13-May-03D.P.Kelsey, WP8 CA and VO organistion1 CA’s and Experiment (VO) Organisation WP8 Meeting EDG Barcelona, 13 May 2003 David Kelsey CCLRC/RAL, UK.

Slides:



Advertisements
Similar presentations
CERN STAR TAP June 2001 Status of the EU DataGrid Project Fabrizio Gagliardi CERN EU-DataGrid Project Leader June 2001
Advertisements

EU DataGrid progress Fabrizio Gagliardi EDG Project Leader
5-Dec-02D.P.Kelsey, GridPP Security1 GridPP Security UK Security Workshop 5-6 Dec 2002, NeSC David Kelsey CLRC/RAL, UK
Stephen Burke - WP8 Status - 14/2/2002 Partner Logo WP8 Status Stephen Burke, PPARC/RAL.
The LHC experiments AuthZ Interoperation requirements GGF16, Athens 16 February 2006 David Kelsey CCLRC/RAL, UK
Andrew McNab - Manchester HEP - 22 April 2002 EU DataGrid Testbed EU DataGrid Software releases Testbed 1 Job Lifecycle Authorisation at your site More.
11-Dec-01D.P.Kelsey, Authentication1 Authentication 11 Dec 2001 David Kelsey CLRC/RAL, UK
5-Sep-02D.P.Kelsey, Security Summary, Budapest1 WP6/7 Security Summary Budapest 5 Sep 2002 David Kelsey CLRC/RAL, UK
Grid Security in EGEE/LCG ISGC 2005, Taipei, Taiwan 29 April 2005 David Kelsey CCLRC/RAL, UK
30-Jan-03D.P.Kelsey, GridPP Security1 Security GridPP6 30 Jan 2003 Coseners House David Kelsey CLRC/RAL, UK
Authentication Policy David Kelsey CCLRC/RAL 15 April 2004, Dublin
Security Mechanisms The European DataGrid Project Team
The EU Grid PMA David Kelsey CCLRC/RAL 16 April 2004, Dublin
Joining the Grid Andrew McNab. 28 March 2006Andrew McNab – Joining the Grid Outline ● LCG – the grid you're joining ● Related projects ● Getting a certificate.
Welcome to CERN Research Technology Training Collaborating.
C. Loomis – Testbed: Status… – Sep. 5, 2002 – 1 Testbed: Status & Plans Charles Loomis (CNRS) Sept. 5, th Project Conference (Budapest)
RomeWorkshop on eInfrastructures 9 December LCG Progress on Policies & Coming Challenges Ian Bird IT Division, CERN LCG and EGEE Rome 9 December.
Andrew McNab - Manchester HEP - 5 July 2001 WP6/Testbed Status Status by partner –CNRS, Czech R., INFN, NIKHEF, NorduGrid, LIP, Russia, UK Security Integration.
12-May-03D.P.Kelsey, SCG Online Authentication1 Online Authentication SCG Meeting EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
20-May-03D.P.Kelsey, LCG-1 Security, HEPiX1 Grid Security for LCG-1 HEPiX, NIKHEF, 20 May 2003 David Kelsey CCLRC/RAL, UK
GGF12 – 20 Sept LCG Incident Response Ian Neilson LCG Security Officer Grid Deployment Group CERN.
LCG/EGEE Security Update HEPiX, Fall 2004 BNL, 18 October 2004 David Kelsey CCLRC/RAL, UK
DataGrid WP6 CA meeting, CERN, 12 December 2002 IISAS Certification Authority Jan Astalos Department of Parallel and Distributed Computing Institute of.
Rackspace Analyst Event Tim Bell
DOE Grids New subordinate CP/CPS v2.3 New subordinate CP/CPS v2.3 New name DOEGrids.org New name DOEGrids.org Old name DOESciencegrid.org Old name DOESciencegrid.org.
The LHC Computing Grid – February 2008 The Worldwide LHC Computing Grid Dr Ian Bird LCG Project Leader 25 th April 2012.
TERENA TF-EMC2 Workshop David Groep,
SouthGrid SouthGrid SouthGrid is a distributed Tier 2 centre, one of four setup in the UK as part of the GridPP project. SouthGrid.
10-Jun-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 10 June 2003 David Kelsey CCLRC/RAL, UK
ESnet PKI Developed for the DOE Science Grid and SciDAC.
DataGrid WP6/CA CA Trust Matrices Trinity College Dublin (TCD) Brian Coghlan CERN DEC-2002.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
9-Sep-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 9 September 2003 David Kelsey CCLRC/RAL, UK
23-Oct-03D.P.Kelsey, LCG Security Update, HEPiX1 LCG Security Update HEPiX-HEPNT, TRIUMF, 23 October 2003 David Kelsey CCLRC/RAL, UK
8-Jul-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) RAL, 8 July 2003 David Kelsey CCLRC/RAL, UK
3-Nov-00D.P.Kelsey, HEPiX, JLAB1 Certificates for DataGRID David Kelsey CLRC/RAL, UK
BNL VO Management and Grid Mapfile Generation Brookhaven National Lab.
3-Jul-02D.P.Kelsey, Security1 Security meetings Report to EDG PTB 3 Jul 2002 David Kelsey CLRC/RAL, UK
Security Mechanisms The European DataGrid Project Team
…building the next IT revolution From Web to Grid…
Les Les Robertson LCG Project Leader High Energy Physics using a worldwide computing grid Torino December 2005.
Guy Wormser IN2P3/CNRS, EGEE Applications Manager December 18, 2003 EGEE is proposed as a project funded by the European Union under contract IST
9-Oct-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) FNAL 9 October 2003 David Kelsey CCLRC/RAL, UK
23-Oct-02D.P.Kelsey, Grid Security, HEPiX, FNAL1 LCG/EDG Security - update and plans HEPiX/HEPNT - FNAL 23 Oct 2002 David Kelsey CLRC/RAL, UK
2-Sep-02D.P.Kelsey, WP6 CA, Budapest1 WP6 CA report Budapest 2 Sep 2002 David Kelsey CLRC/RAL, UK
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Last update 31/01/ :41 LCG 1 Maria Dimou Procedures for introducing new Virtual Organisations to EGEE NA4 Open Meeting Catania.
Information Security Systems Cost Effective Authenticity & Integrity in CEN/FISCALIS eInvoicing Good Practice Guidelines Nick Pope – Principal Consultant,
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
11-Dec-00D.P.Kelsey, Certificates, WP6 meeting, Milan1 Certificates for DataGrid Testbed0 David Kelsey CLRC/RAL, UK
8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK
12-Jun-03D.P.Kelsey, CA meeting1 CA meeting Minimum Requirements CERN, 12 June 2003 David Kelsey CCLRC/RAL, UK
LHC Computing, SPC-FC-CC-C; H F Hoffmann1 CERN/2379/Rev: Proposal for building the LHC computing environment at CERN (Phase 1) Goals of Phase.
18-May-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) Barcelona 18 May 2004 David Kelsey CCLRC/RAL, UK
15-May-03D.P.Kelsey, SCG Summary1 Security Coord Group (SCG) EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
10-May-01D.P.Kelsey, WP6 Security1 Certificates/Authorisation for DataGrid Testbeds David Kelsey CLRC/RAL, UK
7-May-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Issues and Planning or Report from the Security Group CERN, 8 May 2003 David Kelsey CCLRC/RAL, UK.
EGEE is a project funded by the European Union under contract IST New VO Integration Fabio Hernandez ROC Managers Workshop,
11-May-01D.P.Kelsey, Security Update1 GRID Security Update David Kelsey CLRC/RAL, UK
Security, Authentication and Authorization on Grid Computing 1st Chinese-French workshop on LHC Physics and Associated Grid Computing Beijing, December.
DataGrid Security Wrapup Linda Cornwall 4 th March 2004.
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
NSO data collections of subjective well-being
David Kelsey CLRC/RAL, UK
Testbed: Status & Plans
David Kelsey CCLRC/RAL, UK
David Kelsey CCLRC/RAL, UK
The EU DataGrid Security Services
The EU DataGrid Security Services
Presentation transcript:

13-May-03D.P.Kelsey, WP8 CA and VO organistion1 CA’s and Experiment (VO) Organisation WP8 Meeting EDG Barcelona, 13 May 2003 David Kelsey CCLRC/RAL, UK

13-May-03D.P.Kelsey, WP8 CA and VO organistion2 Outline Certificate Authorities (CA’s) –Authentication –Electronic identity –Prove who you are like a national passport Virtual Organisation (VO) management –Authorization –Prove what you are allowed to do Like an entry Visa In context of EDG, LCG (and EGEE)

13-May-03D.P.Kelsey, WP8 CA and VO organistion3 CA background The EDG WP6 CA group –EDG, EU CrossGrid, US DOE, Canada, …(LCG) Best practice and min. standards for acceptable CA’s –Maintains list of approved CA’s CNRS/France acts as the “catch all” CA –subject to satisfactory Registration procedures –Users and hosts/services See

13-May-03D.P.Kelsey, WP8 CA and VO organistion4 Additions in new CA’s –Canada, Cyprus, Greece, Poland, Slovakia Others being developed/discussed (see later) New online CA’s and repositories –Concerns about User-held private key management –FNAL Kerberos CA (LCG-1) –SLAC Virtual Smart Card (BaBar) –Need to define best practice for “online CA” –and understand/manage risks

13-May-03D.P.Kelsey, WP8 CA and VO organistion5 The approved CA’s 18 on the trusted list (today) Canada, CERN, Cyprus, Czech Republic, France, Germany, Greece, Ireland, Italy, Netherlands, Nordic, Poland, Portugal, Russia, Slovakia, Spain, UK, USA “Catch-all” operated by CNRS/France Under development/consideration Belgium, FNAL (KCA), Hungary, Israel, Japan, Taiwan, (Austria?) FNAL and Taiwan the furthest down the road

2nd Annual EU Review – Feb – Software Integration, … – n° 6 Application Testbed Users VOUsers CMS106 WP687 ALICE63 ATLAS55 Earth Obs.29 BaBar29 LHCb28 ITeam22 Genomic22 TSTG16 Medical Img. 6 D03 CAUsers INFN (IT)113 CNRS (FR)71 UK58 CERN (CH)44 NIKHEF (NL)19 Russia15 US DOE10 Spain8 FZK (D)5 Czech Rep.3 Portugal3 NorduGrid2 Poland1 Canada0 Greece0 Slovakia0 TOTAL352 Certificate Authorities Group Evaluates & approves new CAs 16 currently approved. Collaborating w/ other grid proj. More on the way… Cyprus US FNAL (KCA) Belgium Taiwan Virtual Organizations Also for Storage Elements Guidelines (EDG rules) Course-grained Authorization. 2 nd EU Review (Loomis)

7 CNRS CA, DataGrid Catch-All CA Status at May 6 th 2003 Sophie Nicoud - CNRS/UREC – Barcelona May 12 th 2003

13-May-03D.P.Kelsey, WP8 CA and VO organistion8 CA Future Plans Life after DataGrid (in Europe)? –LHC Computing Grid (LCG) –EU FP6 (EGEE) Many of the national CA’s serve a community larger than just DataGrid (and its applications) Sensible to manage the CA requirements and best practices in a broad forum –GGF now working on this –EGEE likely to run the EU CA PMA –But, LCG-1 will define its list of trusted CA’s Online CA’s and certificate repositories –Need more work to understand and manage risks and responsibilities Need to agree the LCG “catch-all” CA for 2004

13-May-03D.P.Kelsey, WP8 CA and VO organistion9 VO Management

13-May-03D.P.Kelsey, WP8 CA and VO organistion10 User Registration: the model User has ONE Grid certificate –From National CA (or CERN or catch-all) –(Hopefully) used in any HEP Grid project Then user registers with EDG or LCG-1 –Two different Usage Guidelines/Rules –Two different Guidelines VO’s (signed) –LCG-1 will have an expiry date May also wish to collect more personal information Next, user requests to join an Experiment VO –More than one also possible Same VO shared between EDG and LCG-1 –At least to start with Same VO services/servers (LDAP) and managers Authorized access if in BOTH the Guidelines and VO

13-May-03D.P.Kelsey, WP8 CA and VO organistion11 VO Management Today in EDG –VO managers Alice: Daniele Mura (INFN) Atlas: Alessandro De Salvo (INFN) CMS: Andrea Sciaba (INFN) LHCb: Joel Closier (CERN) BaBar: Tim Adye (RAL) D0: Jeff Templon (NIKHEF) –All VO servers run by NIKHEF Except BaBar (UK GridPP) –No robust definition of what VO manager should do to check the identity and right of a user to join OK for EDG, but not LCG-1

13-May-03D.P.Kelsey, WP8 CA and VO organistion12 VO Management We need to check carefully before registering users in VO –Grants access to site resources LCG discussing/planning how to manage User registration For Production Grid on large scale –Site managers/security officers require robust and auditable registration procedures –To avoid the necessity of users registering at all sites Initial thoughts (for LCG) –Distributed VO registration authorities (for AuthZ) based on National Tier1/2 contacts LCG now considering RA’s based on the Experiment VO’s –EDG and LCG should work together on this (now) –To make more robust than current procedures –Long term aim is to use the Experiment User Offices

13-May-03D.P.Kelsey, WP8 CA and VO organistion13 Issues for discussion Any CA issues? –Catch-all should be able to cover everyone VO User Registration procedures –Need direct personal contact with end user By someone who knows them –Can one VO manager do this? –Hierarchical Reg system (per country? Per site?) VO groups/roles –How would WP8 like to use these?