David Kelsey CCLRC/RAL, UK

Slides:



Advertisements
Similar presentations
Grid Security Policy GridPP18, Glasgow David Kelsey 21sr March 2007.
Advertisements

GGF16, Athens AuthZ Interoperability Here and Now Workshop, 16 Feb 2006.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
Denise Heagerty, CERN, HEPiX Meeting Oct HEPiX Security Workshop Overview of talks Some extracts of general interest LCG Security Group FNAL, KEK,
30-Jan-03D.P.Kelsey, GridPP Security1 Security GridPP6 30 Jan 2003 Coseners House David Kelsey CLRC/RAL, UK
Authentication Policy David Kelsey CCLRC/RAL 15 April 2004, Dublin
13-May-03D.P.Kelsey, WP8 CA and VO organistion1 CA’s and Experiment (VO) Organisation WP8 Meeting EDG Barcelona, 13 May 2003 David Kelsey CCLRC/RAL, UK.
12-May-03D.P.Kelsey, SCG Online Authentication1 Online Authentication SCG Meeting EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
EGEE ARM-2 – 5 Oct LCG Security Coordination Ian Neilson LCG Security Officer Grid Deployment Group CERN.
20-May-03D.P.Kelsey, LCG-1 Security, HEPiX1 Grid Security for LCG-1 HEPiX, NIKHEF, 20 May 2003 David Kelsey CCLRC/RAL, UK
GGF12 – 20 Sept LCG Incident Response Ian Neilson LCG Security Officer Grid Deployment Group CERN.
LCG/EGEE Security Update HEPiX, Fall 2004 BNL, 18 October 2004 David Kelsey CCLRC/RAL, UK
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
JSPG: User-level Accounting Data Policy David Kelsey, CCLRC/RAL, UK LCG GDB Meeting, Rome, 5 April 2006.
Security Area in GridPP2 4 Mar 2004 Security Area in GridPP2 “Proforma-2 posts” overview Deliverables – Local Access – Local Usage.
INFSO-RI Enabling Grids for E-sciencE EGEE/LCG Joint Security Policy Group David Kelsey, CCLRC/RAL, UK EGEE.
10-Jun-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 10 June 2003 David Kelsey CCLRC/RAL, UK
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Ake Edlund EGEE Sec Head 9th MWSG meeting, SLAC,
Security Policy Update LCG GDB Prague, 4 Apr 2007 David Kelsey CCLRC/RAL
13-Jul-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint LCG/EGEE Security Group) CERN 13 July 2004 David Kelsey CCLRC/RAL,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
9-Sep-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 9 September 2003 David Kelsey CCLRC/RAL, UK
23-Oct-03D.P.Kelsey, LCG Security Update, HEPiX1 LCG Security Update HEPiX-HEPNT, TRIUMF, 23 October 2003 David Kelsey CCLRC/RAL, UK
8-Jul-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) RAL, 8 July 2003 David Kelsey CCLRC/RAL, UK
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and OSG: Common Security Policies? OSG.
10-May-01D.P.Kelsey, Security Workshop Summary1 DataGrid Security Workshop 29/30 March 2001 SUMMARY David Kelsey CLRC/RAL, UK
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks JSPG Status and plans EGEE’06 Conference.
JRA Execution Plan 13 January JRA1 Execution Plan Frédéric Hemmer EGEE Middleware Manager EGEE is proposed as a project funded by the European.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Linda Cornwall CCLRC (RAL) FP6 Security workshop.
LCG/EGEE Security Operations HEPiX, Fall 2004 BNL, 22 October 2004 David Kelsey CCLRC/RAL, UK
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
Apr 26, 20071/3 OSG Executive Board Meeting Gabriele Garzoglio OSG Executive Board Meeting Gabriele Garzoglio VO Services, PL Computing Division, Fermilab.
9-Oct-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) FNAL 9 October 2003 David Kelsey CCLRC/RAL, UK
Grid Security Vulnerability Group Linda Cornwall, GDB, CERN 7 th September 2005
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Dr Linda Cornwall CCLRC (RAL) FP6 Security workshop.
Open Science Grid & its Security Technical Group ESCC22 Jul 2004 Bob Cowles
Security Operations David Kelsey GridPP Deployment Board 3 Mar 2005
Security Vulnerability Identification and Reduction Linda Cornwal, JRA1, Brno 20 th June 2005
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
Last update 22/02/ :54 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD VO Registration procedure Presented by.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and JSPG activities David Kelsey CCLRC/RAL.
Security EGEE/SA1 ROC Managers ARM-3 meeting Lyon, 17 March 2005 David Kelsey CCLRC/RAL, UK
EGEE ARM-2 – 5 Oct LCG/EGEE Security Coordination Ian Neilson Grid Deployment Group CERN.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
12-Jun-03D.P.Kelsey, CA meeting1 CA meeting Minimum Requirements CERN, 12 June 2003 David Kelsey CCLRC/RAL, UK
18-May-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) Barcelona 18 May 2004 David Kelsey CCLRC/RAL, UK
Security Policy Update WLCG GDB CERN, 8 Dec 2010 David Kelsey STFC/RAL david.kelsey AT stfc.ac.uk.
Planning for LCG Emergencies HEPiX, Fall 2005 SLAC, 13 October 2005 David Kelsey CCLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
7-May-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Issues and Planning or Report from the Security Group CERN, 8 May 2003 David Kelsey CCLRC/RAL, UK.
LCG User, Site & VO Registration in EGEE/LCG Bob Cowles OSG Technical Meeting Dec 15-17, 2004 UCSD.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
Grid Security Policy: EGEE to EGI David Kelsey (RAL) 16 Sep 2009 JSPG meeting, DFN Berlin david.kelsey at stfc.ac.uk.
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
Security Policy Update WLCG GDB CERN, 11 June 2008 David Kelsey STFC/RAL
Bob Jones EGEE Technical Director
Grid Operations Centre Progress to Aug 03
David Kelsey CCLRC/RAL, UK
LCG Security Status and Issues
David Kelsey CCLRC/RAL, UK
Ian Bird GDB Meeting CERN 9 September 2003
David Kelsey STFC-RAL 2nd WISE workshop, XSEDE16, Miami 18 July 2016
John Gordon, STFC-RAL GDB 10 October 2007
LCG/EGEE Incident Response Planning
Integrated Site Security for Grids
LCG Operations Centres
LCG Operations Workshop, e-IRG Workshop
Presentation transcript:

David Kelsey CCLRC/RAL, UK d.p.kelsey@rl.ac.uk EGEE/LCG Joint Security Group EGEE Middleware Security Group meeting CERN 17 June 2004 David Kelsey CCLRC/RAL, UK d.p.kelsey@rl.ac.uk 17-Jun-04 D.P.Kelsey, Joint Security Group

D.P.Kelsey, Joint Security Group Overview What is the Joint Security Group? Grid security warning (Draft) Guide to Application & Network Security EGEE Site Security requirements 17-Jun-04 D.P.Kelsey, Joint Security Group

The EGEE/LCG Joint Security Group Merger of old LCG Security Group (presented at MWSG1) and the new EGEE SA1 Site Security Group Agreed by EGEE SA1 leader and LCG GDB in May 2004 One group with two roles Advises the LCG GDB on security policy, operational and procedural issues. LCG GDB makes decisions for LCG Advises EGEE (SA1) on security policy etc for EGEE and input to EGEE MWSG No equivalent (yet?) of LCG GDB.. JSG is not responsible for security middleware and tools development, selection etc. (EGEE JRA3 and MWSG) EU pushing for common policy for the whole of EU eScience aim to make all of JSG policy documents “general” Establish strong links between JSG and OSG Security to encourage/facilitate global interoperability.  17-Jun-04 D.P.Kelsey, Joint Security Group

D.P.Kelsey, Joint Security Group Meetings, web etc. Recent Joint Security Group meetings 19 May & 4 June 2004 Next meeting: 1 July 2004 Agenda, presentations, minutes etc http://agenda.cern.ch/displayLevel.php?fid=68 Joint Security Group Web site http://proj-lcg-security.web.cern.ch 17-Jun-04 D.P.Kelsey, Joint Security Group

D.P.Kelsey, Joint Security Group LCG SEC Membership Experiment representatives/VO managers Alberto Masoni, ALICE Anders Waananen, ATLAS David Stickland, Greg Graham, CMS Joel Closier, LHCb Site Security Officers Denise Heagerty (CERN), Dane Skow (FNAL) Site/Resource Managers David Groep (NIKHEF) (&middleware expert) Dave Kelsey (RAL) - Chair Security middleware/tools experts Roberto Cecchini (INFN), Tanya Levshina (FNAL) CERN LCG team Ian Neilson (LCG Security Officer) Maria Dimou Non-LHC HEP experiments/Grids Bob Cowles (SLAC) 17-Jun-04 D.P.Kelsey, Joint Security Group

D.P.Kelsey, Joint Security Group JSG membership Need to expand to cover non-LCG sites and non-HEP applications E.g. Biomedical Volunteers? Suggestions? Mail list Change name? Open or closed? 17-Jun-04 D.P.Kelsey, Joint Security Group

D.P.Kelsey, Joint Security Group LCG Security warning Growing interest in Grid TeraGrid attack Article in New Scientist magazine (22 May) “Hacking the Grid” Talk at 2600 hacker conference (9-11 July) An attack is inevitable! All sites need to be aware Keep each other informed via the Security Contacts list Follow LCG Incident Response procedures Important role for GOC Warning sent to all security contacts on 10th June Planning to test security procedures (LCG service challenges) 17-Jun-04 D.P.Kelsey, Joint Security Group

Guide to LCG Application & Network Security The final document in the set of LCG policy and procedures V1.4 (7th June) now being discussed by LCG GDB Main author: Ian Neilson (LCG Security Officer) Aim It is a Guide and not Policy but GDB may insist that it is Policy Guide choices in design, planning and deployment of LCG Grid services Identify key areas of best practice BUT, it contains important recommendations for deploying a secure production Grid Important for GDB to approve the Guide 17-Jun-04 D.P.Kelsey, Joint Security Group

Guide: Application and Service Development LCG expects development processes that Support adequate and documented treatment of security E.g. Current misalignment IP connectivity from anywhere to anywhere Incoming: weakens site Outgoing: distributed DOS Current firewall requirements in Appendix B LCG Security Group considers these inappropriate for a production Grid Application developers MUST NOT rely on the current settings – not a minimal set 17-Jun-04 D.P.Kelsey, Joint Security Group

Some recommendations (development) Design and development process Coding practice Communications security Authentication Encryption Use existing protocols Functional security Authorization Degrade and fail gracefully Logging Avoid leakage of information 17-Jun-04 D.P.Kelsey, Joint Security Group

Application and Service Deployment LCG expects security instructions in documentation Evaluate risks Establish clear network access control policy Apply configuration management and automate Keep systems patched for security updates Configure and retain audit logs 17-Jun-04 D.P.Kelsey, Joint Security Group

EGEE Site Security Requirements Other important input (both on agenda page) Network & Applications Security Guide the GGF Site AAA requirements guide 17-Jun-04 D.P.Kelsey, Joint Security Group

“Top 10” security requirements (not in priority order) Sites in control of local security policy Audit/track at individual user level Sites control local AuthZ policy Authorize, limit or forbid IP connectivity Hooks/logging for intrusion detection Consistent and appropriate audit logs Development and deployment of secure middleware Able to cope with distributed AuthZ (user, VO, site) Shutdown and restart services gracefully Robust VO and user registration tools (procedures) See document on agenda page for more details 17-Jun-04 D.P.Kelsey, Joint Security Group

Some feedback from LCG sites Is there are plan to investigate/use SELinux? Or look at security features of Linux kernel 2.6? List of current LCG-2 security problems 17-Jun-04 D.P.Kelsey, Joint Security Group