GRID middleware and security, the missing bits David Kelsey TAC, Malaga 8 Jun 2009.

Slides:



Advertisements
Similar presentations
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Why Grids Matter to Europe Bob Jones EGEE.
Advertisements

EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
The EGI – a sustainable European grid infrastructure Michael Wilson STFC RAL.
Grid Computing in Higher Education (Scott Rea) EDUCAUSE PKI Deployment Forum Madison, WI - April 15, 2008.
Authorization WG Update David Kelsey EU Grid PMA, Copenhagen 27 May 2008.
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
The LHC Computing Grid – February 2008 The Worldwide LHC Computing Grid Dr Ian Bird LCG Project Leader 15 th April 2009 Visit of Spanish Royal Academy.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Policy Issues for Identity Management (and other attributes) EGI Technical.
Updates from the EUGridPMA David Groep, Apr 20 th, 2009.
Updates from the EUGridPMA David Groep, Oct 11 th, 2011.
Grid Trust Fabric TNC 2006, Catania 16 May 2006 David Kelsey CCLRC/RAL, UK
Updates from the EUGridPMA David Groep, Apr 8 nd, 2008.
Authentication and Authorization in a federated environment Jules Wolfrat (SARA)
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
4th EGEE Meeting, PISA October, 2005 E-Infraestructure shared between Europe and Latin America Jesús Casado, CIEMAT
Advanced Computing Services for Research Organisations Bob Jones Head of openlab IT dept CERN This document produced by Members of the Helix Nebula consortium.
Updates of APGrid PMA 22 June, Members (15 + 1) 15 Accredited CAs AIST (JP) APAC (AU) ASGC (TW) CNIC (CN), SDG IGCA (IN) IHEP (CN) KEK (JP) KISTI.
A short introduction to GRID Gabriel Amorós IFIC.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
INFSO-RI Enabling Grids for E-sciencE EGEE Induction Grid training for users, Institute of Physics Belgrade, Serbia Sep. 19, 2008.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
5 th APGrid PMA Meeting An Update from the TAGPMA Vinod Rebello Taipei, Taiwan 20th April 2009 The Americas Grid Policy Management Authority.
CAOPS-IGTF Session An Update from the TAGPMA Vinod Rebello given by Scott Rea OGF 25, Catania, Italy March 2, 2009 The Americas Grid Policy Management.
TERENA TF-EMC2 Workshop David Groep,
Updates from the EUGridPMA David Groep, July 16 st, 2007.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE – paving the way for a sustainable infrastructure.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
TAGPMA & the Bridge WG (Scott Rea – Dartmouth College) Internet2 Member Meeting, Dec 2006 PKI Activities and Applications Update - Chicago, IL.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Bob Jones EGEE project director CERN.
FP6−2004−Infrastructures−6-SSA E-infrastructure shared between Europe and Latin America EELA Infrastructure (WP2) Roberto Barbera.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
INFSO-RI Enabling Grids for E-sciencE External Projects Integration Summary – Trigger for Open Discussion Fotis Karayannis, Joanne.
Federating the Grid David Kelsey TNC2010, Vilnius 2 Jun 2010.
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
E-science grid facility for Europe and Latin America Task TSA1.3 - Authentication Services and Policies Acheivements Jacques Alves da Silva.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGI Operations Tiziana Ferrari EGEE User.
Updates from the EUGridPMA David Groep, May 9 st, 2007.
NRENs, Grids and Integrated AAI In Search For the Utopian Solution Christos Kanellopoulos AUTH/GRNET October 17 th, 2005 skanct at physics.auth.gr 2nd.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Opening Remarks and Updates of the APGrid PMA 5 th APGridPMA September 16, 2008 Yoshio Tanaka APGridPMA Chair, AIST, Japan.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
WLCG Laura Perini1 EGI Operation Scenarios Introduction to panel discussion.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE: Enabling grids for E-Science Bob Jones.
Grid Security Update David Kelsey (RAL) HEPiX, LBNL 28 Oct 2009.
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
David Groep Nikhef Amsterdam PDP & Grid AARC Authentication and Authorisation for Research and Collaboration an impression of the road ahead.
Summary of Poznan EUGridPMA32 September EUGridPMA Poznan 2014 meeting – 2 David Groep – Welcome back at PSNC.
15 th EUGridPMA Plenary Meeting Update from the TAGPMA Vinod Rebello Nicosia, Cyprus January 26 – 28, 2009 The Americas Grid Policy Management Authority.
Update of APGridPMA Eric Yen 25 th EUGridPMA & IGTF All Hands Meeting KIT, Germany 7 May, 2012.
Welcome to Amsterdam EUGridPMA35 September EUGridPMA Amsterdam 2015 meeting – 2 David Groep – Welcome back in Amsterdam.
14 th EUGridPMA Meeting Update from TAGPMA Jim Basney Lisbon, Portugual October 6-8, 2008 The Americas Grid Policy Management Authority.
Grid Security Policy: EGEE to EGI David Kelsey (RAL) 16 Sep 2009 JSPG meeting, DFN Berlin david.kelsey at stfc.ac.uk.
An Update from the TAGPMA Scott Rea EuGridPMA Mtg, Berlin, DE Sept 13, 2009 The Americas Grid Policy Management Authority.
Updates of APGrid PMA 18 th EUGridPMA Meeting 18 th EUGridPMA Meeting 18 January, 2010 Eric Yen ASGCCA Taiwan.
16 th EUGridPMA Meeting An Update from the TAGPMA Vinod Rebello Zurich, Switzerland 11th May 2009 The Americas Grid Policy Management Authority.
Grids & PKI: TAGPMA & Bridges (Scott Rea – Dartmouth College) Internet2 Member Meeting, Dec 2006 PKI Implementers Workshop - Chicago, IL.
LCG Security Status and Issues
EGEE support for HEP and other applications
EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.
David Kelsey (STFC-RAL)
AAI in EGI Status and Evolution
Presentation transcript:

GRID middleware and security, the missing bits David Kelsey TAC, Malaga 8 Jun 2009

8 Jun 09Grids, TAC, Kelsey2 Outline EGEE and EGI – Introduction Federated Identity Management Virtual Organisations, Global Trust and Attribute Management Operational Security Disclaimers: My personal views –not the official views of any Grid project, IGTF etc. “Middleware” - just Authentication and Authorisation “Missing bits” – well at least some pointers to possibilities for future coordination Thanks to (for slides): Bob Jones and David Groep –With some modifications by me

Enabling Grids for E-sciencE EGEE-III INFSO-RI EGEE - Bob Jones - Research Connection, Prague, May EGEE-III Main Objectives –Expand/optimise existing EGEE infrastructure, include more resources and user communities –Prepare migration from a project- based model to a sustainable federated infrastructure based on National Grid Initiatives Flagship Grid infrastructure project co-funded by the European Commission Duration: 2 years Consortium: ~140 organisations across 33 countries EC co-funding: 32Million €

Enabling Grids for E-sciencE EGEE-III INFSO-RI EGEE - Bob Jones - Research Connection, Prague, May 2009 ~280 sites 45 countries >80,000 CPUs >20 PetaBytes >14,000 users >250,000 jobs/day

Enabling Grids for E-sciencE EGEE-III INFSO-RI EGEE - Bob Jones - Research Connection, Prague, May Applications >260 VOs from several scientific domains –Astronomy & Astrophysics –Civil Protection –Computational Chemistry –Comp. Fluid Dynamics –Computer Science/Tools –Condensed Matter Physics –Earth Sciences –Fusion –High Energy Physics –Life Sciences More applications and user communities every month

Enabling Grids for E-sciencE EGEE-III INFSO-RI EGEE - Bob Jones - Research Connection, Prague, May Collaborating e-Infrastructures

Goal: Long-term sustainability of grid infrastructures in Europe Approach: Establish a federated model bringing together National Grid Infrastructures (NGIs) to build the European Grid Infrastructure (EGI) EGI Organisation: Coordination and operation of a common multi-national, multi- disciplinary Grid infrastructure To enable and support international Grid-based collaboration To provide support and added value to NGIs To liaise with corresponding infrastructures outside Europe 7

EGI workshop, CataniaMarch 2nd, EGI and NGI Tasks EGI tasks NGI international tasks NGI local tasks EGI NGI

Federated Identity Management for Grids International Grid Trust Federation (IGTF) –3 geographical Policy Management Authorities Coordinates a Global PKI (X.509) –Used by many different Grids IGTF defines minimum requirements and best practices –Accredits CAs against –3 different authentication profiles 8 Jun 09Grids, TAC, Kelsey9

OGF25 IGTF Work shop– Mar David Groep – Geographical coverage of the EUGridPMA  25 of 27 EU member states (all except LU, MT)  +AM, CH, HR, IL, IR, IS, MA, ME, MK, NO, PK, RO, RS, RU, TR, UA, SEE-GRID + CA, CERN (int), DoEGrids(US)* Pending or in progress  BY, MD, SY, LV, ZA, SN

11 16th EUGridPMA Mtg, 11 May 09Vinod Rebello – TAGPMA Membership NRC – Canada ESnet (DOEGrids) – USA EELA – International Fermi National Accelerator Laboratory - USA HEBCA/USHER/Dartmouth College – USA IBDS (ANSP) - Brazil WLCG – International NCSA – USA NERSC – USA Open Science Grid – International Purdue University – USA REUNA – Chile San Diego Supercomputer Center – USA SENAMHI – Peru TACC – USA TeraGrid (PSC) – USA Texas High Energy Grid – USA University of Virginia – USA UFF – Brazil ULA – Venezuela UNAM – Mexico UNLP – Argentina IGTF Accredited CA Operators CA Accreditation in progress Interested in accreditation Relying Party

APGridPMA members AIST (JP) APAC (AU) ASGCC (TW) CNIC (CN) HKU (HK) IGCA (IN) IHEP (CN) KEK (JP) KISTI (KR) NAREGI (JP) NCHC (TW) NECTEC (TH) NGO/Netrust (SG) PRAGMA-UCSD (US) 8 Jun 09Grids, TAC, Kelsey12

Interfederation Grids-NRENs A growing number of CAs are now run by NRENs (or NGIs) Future challenges for Grid IdM –Scaling –Ease of use -> Interfederation: IGTF and R&E AAIs –Started with SWITCH 8 Jun 09Grids, TAC, Kelsey13

OGF25 IGTF Work shop– Mar David Groep – A Federated Grid CA  Use your federation ID ... to authenticate to a service ... that issues a certificate ... recognised by the Grid today Graphic from: Jan Meijer, UNINETT

OGF25 IGTF Work shop– Mar David Groep – Matching the Grid requirements  Persistent and unique naming  IdPs historically tended to recycle login names  even eduPersonPrincipalName is often recyled  only eduPersonTargetedID is immune to thus, but not supported everywhere (and is usually opaque)  this adds a requirement to the federation or to the IdPs  Reasonable representation of names  Given name, surname and nickname are usually considered privacy sensitive  user-approved release of these appears doable  requires evaluation of legal framework

OGF25 IGTF Work shop– Mar David Groep – New: TERENA Grid CA Service  Initial partners: FEIDE, SURFfederatie, HAKA, WAYF, Swamid, TERENA (replaces DutchGrid and NorduGrid CAs)  Trans-national, cross-federation service  But not (yet) confederated  How many SLCS/MICS CAs does Europe need ?  Consolidate operational PKI skills in one place  Better sustainability, in line with the European trend

OGF25 IGTF Work shop– Mar David Groep – Federated CAs in Europe  SWITCH: May 2007  TERENA: Summer 2009  Others interested (CESNET, …)

Some issues LoA –Grids demand stricter identity vetting than some other applications Data Privacy –Grids require release of display names 8 Jun 09Grids, TAC, Kelsey18

Virtual Organisations and Global Trust Security/Trust model –User registers once with VO Sites delegate this to the VO –VO builds trust with a Grid –Interoperable common simple policy documents essential to regulate behaviour User, Site, VO AUP & security policies 8 Jun 09Grids, TAC, Kelsey19

Grid Authorisation: Attribute Management VO Membership Service (VOMS) –RBAC –Attribute Certificate (signed by VO) extension in proxy cert Contains groups, roles, and generalised attributes VO is SOA for these attributes –Needs to stay in control Aggregation of attributes (VO and Institute IdP) –some work already started in EGEE (SWITCH) VASH Should we (can we?) standardise some attributes? –SCHAC schema 8 Jun 09Grids, TAC, Kelsey20

Trustworthy AuthZ AA services IGTF working on min requirements and best practice for operation of a Grid Attribute Authority A possible scalable accreditation process NGIs (or NRENs) could do it according to IGTF standards 8 Jun 09Grids, TAC, Kelsey21

Grid Security Operations EGEE Operational Security Coordination Team (OSCT) –Regional structure (11 centres) Incident Response, Monitoring, Training Coordination already being explored with TF-CSIRTS (and TRANSITS training) –mutual benefits GRID-SEC being established to enable incident communication between GRIDs and GRIDs and NRENs 8 Jun 09Grids, TAC, Kelsey22

More details – further work Romain Wartel – talk at 17:00 today –“NRENs and Grid security teams: a critical cooperation” Supporting virtual technologies track And a BOF on Tuesday evening (19:00) 8 Jun 09Grids, TAC, Kelsey23

NRENs and Grids What about network operations? advertise the upcoming NRENs and Grids workshop at EGEE'09 –Jointly organised by TERENA and EGEE- SA2 8 Jun 09Grids, TAC, Kelsey24

Uniting our strengths to realise a sustainable European grid

Links EGEE EGI IGTF JSPG: EGEE OSCThttp://osct.web.cern.ch/osct/ GRID-SEC sec/Site/GRID-SEC.htmlhttp://grid-sec.web.cern.ch/grid- sec/Site/GRID-SEC.html 8 Jun 09Grids, TAC, Kelsey26

NRENS & Grids Identity Management –Inter-federation already happening, but room for growth –Room to work together, e.g. on LoA Attribute Management (AuthZ) –How to build a scalable trust fabric –Attributes defined in SCHAC? Operational Security –not replacing national CSIRTS, but adding value –encourage collaboration 8 Jun 09Grids, TAC, Kelsey27

Discussion 8 Jun 09Grids, TAC, Kelsey28