15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,

Slides:



Advertisements
Similar presentations
Grid Security Policy GridPP18, Glasgow David Kelsey 21sr March 2007.
Advertisements

Last update 01/06/ :23 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD Site Registration policy & procedures
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
30-Jan-03D.P.Kelsey, GridPP Security1 Security GridPP6 30 Jan 2003 Coseners House David Kelsey CLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE Operational Security OSCT JSPG March 2006 Ian Neilson, CERN.
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
RomeWorkshop on eInfrastructures 9 December LCG Progress on Policies & Coming Challenges Ian Bird IT Division, CERN LCG and EGEE Rome 9 December.
Deployment Session David Kelsey GridPP13, Durham 5 Jul 2005
INFSO-RI Enabling Grids for E-sciencE Incident Response Policies and Procedures Carlos Fuentes
EGEE ARM-2 – 5 Oct LCG Security Coordination Ian Neilson LCG Security Officer Grid Deployment Group CERN.
INFSO-RI Enabling Grids for E-sciencE SA1: Cookbook (DSA1.7) Ian Bird CERN 18 January 2006.
GGF12 – 20 Sept LCG Incident Response Ian Neilson LCG Security Officer Grid Deployment Group CERN.
LCG/EGEE Security Update HEPiX, Fall 2004 BNL, 18 October 2004 David Kelsey CCLRC/RAL, UK
Deployment Issues David Kelsey GridPP13, Durham 5 Jul 2005
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
JSPG: User-level Accounting Data Policy David Kelsey, CCLRC/RAL, UK LCG GDB Meeting, Rome, 5 April 2006.
INFSO-RI Enabling Grids for E-sciencE EGEE/LCG Joint Security Policy Group David Kelsey, CCLRC/RAL, UK EGEE.
Responsibilities of ROC and CIC in EGEE infrastructure A.Kryukov, SINP MSU, CIC Manager Yu.Lazin, IHEP, ROC Manager
10-Jun-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 10 June 2003 David Kelsey CCLRC/RAL, UK
Security Policy Update LCG GDB Prague, 4 Apr 2007 David Kelsey CCLRC/RAL
13-Jul-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint LCG/EGEE Security Group) CERN 13 July 2004 David Kelsey CCLRC/RAL,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
9-Sep-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 9 September 2003 David Kelsey CCLRC/RAL, UK
23-Oct-03D.P.Kelsey, LCG Security Update, HEPiX1 LCG Security Update HEPiX-HEPNT, TRIUMF, 23 October 2003 David Kelsey CCLRC/RAL, UK
8-Jul-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) RAL, 8 July 2003 David Kelsey CCLRC/RAL, UK
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and OSG: Common Security Policies? OSG.
LCG Pilot Jobs + glexec John Gordon, STFC-RAL GDB 7 November 2007.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Linda Cornwall CCLRC (RAL) FP6 Security workshop.
LCG/EGEE Security Operations HEPiX, Fall 2004 BNL, 22 October 2004 David Kelsey CCLRC/RAL, UK
9-Oct-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) FNAL 9 October 2003 David Kelsey CCLRC/RAL, UK
Grid Security Vulnerability Group Linda Cornwall, GDB, CERN 7 th September 2005
INFSO-RI Enabling Grids for E-sciencE EGEE SA1 in EGEE-II – Overview Ian Bird IT Department CERN, Switzerland EGEE.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Dr Linda Cornwall CCLRC (RAL) FP6 Security workshop.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
Security Operations David Kelsey GridPP Deployment Board 3 Mar 2005
Security Vulnerability Identification and Reduction Linda Cornwal, JRA1, Brno 20 th June 2005
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Last update 21/01/ :05 LCG 1Maria Dimou- cern-it-gd Current LCG User Registration, VO management and Authorisation Procedures VOMS workshop
INFSO-RI Enabling Grids for E-sciencE An overview of EGEE operations & support procedures Jules Wolfrat SARA.
Last update 29/01/ :01 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD CERN VOMS server deployment LCG Grid Deployment Board
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
Last update 31/01/ :41 LCG 1 Maria Dimou Procedures for introducing new Virtual Organisations to EGEE NA4 Open Meeting Catania.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI SPG future work EGI Technical Forum Lyon, 21 Sep 2011 David Kelsey, STFC/RAL.
EGEE is a project funded by the European Union under contract IST Roles & Responsibilities Ian Bird SA1 Manager Cork Meeting, April 2004.
1Maria Dimou- cern-it-gd LCG November 2007 GDB October 2007 VOM(R)S Workshop report Grid Deployment Board.
Last update 22/02/ :54 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD VO Registration procedure Presented by.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and JSPG activities David Kelsey CCLRC/RAL.
Security EGEE/SA1 ROC Managers ARM-3 meeting Lyon, 17 March 2005 David Kelsey CCLRC/RAL, UK
EGEE ARM-2 – 5 Oct LCG/EGEE Security Coordination Ian Neilson Grid Deployment Group CERN.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
Last update 29/02/ :31 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD VOMS status IT GD Group Meeting
18-May-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) Barcelona 18 May 2004 David Kelsey CCLRC/RAL, UK
Security Policy Update WLCG GDB CERN, 8 Dec 2010 David Kelsey STFC/RAL david.kelsey AT stfc.ac.uk.
Planning for LCG Emergencies HEPiX, Fall 2005 SLAC, 13 October 2005 David Kelsey CCLRC/RAL, UK
Last update 13/03/ :11 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD Status of the Task Force for User Registration of LHC Experiment Users
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
LCG User, Site & VO Registration in EGEE/LCG Bob Cowles OSG Technical Meeting Dec 15-17, 2004 UCSD.
LCG Pilot Jobs + glexec John Gordon, STFC-RAL GDB 7 December 2007.
1Maria Dimou- cern-it-gd LCG End of the Task Force for VO User Registration of LHC Experiment Users Grid Deployment.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
David Kelsey CCLRC/RAL, UK
SA1 Execution Plan Status and Issues
LCG Security Status and Issues
David Kelsey CCLRC/RAL, UK
Ian Bird GDB Meeting CERN 9 September 2003
Incident Response Plan for the Open Science Grid
David Kelsey CCLRC/RAL, UK
Presentation transcript:

15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL, UK

15-Dec-04D.P.Kelsey, LCG-GDB-Security2 Overview Joint Security Policy Group meetings –2 Nov 2004, 6 Dec 2004 –25 Nov 2004 (EGEE workshop – Joint with SA1) –Next meeting: 24/25 Jan 2005 (CERN) Site Registration Policy & Procedures (approval) Now also reporting to EGEE SA1 (ROC managers) VO Registration User Registration Task Force Operational Security/Incident Response User Rules/AUP Plans for next meeting

last update 29/11/ :28 LCG 3Maria Dimou- cern-it-gd D.P.Kelsey, LCG-GDB- SecurityMaria Dimou IT/GD Site Registration policy & procedures Joint Security Policy Group Meeting EGEE Conference Den Haag

last update 29/11/ :28 LCG 4Maria Dimou- cern-it-gd D.P.Kelsey, LCG-GDB- SecurityMaria Dimou IT/GD What we want to achieve  Ensure that Resource Administrators understand and have agreed to their responsibility to abide by LCG/EGEE operational policies.  The new sites provide all necessary contact and security information before they can be part of the Grid.  The respective ROC becomes the one responsible for checking the validity of the information provided by the site and enabling it to join.  The GOC database becomes the only place that the Deployment Team will consult to obtain valid contact information about a site.

last update 29/11/ :28 LCG 5Maria Dimou- cern-it-gd D.P.Kelsey, LCG-GDB- SecurityMaria Dimou IT/GD Site Registration Information  The full name of the participating institute and site.  The abbreviated name of the site to be published in the information system.  The name, address and telephone number of the designated site manager.  The name address and telephone number of an individual to act as site security contact.  The address of a managed list for contact with site administrators.  The address of a managed list for contact with incident response team members.  The name of the Regional Operations Centre providing support for the site.

last update 29/11/ :28 LCG 6Maria Dimou- cern-it-gd D.P.Kelsey, LCG-GDB- SecurityMaria Dimou IT/GD Site Registration Procedure  NewSite_To_ROC: Initial Registration Info and Statement of Acceptance of the Policy Documents.  If OK ROC_To_GOC: Request for new entry in the GOC db.  Site status: candidate  NewSite_In_GOCdb: Complete Registration Info.  NewSite_To_ROC: Info validation request.  If OK ROC changes status: uncertified (read GOC manager in case of no ROC)

last update 29/11/ :28 LCG 7Maria Dimou- cern-it-gd D.P.Kelsey, LCG-GDB- SecurityMaria Dimou IT/GD Site certification Procedure  NewSite_To_DTEAM-admin: Apply for DTEAM VO membership to check via test job submission the completeness of the local installation.  NewSite_To_CIC: Request quality testing.  NewSite_To_LCG-deployment-support:  Request to be included in the Testzone,  Be subject to further acceptance tests  LCG-deployment-support: Includes the new site in the BDII.  If OK ROC changes status: certified

15-Dec-04D.P.Kelsey, LCG-GDB-Security8 Site Registration issues One main discussion point Formal (written) procedure required? –For ROC to verify/approve new site? Similar to RA’s for CA’s Important for audit trail and to justify refusal Awaiting input from ROC managers My view: yes, we need it

15-Dec-04D.P.Kelsey, LCG-GDB-Security9 VO registration Lots of useful and lengthy discussion on this topic! Security issues vs VO approval vs integration New EGEE NA4/SA1 group (OAG) – In Den Haag, agreed to merge the JSPG draft document with an EGEE SA1 document – (JSPG) – (SA1) Subsequently –Agreed to split again –A new “Security” policy document (Jan 2005)

15-Dec-04D.P.Kelsey, LCG-GDB-Security10 LHC User Registration Presented in Oct 2004 GDB Work continues –On modifications to VOMRS at FNAL –On interface to Oracle DB (HR) at CERN Task Force meets monthly to review Aim to implement in early 2005 (March?)

15-Dec-04D.P.Kelsey, LCG-GDB-Security11 Operational Security Overview was presented by Ian Neilson at Den Haag Open Science Grid Incident Response –Presented in Den Haag by Bob Cowles EGEE OSCT team has been formed (Ian Neilson) –Representative from each ROC Working on Incident Response (based on OSG) And Security best practice (web) advice –E.g. forensics of incidents

15-Dec-04D.P.Kelsey, LCG-GDB-Security12 Other topics New User Rules and AUP –Draft AUP input to eIRG workshop (Den Haag) –White Paper being finalised this week Issues: Liability, for-profit or personal use, definition of “offensive” or illegal data Aim to have new LCG/EGEE AUP early next year –Jointly with OSG and others Automated Client Certificates –Job injectors and/or data managers –Technical and policy issues

15-Dec-04D.P.Kelsey, LCG-GDB-Security13 Future Plans January 24/ meeting –Major review of the Security Risk Analysis –And associated risk management –To prioritise activities in 2005 Top-level Security Policy and many associated guides need revision –More general (“Grid” not “LCG-1”) –Useful to OSG and other projects –And tied in to eIRG White Paper activities Need to review status of the 3 LCG GOC “Guides” Operational Security very important, esp incident response Security Vulnerability analysis –GridPP work started here 2005: the year of the first real attack on Grid?

15-Dec-04D.P.Kelsey, LCG-GDB-Security14 Summary Lots of work in progress GDB approval of Site Registration document?