Open Science Grid Security Activities Mine Altunay, FNAL OSG Security Officer For the OSG Security Team: Doug Olson, Deputy Security Officer, LBNL, Jim.

Slides:



Advertisements
Similar presentations
Grid Security Policy GridPP18, Glasgow David Kelsey 21sr March 2007.
Advertisements

 Contributing >30% of throughput to ATLAS and CMS in Worldwide LHC Computing Grid  Reliant on production and advanced networking from ESNET, LHCNET and.
Authorization WG Update David Kelsey EU Grid PMA, Copenhagen 27 May 2008.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 05/15/2013.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
Jan 2010 Current OSG Efforts and Status, Grid Deployment Board, Jan 12 th 2010 OSG has weekly Operations and Production Meetings including US ATLAS and.
Executive Director Report Ruth Pordes OSG Council Meeting, August 5 th 2008.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group EGI Technical Forum Sep 2010 David Kelsey.
Operational Security Working Group Topics Incident Handling Process –OSG Document Review & Comments:
OSG Security Review Mine Altunay June 19, June 19, Security Overview Current Initiatives  Incident response procedure – top priority (WBS.
OSG Security Program Review OSG Security Team M. Altunay, FNAL, OSG Security Officer, D. Olson LBNL, Ron Cudzewicz FNAL J. Basney NCSA, Anand Padmanabhan.
EGEE ARM-2 – 5 Oct LCG Security Coordination Ian Neilson LCG Security Officer Grid Deployment Group CERN.
GGF12 – 20 Sept LCG Incident Response Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Trust Relationships in Grid CHEP 07 Mine Altunay.
OSG RA plans Doug Olson, LBNL May Contents RA, agent, sponsor layout & OU=People use case Sample web form Agent Role GridAdmin Role Questions.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
Mine Altunay OSG Security Officer Open Science Grid: Security Gateway Security Summit January 28-30, 2008 San Diego Supercomputer Center.
OSG Project Manager Report for OSG Council Meeting OSG Project Manager Report for OSG Council Meeting October 14, 2008 Chander Sehgal.
OSG Security Review Mine Altunay December 4, 2008.
INFSO-RI Enabling Grids for E-sciencE EGEE/LCG Joint Security Policy Group David Kelsey, CCLRC/RAL, UK EGEE.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay OSG Security Officer.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Ake Edlund EGEE Sec Head 9th MWSG meeting, SLAC,
Open Science Grid Monitoring and Information Services Interoperability Breakout Session Shaowen Wang August 29, 2005 OSG Blueprint Meeting.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 8/15/2012.
OSG PKI Contingency and Recovery Plans Mine Altunay, Von Welch October 16, 2012.
Mine Altunay July 30, 2007 Security and Privacy in OSG.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Linda Cornwall CCLRC (RAL) FP6 Security workshop.
LCG/EGEE Security Operations HEPiX, Fall 2004 BNL, 22 October 2004 David Kelsey CCLRC/RAL, UK
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
9-Oct-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) FNAL 9 October 2003 David Kelsey CCLRC/RAL, UK
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
INFSO-RI Enabling Grids for E-sciencE EGEE SA1 in EGEE-II – Overview Ian Bird IT Department CERN, Switzerland EGEE.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Dr Linda Cornwall CCLRC (RAL) FP6 Security workshop.
9 Oct Overview Resource & Project Management Current Initiatives  Generate SOWs  8 written and 6 remain;  drafts will be complete next week 
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
Status Organization Overview of Program of Work Education, Training It’s the People who make it happen & make it Work.
Security Operations David Kelsey GridPP Deployment Board 3 Mar 2005
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) WLCG GDB, CERN 10 Jul 2013.
OSG RA, DOEGrids CA features Doug Olson, LBNL August 2006.
Lessons Learned from disaster recovery Jinny Chien April 20, th APGridPMA in Taipei.
CCRC’08 Monthly Update ~~~ WLCG Grid Deployment Board, 14 th May 2008 Are we having fun yet?
Operations Activity Doug Olson, LBNL Co-chair OSG Operations OSG Council Meeting 3 May 2005, Madison, WI.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
Sep 25, 20071/5 Grid Services Activities on Security Gabriele Garzoglio Grid Services Activities on Security Gabriele Garzoglio Computing Division, Fermilab.
OSG Report for DOE/NSF Joint Oversight Group U.S. Large Hadron Collider Program OSG Report for DOE/NSF Joint Oversight Group U.S. Large Hadron Collider.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and JSPG activities David Kelsey CCLRC/RAL.
Security EGEE/SA1 ROC Managers ARM-3 meeting Lyon, 17 March 2005 David Kelsey CCLRC/RAL, UK
OSG Area Coordinators Meeting Security Team Report Mine Altunay 02/13/2012.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
Security Policy Update WLCG GDB CERN, 8 Dec 2010 David Kelsey STFC/RAL david.kelsey AT stfc.ac.uk.
Open Science Grid OSG Resource and Service Validation and WLCG SAM Interoperability Rob Quick With Content from Arvind Gopu, James Casey, Ian Neilson,
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
LCG User, Site & VO Registration in EGEE/LCG Bob Cowles OSG Technical Meeting Dec 15-17, 2004 UCSD.
LCG Pilot Jobs + glexec John Gordon, STFC-RAL GDB 7 December 2007.
OSG Security: Updates on OSG CA & Federated Identities Mine Altunay, PhD OSG Security Team OSG AHM March 24, 2015.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
Open Science Grid Security Activities D. Olson, LBNL OSG Deputy Security Officer For the OSG Security Team: M. Altunay, FNAL, OSG Security Officer, D.O.,
OSG Area Coordinators Meeting Security Team Report Mine Altunay 8/15/2012.
Ruth Pordes, March 2010 OSG Update – GDB Mar 17 th 2010 Operations Services 1 Ramping up for resumption of data taking. Watching every ticket carefully.
OSG VO Security Policies and Requirements Mine Altunay OSG Security Team July 2007.
Grid Security Policy: EGEE to EGI David Kelsey (RAL) 16 Sep 2009 JSPG meeting, DFN Berlin david.kelsey at stfc.ac.uk.
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
Grid Colombia Workshop with OSG Week 2 Startup Rob Gardner University of Chicago October 26, 2009.
OSG PKI Transition: Status and Next Steps (and Lessons Learned) Von Welch OSG PKI Transition Lead Indiana University Center for Applied Cybersecurity Research.
OSG Security Review Mine Altunay March 12, Jan Security Overview Current Initiatives  OSG Security roadmap  Technical and operational.
Open Science Grid Progress and Status
Open Science Grid Consortium Meeting
LCG Security Status and Issues
David Kelsey STFC-RAL 2nd WISE workshop, XSEDE16, Miami 18 July 2016
Presentation transcript:

Open Science Grid Security Activities Mine Altunay, FNAL OSG Security Officer For the OSG Security Team: Doug Olson, Deputy Security Officer, LBNL, Jim Basney NCSA, Ron Cudzewicz FNAL, Grid Deployment Board July 9, 2008

OSG Security: Organization and Interfaces 2 07/09/2008 Altunay, OSG Security, GDB July, 2008 OSG Security Team Middle ware Security Group Joint Security Policy Group Intl Grid Trust Federation Partner Grids Incident Response Basney EUGridPMA Olson TAGPMA M. Altunay Wartel (EGEE-OSCT), Marsteller (TG), NDGF, … J.Basney Altunay co-chair with Witzig OSG VO and Site Security Contacts Altunay: VDT Security Officer WLCG Dave Kelsey WLCG Security Coordinator Altunay & Witzig VDT Security & OSG Operations & OSG Core Assets

Interfaces between OSG and WLCG Some questions:  Only through JSPG and MWSG ???  Should there be a separate direct arrow between OSG Security and WLCG  What about VDT Security Officer  Another direct arrow from VDT to WLCG? Any additions to the previous picture, any mistakes? 3 07/09/2008 Altunay, OSG Security, GDB July, 2008

Interfaces between OSG and JSPG New JSPG Mandate  JSPG reports to WLCG  Dave Kelsey -- also WLCG Security Coordinator  No WLCG Security Officer  OSG only gives feedback for the policies – no mandatory inclusion of JSPG policies  OSG ED is part of WLCG MB and relays OSG concerns at MB 4 07/09/2008 Altunay, OSG Security, GDB July, 2008

Recent WLCG Security Challenge USCMS received pretty poor scores  OSG is actively working on it  Held a meeting on 6/27 with USCMS  Discovered policy problems  Unawareness of WLCG incident response procedure  Policy enactment issues: lack of CMS security contacts at FNAL Going back to tie between OSG and WLCG  Should OSG Security be involved with next challenges?  Are we missing a link here? 5 07/09/2008 Altunay, OSG Security, GDB July, 2008

A Recent Incident at Atlas We had a security incident at AGLT2 (Atlas) Have not completed the post-mortem and no operational disruption Take-home messages: What we learned  Good test for Atlas security officers:  John Hover USAtlas Security Officer  Atlas Security Officer: Alessandro de Salvo (OSG did not have his contact before) Very important for VOs to identify Security Officers.  We worked with CMS (Marie-Christine Sawley)  Other VOs ? 6 07/09/2008 Altunay, OSG Security, GDB July, 2008

VO Policies & Security Duties Urged and educated VOs for their security policies and work at OSG Users meeting A VO must have  Security Officers: intl and local levels  Operations and Management contacts  local contacts (in USA) are registered with OSG  A clear user registration workflow – presented a sample policy template to OSG VOs  A clear AUP – presented a template to OSG VOs  5 VOs are preparing their policies: CMS, USAtlas, Edu, OSG VO, Engage  More VOs to come  Essential for Incident Response 7 07/09/2008 Altunay, OSG Security, GDB July, 2008