systems Center and Information Technology Research Center National Space Science.
Next Steps: becoming users of the NGS Mike Mineter
Grid User Interface for ATLAS & LHCb A more recent UK mini production used input data stored on RAL’s tape server, the requirements in JDL and the IC Resource.
Next Steps.
INFSO-RI Enabling Grids for E-sciencE EGEE SA1 in EGEE-II – Overview Ian Bird IT Department CERN, Switzerland EGEE.
Glite. Architecture Applications have access both to Higher-level Grid Services and to Foundation Grid Middleware Higher-Level Grid Services are supposed.
1 Grid Activity Summary » Grid Testbed » CFD Application » Virtualization » Information Grid » Grid CA.
Globus and PlanetLab Resource Management Solutions Compared M. Ripeanu, M. Bowman, J. Chase, I. Foster, M. Milenkovic Presented by Dionysis Logothetis.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
INFSO-RI Enabling Grids for E-sciencE An overview of EGEE operations & support procedures Jules Wolfrat SARA.
Testing and integrating the WLCG/EGEE middleware in the LHC computing Simone Campana, Alessandro Di Girolamo, Elisa Lanciotti, Nicolò Magini, Patricia.
Securing the Grid & other Middleware Challenges Ian Foster Mathematics and Computer Science Division Argonne National Laboratory and Department of Computer.
LHC Computing, CERN, & Federated Identities
Università di Perugia Enabling Grids for E-sciencE Status of and requirements for Computational Chemistry NA4 – SA1 Meeting – 6 th April.
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
Rob Allan Daresbury Laboratory NW-GRID Training Event 26 th January 2007 Next Steps R.J. Allan CCLRC Daresbury Laboratory.
Site Authorization Service Local Resource Authorization Service (VOX Project) Vijay Sekhri Tanya Levshina Fermilab.
The Globus Toolkit The Globus project was started by Ian Foster and Carl Kesselman from Argonne National Labs and USC respectively. The Globus toolkit.
PARALLEL AND DISTRIBUTED PROGRAMMING MODELS U. Jhashuva 1 Asst. Prof Dept. of CSE om.
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
Grid Deployment Technical Working Groups: Middleware selection AAA,security Resource scheduling Operations User Support GDB Grid Deployment Resource planning,
Activities and Perspectives at Armenian Grid site The 6th International Conference "Distributed Computing and Grid- technologies in Science and Education"
The status of IHEP Beijing Site WLCG Asia-Pacific Workshop Yaodong CHENG IHEP, China 01 December 2006.
1 Tutorial Outline 30’ From Content Management Systems to VREs 50’ Creating a VRE 80 Using a VRE 20’ Conclusions.
GRID & Parallel Processing Koichi Murakami11 th Geant4 Collaboration Workshop / LIP - Lisboa (10-14/Oct./2006) 1 GRID-related activity in Japan Go Iwai,
Grid Colombia Workshop with OSG Week 2 Startup Rob Gardner University of Chicago October 26, 2009.
29 th EUGridPMA meeting, September 2013, Bucharest AEGIS Certification Authority Dušan Radovanović University of Belgrade Computer Centre.
LHC collisions rate: Hz New PHYSICS rate: Hz Event selection: 1 in 10,000,000,000,000 Signal/Noise: Raw Data volumes produced.
Accessing the VI-SEEM infrastructure
Grid site as a tool for data processing and data analysis
JRA3 Introduction Åke Edlund EGEE Security Head
Ian Bird GDB Meeting CERN 9 September 2003
High Energy Physics Computing Coordination in Pakistan
NATIONAL CENTRE FOR PHYSICS PK-Grid-CA
Presentation transcript:

Managing our Grid Node, Involvement under Trust Fabric, External Collaboration, & In-House Projects Adeel-ur-Rehman on behalf of Advanced Scientific Computing Group (ASC)

Scheme of Talk  Grid Computing NCP-LCG2 (T2_PK_NCP)  Certification Authority PK-GRID-CA  In-House HPC Framework NCP Cluster  Projects with CERN CMS Collaboration  Software Development & Support  Assistance for EHEP fellows 6/10/2016 ASM

Grid Computing 6/10/2016 ASM

What are Grids?  A Grid is: Special form of distributed computing o Computing and storage resources are distributed over several locations called sites o Sites are typically connected via WAN links o Site normally has a local-area network which itself has distributed computing and data storage resources Coordinated resource sharing and problem solving in dynamic, multi-institutional Virtual Organizations (VO) o A VO is a collection of users sharing similar needs and requirements in their access to processing, data and distributed resources and pursuing similar goals. 6/10/2016 ASM

Grid in terms of VOs 6/10/2016 ASM

LHC & WLCG  The Large Hadron Collider (LHC) – the huge particle accelerator: is constructed at the European Laboratory for Particle Physics (CERN), at Franco-Swiss border near Geneva, Switzerland. is the world’s largest and most powerful particle accelerator.  the experiments using it are generating very large amounts of data (in Peta-Bytes / year). 6/10/2016 ASM

LHC & WLCG  The job of the Worldwide LHC Computing Grid Project (WCLG) is to prepare the computing infrastructure for the: Simulation processing and analysis of LHC data for all initial four of the LHC collaborations: o ALICE, ATLAS, CMS, and LHCB  The processing of this data requires enormous computational and storage resources. 6/10/2016 ASM

WLCG at NCP  Pakistan initiated collaboration with CERN for CMS experiment in 1990s.  Consequently, the effort to bring Pakistan on the WLCG map as a Grid Node also started.  A Grid Technology Workshop was organized by NCP from October 20-22,  The first ever testbed was deployed during the workshop for tutorial. 6/10/2016 ASM

WLCG at NCP  Now NCP is an official Grid Node in Pakistan. Tested & Certified by the Grid Deployment Team (dteam) at CERN first in South Asia and fifth in Asia  Since then, we have been appearing on the Grid Operations Centre (GOC), as well as GStat websites: &object_id=101&grid_id=0 &object_id=101&grid_id=0 LCG2/#fragment-1 LCG2/#fragment-1  The node has been constantly upgraded w.r.t. WLCG middleware and versions switching b/w: Globus gLite EMI 1, 2 (now heading towards EMI3) 6/10/2016 ASM

NCP on WLCG Globe 6/10/2016 ASM T2_PK_NCP

6/10/2016 ASM Installed Resources Physical CPU106 Logical CPU /Cores524 KSI2K1591 Disk (TB)260 Network (Mbps)155 T2_PK_NCP Site

Trust Fabric Involvement 6/10/2016 ASM

Grid Security Infrastructure (GSI)  The GSI in WLCG enables secure authentication and communication over an open network.  GSI is based on public key encryption, X.509 certificates, and the Secure Sockets Layer (SSL) communication protocol.  Extensions to these standards have been added for single sign-on and delegation.  So, in order to access the WLCG framework, one must have a digital certificate signed by a trusted Certification Authority (CA). 6/10/2016 ASM

Certification Authority (CA)  A CA is an executive body which issues certificates for users, programs, and machines.  A digital certificate is an electronic "credit card" that establishes our credentials when doing business or other transactions on the Web.  It uses Public Key Infrastructure (PKI) Enables users of a public network to exchange data securely using a public/private cryptographic key pair obtained and shared through a trusted authority (CA). 6/10/2016 ASM

PK-GRID-CA  NCP is itself a CA (non-commercial) which provides X.509 certificate (user/host) to support the secure environment in grid related projects  NCP produced the first Certificate Policy and Certification Practice Statement (CP-CPS) document in December  Reviewed by several members of European Grid Policy Management Authority (EU-Grid-PMA) that works under the umbrella of International Grid Trust Federation (IGTF).  IGTF also takes care of APGridPMA (for Asia Pacific), and TAGPMA (for the whole America) 6/10/2016 ASM

PK-GRID-CA  Three revisions were made which resulted from comments and suggestions by PMA members.  The CA was presented in September 2004 in the 2 nd meeting of the EU-Grid-PMA held in Brussels.  NCP was formally approved by the EU-Grid-PMA as a Certification Authority.  PK-Grid-CA had started operations since then.  First Certification Authority in Pakistan.  For more information: 6/10/2016 ASM

6/10/2016 ASM PK-GRID-CA  The routine task comprises of (but not limited to): issuing user/host certificates for our subscribers generating Certificate Revocation Lists (CRLs) revoking certificates when needed signing root key for our CA when due managing CA web portal for handling user requests maintaining users’ records, necessary correspondence and required cryptographic data pertaining to our root certificate recording each and every interaction of the CA offline server monitoring CA premises maintaining and updating our Certificate Policy/Certification Practice Statement (CP/CPS) document as required etc.

6/10/2016 ASM PK-GRID-CA Statistics  Current PK-Grid-CA stats: Total Certs Issued : 345 o User Certs : 204 o Host Certs : 141 o Certificates Expired : 206 o Certificates Revoked : 54 o Active Certificates : 85  For more info;

6/10/2016 ASM High Performance Computing Cluster

NCP Cluster  To provide our scientists the access to High Performance Computing resources for running simulation codes to model their research problems.  Over 30 researchers from all over the country have been facilitated with our cluster resources. 6/10/2016 ASM

NCP Cluster 6/10/2016 ASM

NCP Cluster  This cluster has been involved to conduct research and development under diversified areas of study like Ion Channeling, Multi-Particle Interaction, Space Physics, Weather Forecasting, Density Functional Theory (DFT) etc. 6/10/2016 ASM

NCP Cluster  Hardware Resources and Environment: SunFire Intel Xeon Machine 16 GB RAM 8 cores/node with 4 computational nodes Scientific Linux CERN 5.3 OS f77, g77 (gfortran), gcc openPBS (for batch processing) mpich p1 (for parallel processing) 6/10/2016 ASM

Software Development/Testing with CMS (CERN) Collaboration 6/10/2016 ASM

RPC Construction DB  Designing, development and testing of ConstructionDB wih Resistive Plate Chambers (RPC) group under CMS. 6/10/2016 ASM RPC Construction DB Barrel DB Endcap New Upgrade

RPC Construction DB  The software is being built in terms of various levels of Quality Controls (QCs) leading to different development phases.  QC1 (Chamber components validation)  QC2 (GAPS certification)  QC3 (Chambers test) QC3_A Chambers assembly validation (Implemented on production server) QC3_B Tests on Cosmic stand (Implemented on production server)  QC4 Chamber reception & acceptance from sites (Implemented on production server) Super-module assembly and final test before shipment to P5 (Testing Phase)  QC5 Installation and commissioning a P5 (Still to be done) 6/10/2016 ASM

Testing of DQM Sequences  Testing performance & goodness of offline Data Quality & Monitoring (DQM) modules within CMSSW project. Looking for compile-time and run-time failures Observing memory consumption fluctuation Notifying the corresponding persons at CERN about our findings in order to decide for the integration of a particular piece of DQM code within CMSSW 6/10/2016 ASM

Testing of DQM Sequences  The exercise has been carried out over various release cycles of CMSSW like 5_2_X, 5_3_X, 6_0_X, 6_1_X, 6_2_X and currently 7_0_X.  Other than that, we are also involved in adopting this workflow as per need of the outer environment such as: Integration of the test suite within CMSSW CVS -> Git (Revision Control Systems) Integration with automated build systems (Jenkins) 6/10/2016 ASM

Miscellaneous 6/10/2016 ASM

In-House Development and Support  Employee Salary System  Finance Ledger System (FLS)  Online Leave Application System (OLAS)  Library Information Management System (LIMS)  Hardware Inventory Management System (HIMS) or Network Resource Management System (NRMS)  Store Management System  Transport Requisition System  Redmine Ticketing System  ISS Conference Registration System 6/10/2016 ASM

Training & Assistance  Following types of facilities are offered to our EHEP students for their research work: Periodic conduction of courses/tutorials: o C++ Programming  Basic  Advanced o Python Programming Providing help in describing the source code of analysis software such as CMSSW, ROOT etc. Involvement in troubleshooting the grid site operations on demand. 6/10/2016 ASM

References  “WLCG Node in Pakistan – Challenges & Experiences”, by Sajjad Asghar, Usman Ahmad Malik & Adeel-ur-Rehman, Managed Grids and Cloud Systems in the Asia-Pacific Research Community 2010, pp , Springer.Managed Grids and Cloud Systems in the Asia-Pacific Research Community  “Establishment of Public Key Infrastructure in Pakistan”, by Sajjad Asghar, Usman Ahmad Malik & Adeel-ur-Rehman 8th National Research Conference, SZABIST, Islamabad    6/10/2016 ASM

6/10/2016 ASM