Sponsored by the National Science Foundation Campus Policies for the GENI Clearinghouse and Portal Sarah Edwards, GPO March 20, 2013.

Slides:



Advertisements
Similar presentations
MFA for Business Banking – Security Code Multifactor Authentication: Quick Tip Sheets Note to Financial Institutions: We are providing these QT sheets.
Advertisements

E-books and E-journals Off-campus This presentation will show you how to log in and access Oxford Brookes Library e-books and e-journals when youre off.
How-to Use iLab Solutions software within Auckland Science Analytical Services in the Faculty of Science, the University of Auckland Auckland Science Analytical.
Sponsored by the National Science Foundation 1 Activities this trimester 0.5 revision of Operational Security Plan Independently (from GPO) developing.
Sponsored by the National Science Foundation GENI Exploring Networks of the Future
Sponsored by the National Science Foundation GENI Clearinghouse Panel GEC 12 Nov. 2, 2011 INSERT PROJECT REVIEW DATE.
Dorian Grid Identity Management and Federation Dialogue Workshop II Edinburgh, Scotland February 9-10, 2006 Stephen Langella Department.
1 eAuthentication in Higher Education Tim Bornholtz Session #47.
Slides for Grid Computing: Techniques and Applications by Barry Wilkinson, Chapman & Hall/CRC press, © Chapter 1, pp For educational use only.
SOA Security Chapter 12 SOA for Dummies. Outline User Authentication/ authorization Authenticating Software and Data Auditing and the Enterprise Service.
Implementing Default-Deny while Enabling End-to-end Performance Damian Doyle Jack Suess.
Identity and Access Management IAM A Preview. 2 Goal To design and implement an identity and access management (IAM) middleware infrastructure that –
Identity Management What is it? Why? Responsibilities? Bill Weems Academic Computing University of Texas Health Science Center at Houston.
Sponsored by the National Science Foundation Omni: a command line GENI resource reservation tool Niky Riga, Sarah Edwards GENI Project Office 13 March,
School and LEA Users
Sponsored by the National Science Foundation GENI Stitching Services: Present and Future Marshall Brinn, GPO March 18, 2014.
National Science Foundation Arlington, Virginia January 7-8, 2013 Tom Lehman University of Maryland Mid-Atlantic Crossroads.
Sponsored by the National Science Foundation PlanetLab and PLFED Spiral 2 Year-end Project Review Princeton University PI: Larry Peterson Staff: Andy Bavier,
Single Sign-On Multiple Benefits via Alaska K20 Identity Federation 20 May 2011 BTOP Partner Meeting Anchorage, Alaska 20 May 2011 BTOP Partner Meeting.
Sponsored by the National Science Foundation GEC16 Service Developers Roundtable: Strawman Unified I&M Tools and Services Marshall Brinn, GPO March 19,
Exploring InCommon Getting Started with InCommon: Creating Your Roadmap.
Sponsored by the National Science Foundation Getting Started With Your Own Experiment Sarah Edwards, GENI Project Office.
Internet2 – InCommon and Box Marla Meehl Colorado CIO 11/1/11.
Integrating with UCSF’s Shibboleth system
This presentation is designed to help assist you in registering and creating an account to do online homework using the MyMathLab program via CourseCompass.
Sponsored by the National Science Foundation GENI Software Marshall Brinn, GPO Architect January 7, 2013.
Sponsored by the National Science Foundation GEC16 Plenary Session: GENI Solicitation 4 Tool Context Marshall Brinn, GPO March 20, 2013.
Sponsored by the National Science Foundation Enabling Trusted Federation Marshall Brinn, GENI Program Office October 1, 2014.
Evolution of the Open Science Grid Authentication Model Kevin Hill Fermilab OSG Security Team.
Sponsored by the National Science Foundation GENI Exploring Networks of the Future Sarah Edwards, GPO
Federated Environments and Incident Response: The Worst of Both Worlds? A TeraGrid Perspective Jim Basney Senior Research Scientist National Center for.
Sponsored by the National Science Foundation GENI Terminology.
Sponsored by the National Science Foundation GENI Terminology: How All the Pieces Fit Together Sarah Edwards GENI Project Office.
An Overview of Single Sign-On, Federation, Its Benefits, and Basic Procedures for Integrating Applications.
Sponsored by the National Science Foundation Towards Uniform Clearinghouse APIs GEC17 Developer Working Sessions July 23,
Sponsored by the National Science Foundation Monitoring Demonstration Kevin Bohan, GMOC
Sponsored by the National Science Foundation Lab Zero: A First Experiment using GENI Sarah Edwards, GENI Project Office.
Sponsored by the National Science Foundation GENI Security Architecture What’s Up Next? GENI Engineering Conference 7 Durham, NC Stephen Schwab SPARTA/Cobham.
Sponsored by the National Science Foundation 1 Last updated April 1, 2013 Are you ready for the tutorial? 1.Sign In 2.Grab a Worksheet 3.Did you do the.
Sponsored by the National Science Foundation Getting Started With Your Own Experiment Sarah Edwards, GENI Project Office.
Sponsored by the National Science Foundation GENI Experimenter Portal Service Developers Roundtable GENI Engineering Conference 16 Salt Lake City, Utah.
Sponsored by the National Science Foundation 1 ICDCS13: July 8, 2013 Are you ready for the tutorial? 1.Grab a Worksheet and instructions 2.Did you do the.
Sponsored by the National Science Foundation Lab Zero: A First Experiment using GENI.
Sponsored by the National Science Foundation GENI Campus Ops Workflow Chaos Golubitsky San Juan, Puerto Rico Mar
Sponsored by the National Science Foundation Introduction to GENI Architecture: Federated Trust Perspective Marshall Brinn, GPO GEC20: June 24, 2014.
Leveraging the InCommon Federation to access the NSF TeraGrid Jim Basney Senior Research Scientist National Center for Supercomputing Applications University.
Sponsored by the National Science Foundation 1 GREE SC: June 24, 2013 Are you ready for the tutorial? 1.Grab a Worksheet and instructions 2.Did you do.
Sponsored by the National Science Foundation GENI Aggregate Manager API Tom Mitchell March 16, 2010.
Sponsored by the National Science Foundation Establishing Policy-based Resource Quotas at Software-defined Exchanges Marshall Brinn, GPO June 16, 2015.
Sponsored by the National Science Foundation Measurement System Spiral 2 Year-end Project Review University of Wisconsin, Colgate University, Boston University.
Sponsored by the National Science Foundation Lab Zero: A First Experiment using GENI Sarah Edwards GENI Project Office.
Sponsored by the National Science Foundation Today’s Exercise.
MassHealth Medicaid Management Information System (MMIS) Provider Online Service Center (POSC) Technical Upgrade January 13, 2016.
Sponsored by the National Science Foundation 1 Lab Zero – October 20, 2014 Are you ready for the tutorial? 1.Grab a Worksheet and instructions 2.Did you.
2003 © SWITCH Authentication and Authorisation Infrastructure - AAI Christoph Graf Project Leader AAI SWITCH.
Sponsored by the National Science Foundation GENI Experimenter Portal Service Developers Roundtable GENI Engineering Conference 16 Salt Lake City, Utah.
Sponsored by the National Science Foundation 1 Lab Zero – March 14, 2014 Are you ready for the tutorial? 1.Grab a Worksheet and instructions 2.Did you.
Vodafone India Partner On-boarding Quick Start Guide.
Maryknoll Wireless Network Access Steps for Windows 7 As of Aug 20, 2012.
B2access.eudat.eu B2ACCESS User Training How to register with B2ACCESS Version 1 February 2016 This work is licensed under the Creative Commons.
Sponsored by the National Science Foundation ABAC and GPO Clearinghouse Authorization Marshall Brinn, GPO GEC20: June 22, 2014.
Gateways security Aashish Sharma Security Engineer National Center for Supercomputing Applications (NCSA) University of Illinois at Urbana-Champaign.
Sponsored by the National Science Foundation GENI Terminology Sarah Edwards, GENI Project Office Violet Syrotiuk, Arizona State University.
Sponsored by the National Science Foundation 1 GEC16: March 19, 2013 Are you ready for the tutorial? 1.Sign In 2.Grab a Worksheet 3.Did you do the pre-work?
Sponsored by the National Science Foundation GEC17 Plenary Session: Architecture Marshall Brinn, GPO July 22, 2013.
Faculty Access Class Rosters & Entering Grades.
GENI Terminology Sponsored by the National Science Foundation.
How To Add Non-DOD Staff to RMS 3.0 Government Mode
On the off chance that your business utilizes Roadrunner as your Internet specialist organization, you will have at least one accounts. While you.
Grid Computing Software Interface
Presentation transcript:

Sponsored by the National Science Foundation Campus Policies for the GENI Clearinghouse and Portal Sarah Edwards, GPO March 20, 2013

Sponsored by the National Science Foundation 2 GEC16: March 19, 2013 What is it? The clearinghouse is a set of services to track: –experimenters, –projects, –slices, and –authorization The portal is a web-based user interface for experimenters to access the clearinghouse services and GENI aggregates –Accounts used in three tutorials at this GEC: Getting Started with GENI, Advanced Networking, OpenFlow Who operates it? –Currently, the GPO

Sponsored by the National Science Foundation 3 GEC16: March 19, 2013 Risk: Policies The policies are the same between the portal/clearinghouse and the GPO run ProtoGENI (pgeni.gpolab.bbn.com): –Who can be approved to be a project lead –Project leads are trusted to make their own decisions about who gets added to their projects

Sponsored by the National Science Foundation 4 GEC16: March 19, 2013 Current GPO Project Lead Policies Projects organize research in GENI –Projects contain both people and their experiments –A project is led by a single responsible individual: the project lead –Who can be a project lead? Academic Faculty Senior technical staff in non- academic environments Project Lead Members Slice

Sponsored by the National Science Foundation 5 GEC16: March 19, 2013 Risk: Security The security risks are similar between the clearinghouse and pgeni.gpolab.bbn.com. In each case: the host could be compromised certificates and keys could be stolen and used to allocate resources using the GENI AM API upon detection, the root certificate can be removed from the trusted bundle so that the stolen certificates/keys are no longer useful

Sponsored by the National Science Foundation 6 GEC16: March 19, 2013 Risk: Bugs The portal/clearinghouse is new, and it is possible that there are bugs. We have a team actively working on the portal and we'll fix critical bugs as quickly as possible. While it is possible that the portal/ch could allow erroneous requests to be issued to rack aggregates, that's a path that has had significant testing thus far, and appears to work accurately.

Sponsored by the National Science Foundation 7 GEC16: March 19, 2013 Recommendations Trust the recommended GENI trust anchors: –Utah ProtoGENI –PlanetLab –GPO ProtoGENI aka pgeni.gpolab.bbn.com (legacy) –GENI Clearinghouse (NEW) Campus owner/operators have ultimate authority, and can modify the trust bundle if necessary If you agree, we would like to make this the standard recommendation for new GENI racks

Sponsored by the National Science Foundation 8 GEC16: March 19, 2013 The Portal Trusts InCommon For many experimenters: no new passwords familiar login screens Portal needs certain attributes (more in minute) The GENI Portal leverages InCommon for single sign-on authentication Experimenters from 288 educational and research institutions have InCommon accounts

Sponsored by the National Science Foundation 9 GEC16: March 19, 2013 How to access the portal? GENI Portal trusts both: –InCommon institutions –GPO Identity Provider (IdP) Anyone with an account at a supported identity provider can log in, but they will have no privileges If an experimenter does not have an account through an InCommon institution, the GPO will create an account on the GPO IdP –Once you have an account, you must be a member of a project to do anything interesting

Sponsored by the National Science Foundation 10 GEC16: March 19, 2013 What can you do? The GENI Portal gives access to real resources Therefore, we need to be able to contact experimenters if something goes wrong GENI Portal requires: –eppn (eduPersonPrincipalName) – address GENI Portal prefers to receive: –affiliation –given name –surname InCommon members can easily share these attributes by enabling the Research & Scholarship (R&S) category R&S:

Sponsored by the National Science Foundation 11 GEC16: March 19, 2013 Try logging in Want to know if your institution is an InCommon member which shares the needed attributes? The GENI Portal is at: Click “Use GENI” Pick your institution from the list Login using your usual username and password Does this work? You’re done If not, –We will contact the appropriate person at your institution

Sponsored by the National Science Foundation 12 GEC16: March 19, 2013 Looking forward: Policy Support Currently –policy is that racks should accept anyone with a valid GENI credential on a first come first serve basis –no mechanism to enforce other policies Two cases: 1.access to resources IN the rack 2.access to campus resources that connect through the rack (specifically the OpenFlow local campus resources port) What other campus policies are relevant to access the GENI racks in these two cases?

Sponsored by the National Science Foundation 13 GEC16: March 19, 2013 Looking forward: Operational portal/CH In the long run the operational GENI portal/CH won’t be operated by the GPO. That means two important things: 1)The policies have to be ok now and after the handoff 2)Are there requirements on who can implement these policies? The GPO portal/CH team is making sure we address this while we are implement. And we want your input.