ESnet RAF and eduroam ™ Tony J. Genovese ATF Team ESnet/Lawrence Berkeley National Laboratory.

Slides:



Advertisements
Similar presentations
MyProxy Jim Basney Senior Research Scientist NCSA
Advertisements

Usage of PGP in TACAR 19th OGF Meeting Chapel Hill, USA February 1, 2007 Licia Florio Project Development Officer
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
DOE’s PKI service for Grids Tony J. Genovese Malaga, Spain November 2003.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
Cross Platform Single Sign On using client certificates Emmanuel Ormancey, Alberto Pace Internet Services group CERN, Information Technology department.
Open Science Grid Use of PKI: Wishing it was easy A brief and incomplete introduction. Doug Olson, LBNL PKI Workshop, NIST 5 April
Password?. Project CLASP: Common Login and Access rights across Services Plan
2006 © SWITCH Authentication and Authorization Infrastructures in e-Science (and the role of NRENs) Christoph Witzig SWITCH e-IRG, Helsinki, Oct 4, 2006.
PKI Activities at Virginia January 2004 CSG Meeting Jim Jokl.
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
TF-EMC2 February 2006, Zagreb Deploying Authorization Mechanisms for Federated Services in the EDUROAM Architecture (DAME) -Technical Project Proposal-
CA-OPS Authentication Profiles Tony Genovese ATF team ESnet Lawrence Berkeley National Laboratory.
Open Science Grid Use of PKI: Wishing it was easy A brief and incomplete introduction. Doug Olson, LBNL PKI Workshop, NIST 5 April 2006.
NRENs supporting Grids using current Grid technology TERENA NREN-GRID Workshop Amsterdam Milan Sova CESNET.
Understanding Active Directory
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Public Key Infrastructure from the Most Trusted Name in e-Security.
Public Key Infrastructure Ammar Hasayen ….
1 Digital Credential for Higher Education John Gardiner August 11, 2004.
Virginia Tech Overview of Tech Secure Enterprise Technology Initiatives e-Provisioning Group Frank Galligan Fed/Ed.
Deploying a Certification Authority for Networks Security Prof. Dr. VICTOR-VALERIU PATRICIU Cdor.Prof. Dr. AUREL SERB Computer Engineering Department Military.
Best Practices in Deploying a PKI Solution BIEN Nguyen Thanh Product Consultant – M.Tech Vietnam
12-May-03D.P.Kelsey, SCG Online Authentication1 Online Authentication SCG Meeting EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
Grid Security Issues Shelestov Andrii Space Research Institute NASU-NSAU, Ukraine.
2005 © SWITCH Perspectives of Integrating AAI with Grid in EGEE-2 Christoph Witzig Amsterdam, October 17, 2005.
GILDA testbed GILDA Certification Authority GILDA Certification Authority User Support and Training Services in IGI IGI Site Administrators IGI Users IGI.
March 27, 2006TAGPMA - Rio de Janeiro1 Short Lived Credential Services Profile Tony J. Genovese The Americas Grid PMA DOEGridsATF/ESnet/LBNL.
High-quality Internet for higher education and research AAI from the NREN perspective Schiphol, October 17, 2005
Neil Witheridge APAN29 Sydney February 2010 ARCS Authorisation Services Neil Witheridge Manager, ARCS Authorisation Services APAN29, Sydney, February 2010.
TERENA TF-EMC2 Workshop David Groep,
Grid and NREN operational support Tony Genovese ATF team ESnet Lawrence Berkeley National Laboratory.
Module 9: Designing Public Key Infrastructure in Windows Server 2008.
ESnet PKI Developed for the DOE Science Grid and SciDAC.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
The Distribution Online Vending Pilot Project Demo Testing Certificate Management Kennedy P Subramoney 23 July 2004.
SOS August 21, 2006 GGF Security for Open Science Center for Enabling Technology Lead PI - Deb Agarwal, Lawrence Berkeley National Laboratory - Lawrence.
National Computational Science National Center for Supercomputing Applications National Computational Science GSI Online Credential Retrieval Requirements.
Leveraging the InCommon Federation to access the NSF TeraGrid Jim Basney Senior Research Scientist National Center for Supercomputing Applications University.
University of Washington Identity and Access Management IEEAF – RENU Network Design Workshop Seattle - 29 Nov 2007 Lori Stevens, Director, Distributed.
Identity Management in DEISA/PRACE Vincent RIBAILLIER, Federated Identity Workshop, CERN, June 9 th, 2011.
NRENs, Grids and Integrated AAI In Search For the Utopian Solution Christos Kanellopoulos AUTH/GRNET October 17 th, 2005 skanct at physics.auth.gr 2nd.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Module 3 Planning for Active Directory®
Connect. Communicate. Collaborate Deploying Authorization Mechanisms for Federated Services in the eduroam architecture (DAMe)* Antonio F. Gómez-Skarmeta.
Office of Science U.S. Department of Energy Grid Security at NERSC/LBL Presented by Steve Chan Network, Security and Servers
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
Grid Security and Identity Management Mine Altunay Security Officer, Open Science Grid, Fermilab.
Community PKIs Initiatives Updates TF-EMC2 Meeting Loughborough, UK 6-7 May, 2009 Licia Florio, TERENA
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
VOMS Attribute Authorities Michael Helm ESnet/LBNL 23 Feb 2007.
12-Jun-03D.P.Kelsey, CA meeting1 CA meeting Minimum Requirements CERN, 12 June 2003 David Kelsey CCLRC/RAL, UK
The GRIDS Center, part of the NSF Middleware Initiative Grid Security Overview presented by Von Welch National Center for Supercomputing.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay, James Basney,
TACAR Updates version David Groep, NIKHEF. 9 th EUGridPMA ‘RAL’ meeting – Jan David Groep – TACAR Aims  Trusted and.
GIRAF Grid Integrated Radius Authentication Fabric A Whole Bunch of People GGF-11 June 9, 2004.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
DataGrid Security Wrapup Linda Cornwall 4 th March 2004.
Security Bob Cowles
A Study of Certification Authority Integration Model in a PKI Trust Federation on Distributed Infrastructures for Academic Research Eisaku SAKANE, Takeshi.
Supporting Advanced Scientific Computing Research Basic Energy Sciences Biological and Environmental Research Fusion Energy Sciences High Energy Physics.
National Center for Supercomputing Applications University of Illinois at Urbana-Champaign This material is based upon work supported by the National Science.
Secure Connected Infrastructure
LCG Security Status and Issues
Secure Enterprise Technology Initiatives e-Provisioning Group
کاربرد گواهی الکترونیکی در سیستمهای کاربردی (امضای دیجیتال)
Public Key Infrastructure from the Most Trusted Name in e-Security
Presentation transcript:

ESnet RAF and eduroam ™ Tony J. Genovese ATF Team ESnet/Lawrence Berkeley National Laboratory

ATF Overview Authentication services for DOE Office of Science projects, including international collaborations, computational Grids, ESnet community, and ESnet internal Authentication services for DOE Office of Science projects, including international collaborations, computational Grids, ESnet community, and ESnet internal Primarily focused on the Office of Science community Primarily focused on the Office of Science community ATF’s principle service is a set of certificate authorities (CAs) ATF’s principle service is a set of certificate authorities (CAs) Policy is driven completely by the needs of the science community Policy is driven completely by the needs of the science community Facilitating several trust federations to enable interoperable science Grids – Policy Management Authorities Facilitating several trust federations to enable interoperable science Grids – Policy Management Authorities the IGTF - International Grid Trust Federation the IGTF - International Grid Trust Federation the Americas “regional” policy management authority – TAGPMA the Americas “regional” policy management authority – TAGPMA ATF also pilots new technology, new policy systems, and develops project proposals in collaboration with other partners ATF also pilots new technology, new policy systems, and develops project proposals in collaboration with other partners

3 FTEs plus heavy support from ESnet UNIX services 3 FTEs plus heavy support from ESnet UNIX services Plus additional support from network engineering, services, and windows support Plus additional support from network engineering, services, and windows support Roles Roles CA Operator CA Operator Developer Developer Federation Liaison Federation Liaison Product Manager (community outreach) Product Manager (community outreach) Specialized system administration Specialized system administration PMA chairman / member PMA chairman / member Contributor to community best practices/standards efforts Contributor to community best practices/standards efforts All team members have cross trained to insure continuity. All team members have cross trained to insure continuity. Authentication and Trust Federation Team

ESnet subordinate Certificate Authorities and Services ESnet Root CA FUSION (Credential Store) ESnet SSL/TLS ESnet Root CA only signs subordinate CAs DOEGrids Future Co-hosting OCSP Service NERSC Site – NIM Integration PKI Certificate Authorities Overview

Offline Vaulted Root CA Internet Firewall Intrusion Detection Grid User HSM Secure Data Center Building Security LBNL Site security Hardware Security Modules Access controlled racks PKI Systems PKI Security Environment Secure VLAN

DOEGrids CA Usage Statistics User Certificates 1999 Total No. of Certificates 5479 Host & Service Certificates 3461 Total No. of Requests 7006 ESnet SSL Server CA Certificates 38 DOEGrids CA 2 CA Certificates (NERSC) 15 Fusion GRID CA certificates 76 * Report as of Jun 15, 2005

RAF, eduroam ™ and Internet2 interconnects eduroam ™ ESnet RAF eduroam US Internet2 eduroam US Internet2 ESnet LBNL TERENA NL Internet2 UTK Interconnecting with eduroam™ at UTK Interconnect Grid Realms at TERENA ESnet possible secondary route for eduroam™ ORNL PPNL ANL NERSC eduroam ™ Grid realms DOEGrids MyProxy Crypto Card Secure ID Aladdin Smart Card

Grid eduroam ™ Experiment Phase 0 Phase 0 Use Infoblox loaded with IGTF root certificates Use Infoblox loaded with IGTF root certificates EAP/TLS Strong Authentication based on Grid Identity Certs EAP/TLS Strong Authentication based on Grid Identity Certs eduroam ™ Authorization attributes – eduroam ™ defines eduroam ™ Authorization attributes – eduroam ™ defines TACAR or EUGridPMA repository as trust anchor TACAR or EUGridPMA repository as trust anchor IGTF OCSP experimental service – GGF defining the service IGTF OCSP experimental service – GGF defining the service Interconnect to eduroam ™ at UTK Interconnect to eduroam ™ at UTK Grid top level interconnect Grid top level interconnect TERENA - Root TERENA - Root ESnet ESnet Grid PMAs: EU Grid PMA, AP Grid PMA and TAGPMA Grid PMAs: EU Grid PMA, AP Grid PMA and TAGPMA User experience local site dependency User experience local site dependency eduroam ™ defines eduroam ™ defines Each site controls how they expose or provide a service to the community. Each site controls how they expose or provide a service to the community. Develop Federation document set Develop Federation document set Based on GGF documents Plus eduroam ™ policies Based on GGF documents Plus eduroam ™ policies

Next Phases Phase 1 Phase 1 Add Authorization Schema Add Authorization Schema Phase 0 plus LDAP server Phase 0 plus LDAP server Phase 2 Phase 2 Add Virtual Organization Management System Add Virtual Organization Management System Shibboleth Shibboleth GGF – GridShib or other? GGF – GridShib or other? TF-EMC2 TF-EMC2 Phase 0 plus VOMS servers Phase 0 plus VOMS servers Phase 3 – production hardening Phase 3 – production hardening Implement our community’s selected solution – or ? Implement our community’s selected solution – or ?

ESnet RAF Experiment systems LDAP User Account DB phase 1+ Grid Interconnect TERENA RAF radius appliance eduroam ™ Internet2 Interconnect Possible eduroam ™ backup route Cisco Catalyst 4000 EAPOL test bed