Last update 21/01/2016 08:05 LCG 1Maria Dimou- cern-it-gd Current LCG User Registration, VO management and Authorisation Procedures VOMS workshop 2003-12-15.

Slides:



Advertisements
Similar presentations
29 June 2006 GridSite Andrew McNabwww.gridsite.org VOMS and VOs Andrew McNab University of Manchester.
Advertisements

Last update 01/06/ :23 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD Site Registration policy & procedures
Web Hosting. The purpose of this Startup Guide is to familiarize you with Own Web Now's Web Hosting. Own Web Now offers two web hosting platforms, one.
RTÉ eCommissioning A Guide to the Supplier Registration Process.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
Summer School Certificates Diego Romano & Gilda Team.
Copyright B. Wilkinson, This material is the property of Professor Barry Wilkinson (UNC-Charlotte) and is for the sole and exclusive use of the students.
Joining the Grid Andrew McNab. 28 March 2006Andrew McNab – Joining the Grid Outline ● LCG – the grid you're joining ● Related projects ● Getting a certificate.
NAMS Account Activation Training. 2 What is NAMS? The NASA Account Management System is NASA’s centralized process for requesting and maintaining accounts.
Getting started on informaworld™ How do I register my institution with informaworld™? How is my institution’s online access activated? What do I do if.
GFP in the IUID Registry – A Basic Look Walt Clark, CPPM Raytheon IIS.
The EPIKH Project (Exchange Programme to advance e-Infrastructure Know-How) VOMS Installation and configuration Bouchra
CILogon OSG CA Mine Altunay Jim Basney TAGPMA Meeting Pittsburgh May 27, 2015.
Plan My Move & MilitaryINSTALLATIONS May, 2008 Relocation Personnel Roles and Responsibilities MC&FP.
VOX Project Status T. Levshina. Talk Overview VOX Status –Registration –Globus callouts/Plug-ins –LRAS –SAZ Collaboration with VOMS EDG team Preparation.
VOMS Alessandra Forti HEP Sysman meeting April 2005.
10-Jun-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 10 June 2003 David Kelsey CCLRC/RAL, UK
13-Jul-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint LCG/EGEE Security Group) CERN 13 July 2004 David Kelsey CCLRC/RAL,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
Maarten Litmaath (CERN), GDB meeting, CERN, 2006/02/08 VOMS deployment Extent of VOMS usage in LCG-2 –Node types gLite 3.0 Issues Conclusions.
23-Oct-03D.P.Kelsey, LCG Security Update, HEPiX1 LCG Security Update HEPiX-HEPNT, TRIUMF, 23 October 2003 David Kelsey CCLRC/RAL, UK
8-Jul-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) RAL, 8 July 2003 David Kelsey CCLRC/RAL, UK
3-Jul-02D.P.Kelsey, Security1 Security meetings Report to EDG PTB 3 Jul 2002 David Kelsey CLRC/RAL, UK
WP3 Authorization and R-GMA Linda Cornwall WP3 workshop 2-4 April 2003.
GGUS at PEB – –- page 1 LCG Klaus-Peter Mickel, GridKa Karlsruhe LCG-PEB-Meeting ( ) The Global Grid User Support Model (Report of GDB.
INFSO-RI Enabling Grids for E-sciencE LCAS/LCMAPS and WSS Site Access Control boundary conditions David Groep NIKHEF.
Next Steps: becoming users of the NGS Mike Mineter
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
MEMBERSHIP AND IDENTITY Active server pages (ASP.NET) 1 Chapter-4.
Grid Security Vulnerability Group Linda Cornwall, GDB, CERN 7 th September 2005
VO management: Progress since Chicago Workshop Vincenzo Ciaschini 23/5/2002 CNAF – Bologna.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Partner Ready Portal: New Partner Registration Process
Page 1 of 42 To the ETS – Create Client Account & Maintenance Online Training Course Individual accounts (called a Client Account) are subsets of the Site.
Last update 29/01/ :01 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD CERN VOMS server deployment LCG Grid Deployment Board
Last update 31/01/ :41 LCG 1 Maria Dimou Procedures for introducing new Virtual Organisations to EGEE NA4 Open Meeting Catania.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
Primenumbers.co.uk This presentation will help you get the most out of this service.
1Maria Dimou- cern-it-gd LCG GDB May 2008 USAG and direct GGUS ticket routing to Sites Grid Deployment.
1Maria Dimou- cern-it-gd LCG November 2007 GDB October 2007 VOM(R)S Workshop report Grid Deployment Board.
Last update 22/02/ :54 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD VO Registration procedure Presented by.
Last update 29/02/ :31 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD VOMS status IT GD Group Meeting
VOX Project Tanya Levshina. 05/17/2004 VOX Project2 Presentation overview Introduction VOX Project VOMRS Concepts Roles Registration flow EDG VOMS Open.
The GRIDS Center, part of the NSF Middleware Initiative Grid Security Overview presented by Von Welch National Center for Supercomputing.
VOX Project Status T. Levshina. 5/7/2003LCG SEC meetings2 Goals, team and collaborators Purpose: To facilitate the remote participation of US based physicists.
Last update 13/03/ :11 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD Status of the Task Force for User Registration of LHC Experiment Users
Stephen Burke – Sysman meeting - 22/4/2002 Partner Logo The Testbed – A User View Stephen Burke, PPARC/RAL.
EGEE is a project funded by the European Union under contract IST New VO Integration Fabio Hernandez ROC Managers Workshop,
1Maria Dimou- cern-it-gd LCG End of the Task Force for VO User Registration of LHC Experiment Users Grid Deployment.
Collecting Copyright Transfers and Disclosures via Editorial Manager™ -- Editorial Office Guide 2015.
Gilda certificates. Certification Authority
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
Registration StratusLab Tutorial (Orsay, France) 28 November 2012.
EGEE is a project funded by the European Union under contract INFSO-RI DGAS Grid accounting L.Gaido on behalf of A.Guarise LCG Workshop November.
Virtual Organisations and the NGS Mike Jones Research Computing Services e-Science & “The Grid” for Bio/Health Informaticians, IT January 2008.
For help or more information, please contact the P&W SRM team at ;
Progress Project Tracking for EGEE Kasia Pokorska, CERN IT-AIS-PM
Welcome! To the ETS – Create Client Account & Maintenance
David Kelsey CCLRC/RAL, UK
StudentTranscripts Service Overview
CRC exercises Not happy with the way the document for testbed architecture is progressing More a collection of contributions from the mware groups rather.
Update on EDG Security (VOMS)
StudentTranscripts Service Overview
StudentTranscripts Service Overview
StudentTranscripts Service Overview
Grid Security M. Jouvin / C. Loomis (LAL-Orsay)
StudentTranscripts Service Overview
StudentTranscripts Service Overview
StudentTranscripts Service Overview
Presentation transcript:

last update 21/01/ :05 LCG 1Maria Dimou- cern-it-gd Current LCG User Registration, VO management and Authorisation Procedures VOMS workshop

last update 21/01/ :05 LCG 2Maria Dimou- cern-it-gd What “getting on LCG” means As explained in the User Introductory page the basic steps are:User Introductory page  authentication (by means of a personal digital certificate), authentication  registration, registration  authorisation to use LCG resources (via a limited-in-time proxy) and authorisation  job submission job submission

last update 21/01/ :05 LCG 3Maria Dimou- cern-it-gd LCG Registration procedure today Read the LCG Usage Rules. If you agree to adhere to these rules, then proceed to:LCG Usage Rules 1.Obtain a valid digital certificate from your CA.Obtain 2.Load your certificate onto your browser.Load 3.Fill the LCG Registration FormLCG Registration Form In this form you will:  Choose the VO you are affiliated with.  Confirm your adherence to the LCG Usage Rules = Guidelines.

last update 21/01/ :05 LCG 4Maria Dimou- cern-it-gd Complete registration Additional information on that web form:  Family Name  Given Name  Institute  Address  Telephone Number The Address is mandatory as it is used to check the authenticity of the request, by automatically ing back a URL for the user to open, which launches the completion of the registering process.

last update 21/01/ :05 LCG 5Maria Dimou- cern-it-gd What happens behind the scenes  Successful registrations are added in an LDAP directory for the Guidelines and a separate LDAP directory for the VO.  The Guidelines’ LDAP and the DTEAM VO LDAP are physically at CERN, the experiments’ VOs are on an LDAP server at NIKHEF.  The addition of the user in the Guidelines’ LDAP is automatic and ends by an request to the relevant VO manager to include the user in the VO.

last update 21/01/ :05 LCG 6Maria Dimou- cern-it-gd New VO member  The VO manager checks with the Institute (security?) contacts whether the user should be accepted and whether his/her data are correct.  (S)he uses a set of EDG scripts and/or the LDAP commands and browser to add the new member to the VO. (Procedure)Procedure  (S)he notifies the user and all site contacts about the admission of a new member in the VO (continue?) A set of mailing lists facilitates communication between sites and VO managers.A set of mailing lists

last update 21/01/ :05 LCG 7Maria Dimou- cern-it-gd Finally “on the Grid” Once the user is as a valid LDAP entry in a given VO (s)he will automatically appear in the grid-map file a few hours later, e.g.: "/C=CH/O=CERN/OU=GRID/CN=Maria Dimou 7577".dteam The user should be present in, both, the Guidelines’ and the VO LDAP as checked by the /opt/edg/etc/ edg-mkgridmap.conf # LCG Standard Virtual Organizations group ldap://grid-vo.nikhef.nl/ou=lcg1,o=alice,dc=eu-datagrid,dc=org.alice group ldap://grid-vo.nikhef.nl/ou=lcg1,o=atlas,dc=eu-datagrid,dc=org.atlas group ldap://grid-vo.nikhef.nl/ou=lcg1,o=cms,dc=eu-datagrid,dc=org.cms group ldap://grid-vo.nikhef.nl/ou=lcg1,o=lhcb,dc=eu-datagrid,dc=org.lhcb group ldap://lcg-vo.cern.ch/ou=lcg1,o=dteam,dc=lcg,dc=org.dteam #### AUTH: authorization URI auth ldap://lcg-registrar.cern.ch/ou=users,o=registrar,dc=lcg,dc=org

last update 21/01/ :05 LCG 8Maria Dimou- cern-it-gd Why would anyone wish to change this procedure?  Unfriendly mass-updates via the ldap[add|search|delete] commands or the LDAP browser.  Can’t handle CN name clashes within a given VO.  Currently the LCG User Registration procedure allows a user to become a member of only one VO at a time.LCG User Registration  There is no mechanism to tell the local resources what this user is authorised to do with(out) priviledges.

last update 21/01/ :05 LCG 9Maria Dimou- cern-it-gd The VOMS alternative pending issues (I) The user registration information is not yet decided. DN,CN,CA,CA URI, ,Groups and Roles are the only fields foreseen so far in VOMS. Today, (ldap) lcg-registrar contains the Institute and the PhoneNumber in addition. The GDB decided which are the mandatory fieldsGDB decided for LCG user registration.

last update 21/01/ :05 LCG 10Maria Dimou- cern-it-gd The VOMS alternative pending issues (II)  The procedure ensuring a user's compliance to the Guidelines before acceptance in the VO is not yet clear. The LCG security group discussed the issue on but postponed the discussion to this Workshop. Who/when will take the decision?  The VOMS (web) interface for users to submit requests to the VO administrators is not yet available.

last update 21/01/ :05 LCG 11Maria Dimou- cern-it-gd Conclusions for registration  The present procedure doesn’t scale and doesn’t cover the needs of service from the Authorisation point of view, i.e. we need the VOMS Groups/Roles’ values.  The issue of separate (or not) Guidelines/VO database(s) must be decided (in this workshop?)  The minimum mandatory amount of information as decided by the GDB must be available on all user registration tools (VOMS, VOX, …).

last update 21/01/ :05 LCG 12Maria Dimou- cern-it-gd Hint for the authorisation slot VOMS' enhanced functionality in terms of fine-grain categorisation of users in Groups and Roles cannot be exploited as long as we keep the grid-map file, where we have no indication to which Unix group(s) the user’s job must belong. It would be a pity to only use VOMS for its better administration interface because of unclear mechanisms to extract, match and exploit VOMS and LCMAPS information.