OSG Area Coordinators Meeting Security Team Report Mine Altunay 04/02/2014.

Slides:



Advertisements
Similar presentations
OSG PKI RA Training Mine Altunay, Jim Basney OSG PKI Team October 1, 2012.
Advertisements

OSG Area Coordinators Meeting Security Team Report Mine Altunay 05/15/2013.
Jan 2010 Current OSG Efforts and Status, Grid Deployment Board, Jan 12 th 2010 OSG has weekly Operations and Production Meetings including US ATLAS and.
WebFTS as a first WLCG/HEP FIM pilot
WLCG Security TEG, risks and Identity Management David Kelsey GridPP28, Manchester 18 Apr 2012.
Key Accomplishments and Work Plans OSG Security Team July 11, 2012.
CA Stuff Jens Jensen Dave Meredith John Kewley GridPP31, Imperial, London Sept
F Run II Experiments and the Grid Amber Boehnlein Fermilab September 16, 2005.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 01/29/2014.
Key Project Drivers - FY11 Ruth Pordes, June 15th 2010.
OSG PKI Grid Admin (GA) Training Mine Altunay, Jim Basney OSG PKI Team October 8, 2012.
CILogon OSG CA Mine Altunay Jim Basney TAGPMA Meeting Pittsburgh May 27, 2015.
OSG Area Coordinators Meeting Operations Rob Quick 2/22/2012.
OSG Area Coordinators Meeting Security Team Report Kevin Hill 08/14/2013.
OSG Security Review Mine Altunay June 19, June 19, Security Overview Current Initiatives  Incident response procedure – top priority (WBS.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 12/21/2011.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 06/25/2014.
OSG Site Provide one or more of the following capabilities: – access to local computational resources using a batch queue – interactive access to local.
12-May-03D.P.Kelsey, SCG Online Authentication1 Online Authentication SCG Meeting EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
OSG Security Kevin Hill. Goals Operational Security – Identify software vulnerabilities – observing the practices of our VOs and sites, and sending alerts.
Blueprint Meeting Notes Feb 20, Feb 17, 2009 Authentication Infrastrusture Federation = {Institutes} U {CA} where both entities can be empty TODO1:
Use of Condor on the Open Science Grid Chris Green, OSG User Group / FNAL Condor Week, April
OSG Area Coordinators Meeting Security Team Report Mine Altunay 04/3/2013.
Discussion Topics DOE Program Managers and OSG Executive Team 2 nd June 2011 Associate Executive Director Currently planning for FY12 XD XSEDE Starting.
Evolution of the Open Science Grid Authentication Model Kevin Hill Fermilab OSG Security Team.
Updates from the EUGridPMA David Groep, July 16 st, 2007.
OSG Security Review Mine Altunay December 4, 2008.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay OSG Security Officer.
Rob Quick OSG Operations Area Coordinator Manager High Throughput Computing Indiana University Integrating OSG Operational Services Rob Quick OSG Operations.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 8/15/2012.
Maarten Litmaath (CERN), GDB meeting, CERN, 2006/02/08 VOMS deployment Extent of VOMS usage in LCG-2 –Node types gLite 3.0 Issues Conclusions.
OSG PKI Contingency and Recovery Plans Mine Altunay, Von Welch OSG Council August 23, 2012.
OSG PKI Contingency and Recovery Plans Mine Altunay, Von Welch October 16, 2012.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 11/02/2011.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 6/6/2012.
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
OSG Site Admin Workshop - Mar 2008Using gLExec to improve security1 OSG Site Administrators Workshop Using gLExec to improve security of Grid jobs by Alain.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
Grid Security and Identity Management Mine Altunay Security Officer, Open Science Grid, Fermilab.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 4/11/2012.
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 02/13/2012.
12-Jun-03D.P.Kelsey, CA meeting1 CA meeting Minimum Requirements CERN, 12 June 2003 David Kelsey CCLRC/RAL, UK
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay, James Basney,
Site Authorization Service Local Resource Authorization Service (VOX Project) Vijay Sekhri Tanya Levshina Fermilab.
7-May-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Issues and Planning or Report from the Security Group CERN, 8 May 2003 David Kelsey CCLRC/RAL, UK.
LCG Pilot Jobs + glexec John Gordon, STFC-RAL GDB 7 December 2007.
WLCG Operations Coordination report Maria Alandes, Andrea Sciabà IT-SDC On behalf of the WLCG Operations Coordination team GDB 9 th April 2014.
EGEE is a project funded by the European Union under contract IST New VO Integration Fabio Hernandez ROC Managers Workshop,
OSG PKI Transition Impact on CMS. Impact on End User After March , DOEGrids CA will stop issuing or renewing certificates. If a user is entitled.
OSG Security: Updates on OSG CA & Federated Identities Mine Altunay, PhD OSG Security Team OSG AHM March 24, 2015.
OSG PKI Transition Mine Altunay OSG Security Officer
Trusted Virtual Machine Images the HEPiX Point of View Tony Cass October 21 st 2011.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 8/15/2012.
CERN IT Department CH-1211 Geneva 23 Switzerland t OIS Operating Systems & Information Services CERN IT Department CH-1211 Geneva 23 Switzerland.
The Americas Grid Policy Management Authority TAGPMA Update Derek Simmel (delivered by David [Groep|Kelsey]) 31 th EUGridPMA Meeting Tartu, Estonia May.
Ruth Pordes, March 2010 OSG Update – GDB Mar 17 th 2010 Operations Services 1 Ramping up for resumption of data taking. Watching every ticket carefully.
The Americas Grid Policy Management Authority TAGPMA Update Derek Simmel 27 th EUGridPMA Meeting Rome, Italy January 14-16, 2013.
Running User Jobs In the Grid without End User Certificates - Assessing Traceability Anand Padmanabhan CyberGIS Center for Advanced Digital and Spatial.
Certificate Security For Users Obtaining and Using Your Personal Certificate using the OSG PKI Kyle Gross – OSG Operations Support Lead Elizabeth Prout.
Why you should care about glexec OSG Site Administrator’s Meeting Written by Igor Sfiligoi Presented by Alain Roy Hint: It’s about security.
New OSG Virtual Organization Security Training OSG Security Team.
OSG PKI Transition: Status and Next Steps (and Lessons Learned) Von Welch OSG PKI Transition Lead Indiana University Center for Applied Cybersecurity Research.
Bringing Federated Identity to Grid Computing Dave Dykstra CISRC16 April 6, 2016.
Ian Bird, CERN WLCG Project Leader Amsterdam, 24 th January 2012.
OSG Security Kevin Hill.
LCG Security Status and Issues
Update on SHA-2 and RFC proxy support
The Case for HLCA Revisited
Presentation transcript:

OSG Area Coordinators Meeting Security Team Report Mine Altunay 04/02/2014

Key Initiatives Glow VO submitting certificate-free jobs – Completed the review of Glow VO – Found some issues Two kinds of submit node: PI-Managed and CHTC-managed CHTC-managed nodes were straightforward. Single policy and user management process. PI-managed nodes are diverse, dependent on PI’s practices – Made some changes to GLOW submission mechanism. Created two separate job queues. Only CHTC_managed nodes can submit jobs to Fermilab without certificates. – Most users and PIs prefer to use CHTC-managed nodes, so this is not a huge drawback – Moved into production. – Expected to benefit 607 users in Glow. – Very positive feedback from GLOW admins so far.

Glow VO Job Stats Number of Glideins from Glow running on all OSG sites. The dark salmon color is FNAL, not SWT2. The number of jobs running on FNAL increasing

Glow Glideins at FNAL during the last month Disregard data before week11. We started on FNAL at week 11 FNAL providing a significant amount of Glideins for Glow Glow Glideins at all OSG sites during the last month

Key Initiatives News from CILogon Basic CA – The new IGTF profile IOTA had been approved and included in the new IGTF release. – CILogon Basic CA will complete its accreditation under this profile soon. – What this means is we will soon have CILogon Basic CA as part of our standard IGTF distribution as an accredited CA. – Once the accreditation is complete, we want to push even more users to utilize this CA

IDM Roadmap OSG IDM Roadmap revisited before DigiCert current contract expiry – First, we will renew our contract with DigiCert for a year or two. So, no worries about sudden changes – Two questions from Lothar triggered our work: What would happen to OSG stakeholders if we stop to provide certificates? Can we get certificates somewhere other than DigiCert? – We created a short-term roadmap, OSG-doc-1185, answering these questions in detail. Please read the document for details.

IDM Roadmap What would happen to OSG Stakeholders if OSG stops to provide certificates? VOImpact on User CertsImpact on Host Certs LHC (Atlas, CMS, Alice)NoneYes, need 3500 certs Fermilab VONoneYes, need host certs OSG VOSome –10, 15% of users will need certs, but can switch to CILogon CA Yes, needs 100 certs DOSARSome – only 20 users. Can switch to CILogon CA Yes, Needs a small amount GLOWSome, but can switch to CILogon CA Yes, needs 100 certs

IDM Roadmap What would happen to OSG Stakeholders if OSG stops to provide certificates? – User certs has no impact. Few VOs dependent on OSG CA and they do not have any accreditation requirements. So, they can switch to CILogon Basic CA if needed. All other VOs can already get certs form alternative resources, Fermi KCA, CERN CA, etc. – The real issue is the host certs. Everyone is dependent on OSG CA and no VO has an alternative to get certs from.

IDM Roadmap Can we get certificates somewhere else? Yes: – CILogon Net HSM service – Commercial Retail CAs – InCommon Certificate Service – Operating our own Backend CA – Operating our intermediate CA

SolutionProsCons CILogon Net HSMSame functionality as DigiCert. No changes to OIM. Free (for 1.5 years at least). Can start using in 2 months. No changes to OIM or command line clients Uncertain future funding Commercial Retail CAs Per cert cost $ automated process, issues certs in minutes. World-wide trusted CAs. Requires DNS domain ownership. Hard to prove for our site admins. Sites has to write new tools to manage hundreds of host certs InCommon Cert Service Unlimited certs for InCommon members. Getting IGTF accreditation. Not all OSG sites are members. For FNAL and BNL the membership fee would be 50K/year for 3 year subscription. Changes to command line tools Our Own BackEnd CA Same work as Digicert or CILogon NetHSM. No changes to OIM or command line clients Implementation and Maintenance costs Our Intermediate CASimilar to BackEnd CA. No changes to OIM or command line clients Implementation and Maintenance costs

IDM Roadmap CILogon Net HSM is the best option. We note the concern about future funding commitments. – Same set of services we get from DigiCert with minimal changes to Frontend – Started a prototype. Instantiating a new HSM service instance for OSG. Will use the same OIM invocation methods. No changes to the command line clients. If CILogon NET HSM option does not work, then we want to try to set up our own HSM service. If our own HSM does not work out, we should continue with DigiCert CA.

IDM Roadmap While completing the Net HSM experiment, our goal is still to eliminate user certs or make them completely hidden from users 1st step is to add an OSG Identity Provider hooked into the OIM. Soichi already had a prototype IdP working. This will be used for onboarding OSG users into OSGConnect. It will also be used for obtaining CILogon Basic certs when needed. 2 nd step is to add a username/passwd access to OIM. So anyone who just needs access to twiki, docdb, OIM, can do so without certs.

IDM Roadmap 3 rd step is to access storage elements without user certificates. – Similar to Traceability project, but only for storage elements We will continue to move VOs to certificate- free submission mode.

Operational Security Next IGTF release has lots of new things – DOEGrids CA is removed. – New DigiCert trust rots with SHA-2 certs are added – Dropping the old layout– incompatible with sha-2.