OSG Area Coordinators Meeting Security Team Report Mine Altunay 12/21/2011.

Slides:



Advertisements
Similar presentations
OSG PKI RA Training Mine Altunay, Jim Basney OSG PKI Team October 1, 2012.
Advertisements

OSG Area Coordinators Meeting Security Team Report Mine Altunay 04/02/2014.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 05/15/2013.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
May 9, 2008 Reorganization of the OSG Project The existing project organization chart was put in place at the beginning of It has worked very well.
Jan 2010 Current OSG Efforts and Status, Grid Deployment Board, Jan 12 th 2010 OSG has weekly Operations and Production Meetings including US ATLAS and.
Release & Deployment ITIL Version 3
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
3 Dec 2003Market Operations Standing Committee1 Market Rule and Change Management Consultation Process John MacKenzie / Darren Finkbeiner / Ella Kokotsis,
Key Accomplishments and Work Plans OSG Security Team July 11, 2012.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 01/29/2014.
OSG Area Coordinators Meeting Operations Rob Quick 2/22/2012.
OSG Area Coordinators Meeting Cross-ProjectArea Report Ruth Pordes 2/8/2011.
Key Project Drivers - FY11 Ruth Pordes, June 15th 2010.
What if you suspect a security incident or software vulnerability? What if you suspect a security incident at your site? DON’T PANIC Immediately inform:
OSG PKI Grid Admin (GA) Training Mine Altunay, Jim Basney OSG PKI Team October 8, 2012.
CILogon OSG CA Mine Altunay Jim Basney TAGPMA Meeting Pittsburgh May 27, 2015.
OSG Area Coordinators Meeting Operations Rob Quick 2/22/2012.
OSG Area Coordinators Meeting Security Team Report Kevin Hill 08/14/2013.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Future support of EGI services Tiziana Ferrari/EGI.eu Future support of EGI.
OSG Security Review Mine Altunay June 19, June 19, Security Overview Current Initiatives  Incident response procedure – top priority (WBS.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 06/25/2014.
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
What if you suspect a security incident or software vulnerability? What if you suspect a security incident at your site? DON’T PANIC Immediately inform:
May 8, 20071/15 VO Services Project – Status Report Gabriele Garzoglio VO Services Project – Status Report Overview and Plans May 8, 2007 Computing Division,
OSG Security Kevin Hill. Goals Operational Security – Identify software vulnerabilities – observing the practices of our VOs and sites, and sending alerts.
Blueprint Meeting Notes Feb 20, Feb 17, 2009 Authentication Infrastrusture Federation = {Institutes} U {CA} where both entities can be empty TODO1:
OSG Area Coordinators Meeting Security Team Report Mine Altunay 04/3/2013.
Evolution of the Open Science Grid Authentication Model Kevin Hill Fermilab OSG Security Team.
OSG Security Review Mine Altunay December 4, 2008.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay OSG Security Officer.
Rob Quick OSG Operations Area Coordinator Manager High Throughput Computing Indiana University Integrating OSG Operational Services Rob Quick OSG Operations.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 8/15/2012.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
OSG PKI Contingency and Recovery Plans Mine Altunay, Von Welch OSG Council August 23, 2012.
OSG PKI Contingency and Recovery Plans Mine Altunay, Von Welch October 16, 2012.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 11/02/2011.
Mine Altunay July 30, 2007 Security and Privacy in OSG.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 6/6/2012.
OSG PKI Transition: Transition Phase Report Von Welch OSG PKI Transition Lead Indiana University Center for Applied Cybersecurity Research.
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
Meeting Minutes and TODOs TG has no distributed monitoring. During incident response, use a manual twiki page to distribute information TG monitors the.
US LHC OSG Technology Roadmap May 4-5th, 2005 Welcome. Thank you to Deirdre for the arrangements.
Grid Security Vulnerability Group Linda Cornwall, GDB, CERN 7 th September 2005
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
INFSO-RI Enabling Grids for E-sciencE EGEE SA1 in EGEE-II – Overview Ian Bird IT Department CERN, Switzerland EGEE.
G Z LIGO's Physics at the Information Frontier Grant and OSG: Update Warren Anderson for Patrick Brady (PIF PI) OSG Executive Board Meeting Caltech.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 4/11/2012.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 02/13/2012.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay, James Basney,
OSG Security: Updates on OSG CA & Federated Identities Mine Altunay, PhD OSG Security Team OSG AHM March 24, 2015.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Federated Cloud and Software Vulnerabilities Linda Cornwall, STFC 20.
Open Science Grid Security Activities D. Olson, LBNL OSG Deputy Security Officer For the OSG Security Team: M. Altunay, FNAL, OSG Security Officer, D.O.,
OSG PKI Transition Mine Altunay OSG Security Officer
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Questionnaires to Cloud technology providers and sites Linda Cornwall, STFC,
Grid Deployment Technical Working Groups: Middleware selection AAA,security Resource scheduling Operations User Support GDB Grid Deployment Resource planning,
OSG Area Coordinators Meeting Security Team Report Mine Altunay 8/15/2012.
OSG VO Security Policies and Requirements Mine Altunay OSG Security Team July 2007.
Certificate Security For Users Obtaining and Using Your Personal Certificate using the OSG PKI Kyle Gross – OSG Operations Support Lead Elizabeth Prout.
New OSG Virtual Organization Security Training OSG Security Team.
Software Tools Group & Release Process Alain Roy Mine Altunay.
OSG Security Review Mine Altunay March 12, Jan Security Overview Current Initiatives  OSG Security roadmap  Technical and operational.
OSG Security Kevin Hill.
Open Science Grid Consortium Meeting
Ian Bird GDB Meeting CERN 9 September 2003
Leigh Grundhoefer Indiana University
Prevention is better than Cure
Presentation transcript:

OSG Area Coordinators Meeting Security Team Report Mine Altunay 12/21/2011

WBS Ongoing Activities 1Incident response and vulnerability assessment Minimizing the end-end response time to an incident, 1 day for a severe incident, 1 week for a moderate incident, and 1 month for a low-risk incient. 2Troubleshooting; processing security tickets including user requests, change requests from stakeholders, technical problems Goal is to acknowledge tickets within one day of receipt. 3Maintaining security scripts (vdt-update-certs, vdt-ca-manage, cert-scripts, etc) Maintain and provide bug fixes according to the severity of bugs. For urgent problems, provide an update in one week; For moderate severity, provide an update in a month; For low risk problems, provide an update in 6 months. 4Supporting OSG RA in processing certificate requests Each certificate request is resolved within one week; requests for GridAdmin and RA Agents are served within 3 days. 5Preparing CA releases (IGTF), modifying OSG software as the changes in releases require CA release for every two months 6Security Policy work with IGTF, TAGPMA, JSPG and EGI Meet with IGTF and TAGPMA twice a year. Attend JSPG and EGI meteings remotely and face-face once a year. Track security policy changes and report to OSG management. 7Security Test and Controls Execute all the controls included in the Security Plan and prepare a summary analysis. 8Weekly Security Team Meeting to review work items Coordinate weekly work items. 9Weekly reporting to OSG-Production Report important items that will affect production; incidents, vulnerabilities, changes to PKI infrastructure 10Monthly reporting to OSG-ET Meet with ET once a month to discuss work items 11Quarterly reporting to Area Coordinator meeting Meet with area coordinators to discuss work items.

Ongoing Work: Operational Security 1. Software Vulnerabilities/Incidents – No major incidents. – Gratia security updates, – Supposed DOS attack at Fermilab – turned out to be non-security issue – Ongoing attention still taking a lot of effort. 10. replaced by area coordinators reports. Will be dropped. 5. DOEGrids CA certificate change. The older CA cert will have lifetime issues after January 23, – – Quick turn around from ITB folks -- Many thanks. – Tested and released into production by Dec Jim attended Federated ID management workshop in UK and TAGPMA

4.1Identity ManagementBasney, Altunay Work Plan agreed by OSG Management and Security teamBasney, Altunay8/1/119/15/ Integrate a UCSD VO with CILogon CA to utilize local resourcesBasney, Altunay8/15/119/30/ Integrate a VO with Cilogon CA which can submit jobs to OSG resourcesBasney, Altunay9/16/1112/30/ Provide documented and supported alternatives to the DOEGrids CA for OSG host certificatesBasney, Altunay Set up a implementation testbedBasney, Altunay9/30/1110/30/ Integrate OSG host cert system with XSEDE CAsBasney, Altunay10/30/117/15/ Enable user access without certificatesBasney, Altunay5/15/129/30/12 4.2Conduct Security Controls and TestsAltunay, Slagell Execute the security controls in OSG Security PlanAltunay, Slagell3/1/127/1/ Prepare a report on findings from the Security ControlsAltunay, Slagell7/1/127/22/12 Will not report on items that start after 1/1/12

ID Management Will update WBS to reflect DOE Grids CA transition – 4.1.1, 4.1.2, and are complete – replaced by Digicert Pilot. Integration with XSEDE to date does not need any work from Security on Cas. DigiCert pilot – Started on 10/25/2011. Goal to complete on 2/9/2012. – Tested the new certificates on ITB. Completed on 12/14. Our original target date was 12/5. – 10-day delay was due to Digicert’s latency in giving us access to their portals and certificates – ITB testing was difficult and time-consuming due to the number of components and ITB sites involved. The remaining items will not require help from outside of the pilot project members. Many thanks to ITB staff! – Detailed WBS update is periodically sent to Proj Manager (Chander)

SHA-2 Confusion here and in Europe on when SHA-2 certificates must be supported. Clear that OSG cannot support Sha-2 certificates for many months given the amount of s/w that must be converted. Must also support sha-1 and md5 simultaneously Project currently being planned at Actvity moved to Software with Alain as the lead. Security will help. Will not be in the security WBS. – IGTF decided not to enforce or encourage any CAs to switch to SHA-2 immediately. – EGI/WLCG struggles with complying with SHA-2 requirement. – Project goal is to ensure OSG software stack that is compatible with SHA-2 end user certificates and proxies (without dropping support for MD5 and SHA-1). – Contacted software providers and collecting their plans for sha- 2 support. – Tentative date so far is April. – is this realistic? Over to Alain to say.

Action Items from Last report to Area Coordinators – will add to WBS Switch to new layout CA bundles. – Has been tested and released as default to production. We have two separate processes for releasing CA bundles : – one for releasing to Koji/VDT – Other for releasing pacman packages via GOC. – Review and reconciliation of the processes by software, operations and security teams due before the end of 2/2012

New WBS Item OSG consulting services requested by DES. Provide help on policies and procedures e.g. VO Policies and AUPs, User /Member Agreements, etc Deliverable is more understanding of what documents are useful, what VO documents we can point to, a wiki page to make any further VO’s life easier. Investigation stage. No due date is yet set. Estimated to be 2 fte week worth of work. Mine will do this.

Issues /Worries DOE Grids CA transition implementation will be high priority and high visibility. Do we have confidence in the effort needed? It looks like handling of storage/data areas is not really understood or provided for. Kevin Hill is a great asset. Need him to ramp up to full time before the ST&E start. Not doing sufficient training – this is not on the WBS; should it be?