Updated (VO) Community Security Policies

Slides:



Advertisements
Similar presentations
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Advertisements

Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014 and now abbreviated.
Trust and Security for FIM (Sirtfi/SCI) David Kelsey (STFC-RAL) FIM4R at CERN 4 Feb 2015.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Sirtfi David Kelsey (STFC-RAL) REFEDS at TNC15 14 June 2015.
David Groep Nikhef Amsterdam PDP & Grid Evolving Assurance – going where? Collaborative, distributed, and generalized assurance beyond just identity authentication.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Service Operations Security Policy the new generalised site operations security policy.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI SPG future work EGI Technical Forum Lyon, 21 Sep 2011 David Kelsey, STFC/RAL.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
Networks ∙ Services ∙ People Thomas Bärecke Journée Fédération, Paris Collaboration européenne GÉANT SA5 03/07/2015 SA5 T5 team
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
EGI-InSPIRE RI SPG Tasks for Year 2011 Jan 2011 Kelsey/Security Policy Group1.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
Security Policy Update WLCG GDB CERN, 11 June 2008 David Kelsey STFC/RAL
IGTF in 10 years enabling the interoperable global trust federation Nikhef, Amsterdam supported the Dutch national e-Infrastructure funded and coordinated.
Security in the wider world David Kelsey (STFC-RAL) GridPP37 – Ambleside 2 Sep 2016.
SCI & Sirtfi David Kelsey (STFC-RAL) EGI Conference, Lisbon 19 May 2015.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014.
Building Trust for Research and Collaboration
WLCG Update Hannah Short, CERN Computer Security.
David Kelsey STFC-RAL 4th WISE workshop, Nikhef 27 March 2017
Boosting AAI for research and collaboration
RCauth.eu CILogon-like service in EGI and the EOSC
The Policy Puzzle Many groups and (proposed) policies, but leaving many open issues AARC “NA3” is tackling a sub-set of these “Levels of Assurance” –
EGI Updates Check-in Matthew Viljoen – EGI Foundation
AARC Update What’s been happening in AARC which matters for GÉANT
eduTEAMS – Current status & Future Plans
Christos Kanellopoulos
David Kelsey STFC-RAL 2nd WISE workshop, XSEDE16, Miami 18 July 2016
CheckIn: the AAI platform for EGI
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
Federated Identity Management for Researchers (FIM4R)
EGI Security Policy Update
Update on FIM4R David Kelsey
Boosting AAI for research and collaboration
Federated Identity Management for Scientific Collaborations
Towards hamonized policies and best practices
Sustainability for the AARC CILogin-like TTS Pilot
Frameworks for harmonized policies and practices
Policy in harmony: our best practice
Thursday pilot session: 7-minutes
Towards hamonized policies and best practices
Policy and Best Practice … in practice
OIDC Federation for Infrastructures
Update - Security Policies
AARC Blueprint Architecture and Pilots
Supporting communities with harmonized policy
EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.
OIDC Federation for Infrastructures
AARC2 JRA1 Update Nicolas Liampotis
RCauth.eu CILogon-like service in EGI and the EOSC
David Kelsey (STFC-RAL)
David Groep for the entire AARC Policy Team I2TechEX18 meeting
Community AAI with Check-In
AAI in EGI Status and Evolution
WISE Information Security for collaborating e-Infrastructures David Kelsey (STFC-RAL, UK Research and Innovation) ISGC2019, Taipei, 2 April 2019 In collaboration.
Combined Assurance Model
Federated Incident Response
WISE, SCI & policy templates David Kelsey (STFC-RAL, UK Research and Innovation) FIM4R & TIIME, Vienna, 11 February 2019.
Check-in Identity and Access Management solution that makes it easy to secure access to services and resources.
Presentation transcript:

Updated (VO) Community Security Policies EGI OMB meeting 27 July 2017 David Kelsey (STFC/RAL)

EGI security policies Still to be revised

Shown in Catania (May 2017) Future revision of policies Before end of EGI-Engage (31 Aug 2017) Revise old VO security policies VO Registration policy VO Membership management VO Operations Will aim for 2 policies One to control interface between Infrastructures and Communities One to control interface between Communities and Users SPG role in assessment of VO identity proofing For IGTF DOGWOOD assurance (IOTA CA)

Joint Activity EGI Security Policy Group – EGI-Engage And EU H2020 AARC2 project – NA3 - Policy and Best Practice Harmonisation Community Engagement (task 3.4) F2F meetings 8/9 June 2017 – Karlsruhe 5-7 July 2017 - Nikhef

Old policy VO Registration: https://documents.egi.eu/public/ShowDocument?docid=78 VO Operations: https://documents.egi.eu/public/ShowDocument?docid=77 VO Membership Management: https://documents.egi.eu/public/ShowDocument?docid=79

Definition of “Community” A Community is a group of individuals (Users) organised with a common purpose jointly granted access to one or more Infrastructures It may serve as an entity which acts as the interface between the individual Users and an Infrastructure In general, the Users of the Community will not need to separately negotiate access with Service Providers or Infrastructures

Community? Examples of Communities include User groups Virtual Organisations Research Communities Research Infrastructures Virtual Research Communities Projects Communities authorised to use particular portals or gateways geographically organised communities

New Policy EGI SPG Phase 2 – External Drafts There are TWO new policy documents: The Community Operations Security Policy - aimed at governing the relationship between Community and Infrastructure(s). The Community Membership Management Policy is all about the Community managing itself and its Users.   EGI has already expressed the desire to see both documents being separate sections of one EGI policy document But for now we will keep them separate.

“Snctfi” requirements Scalable Negotiator for a Community Trust Framework in Federated Infrastructures https://www.igtf.net/snctfi/ Developed under aegis of EU H2020 AARC Inspiration from SCI and Sirtfi Now managed by IGTF Sirtfi is managed by REFEDS and SCI by WISE 'interoperable trust' of SP-IdP proxies and the community of services behind the proxy The new Community Policies – aimed to address Snctfi requirements

Community Operations Security Policy https://docs.google.com/document/d/1TFE4T4hyFFrVKHyTjh4K8cJlrrvJGfpVvIvL4GCzYFM/edit# This policy applies to the Community Manager and other designated Community management personnel. It places requirements on Communities and it governs their relationships with all Infrastructures with which they have a usage agreement. Phase 2 – External draft Invitations to comment went out (to a wide audience!) 26th July Deadline for comment – 30th August 2017

Community Membership Management Policy https://docs.google.com/document/d/1vPcAja1EyTp-kJPvJpwu3NSd8e1aVcytY3nSGthWNLU/edit#heading=h.4ww9eqfyuow1 This Policy applies to the Community Manager and other designated Community management personnel. It places requirements on Communities regarding eligibility, obligations and rights of their Users, and it governs their relationships with all Infrastructures with which they have a usage agreement. Phase 2 – External draft Invitations to comment went out (to a wide audience!) 26th July Deadline for comment – 30th August 2017