Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL

Slides:



Advertisements
Similar presentations
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks MyProxy and EGEE Ludek Matyska and Daniel.
Advertisements

Grid Security Policy GridPP18, Glasgow David Kelsey 21sr March 2007.
5-Dec-02D.P.Kelsey, GridPP Security1 GridPP Security UK Security Workshop 5-6 Dec 2002, NeSC David Kelsey CLRC/RAL, UK
Grid Security Policy David Kelsey (RAL) 1 July 2009 UK HEP SYSMAN Security workshop david.kelsey at stfc.ac.uk.
GGF16, Athens AuthZ Interoperability Here and Now Workshop, 16 Feb 2006.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Authorization WG Update David Kelsey EU Grid PMA, Copenhagen 27 May 2008.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
30-Jan-03D.P.Kelsey, GridPP Security1 Security GridPP6 30 Jan 2003 Coseners House David Kelsey CLRC/RAL, UK
Authentication Policy David Kelsey CCLRC/RAL 15 April 2004, Dublin
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group Summary EGI TF David Kelsey 6/28/
WLCG Security TEG, risks and Identity Management David Kelsey GridPP28, Manchester 18 Apr 2012.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group EGI Technical Forum Sep 2010 David Kelsey.
CILogon OSG CA Mine Altunay Jim Basney TAGPMA Meeting Pittsburgh May 27, 2015.
12-May-03D.P.Kelsey, SCG Online Authentication1 Online Authentication SCG Meeting EDG Barcelona, 12 May 2003 David Kelsey CCLRC/RAL, UK
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
JSPG: User-level Accounting Data Policy David Kelsey, CCLRC/RAL, UK LCG GDB Meeting, Rome, 5 April 2006.
TERENA TF-EMC2 Workshop David Groep,
Evolution of the Open Science Grid Authentication Model Kevin Hill Fermilab OSG Security Team.
Updates from the EUGridPMA David Groep, July 16 st, 2007.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay OSG Security Officer.
Responsibilities of ROC and CIC in EGEE infrastructure A.Kryukov, SINP MSU, CIC Manager Yu.Lazin, IHEP, ROC Manager
Security Policy Update LCG GDB Prague, 4 Apr 2007 David Kelsey CCLRC/RAL
13-Jul-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint LCG/EGEE Security Group) CERN 13 July 2004 David Kelsey CCLRC/RAL,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
9-Sep-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 9 September 2003 David Kelsey CCLRC/RAL, UK
23-Oct-03D.P.Kelsey, LCG Security Update, HEPiX1 LCG Security Update HEPiX-HEPNT, TRIUMF, 23 October 2003 David Kelsey CCLRC/RAL, UK
8-Jul-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) RAL, 8 July 2003 David Kelsey CCLRC/RAL, UK
3-Jul-02D.P.Kelsey, Security1 Security meetings Report to EDG PTB 3 Jul 2002 David Kelsey CLRC/RAL, UK
FP6−2004−Infrastructures−6-SSA E-infrastructure shared between Europe and Latin America EELA Infrastructure (WP2) Roberto Barbera.
LCG Pilot Jobs + glexec John Gordon, STFC-RAL GDB 7 November 2007.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Linda Cornwall CCLRC (RAL) FP6 Security workshop.
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
9-Oct-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) FNAL 9 October 2003 David Kelsey CCLRC/RAL, UK
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
Security Operations David Kelsey GridPP Deployment Board 3 Mar 2005
2-Sep-02D.P.Kelsey, WP6 CA, Budapest1 WP6 CA report Budapest 2 Sep 2002 David Kelsey CLRC/RAL, UK
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI SPG future work EGI Technical Forum Lyon, 21 Sep 2011 David Kelsey, STFC/RAL.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and JSPG activities David Kelsey CCLRC/RAL.
Security EGEE/SA1 ROC Managers ARM-3 meeting Lyon, 17 March 2005 David Kelsey CCLRC/RAL, UK
8-Mar-01D.P.Kelsey, Certificates, WP6, Amsterdam1 WP6: Certificates for DataGrid Testbeds David Kelsey CLRC/RAL, UK
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
12-Jun-03D.P.Kelsey, CA meeting1 CA meeting Minimum Requirements CERN, 12 June 2003 David Kelsey CCLRC/RAL, UK
18-May-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) Barcelona 18 May 2004 David Kelsey CCLRC/RAL, UK
Security Policy Update WLCG GDB CERN, 8 Dec 2010 David Kelsey STFC/RAL david.kelsey AT stfc.ac.uk.
Why a Commercial Provider should Join the Academic Cloud Federation David Blundell Managing Director 100 Percent IT Ltd Simple, Flexible, Reliable.
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
TACAR Updates version David Groep, NIKHEF. 9 th EUGridPMA ‘RAL’ meeting – Jan David Groep – TACAR Aims  Trusted and.
7-May-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Issues and Planning or Report from the Security Group CERN, 8 May 2003 David Kelsey CCLRC/RAL, UK.
LCG User, Site & VO Registration in EGEE/LCG Bob Cowles OSG Technical Meeting Dec 15-17, 2004 UCSD.
LCG Pilot Jobs + glexec John Gordon, STFC-RAL GDB 7 December 2007.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI VOMS Proxy Lifetime UCB 21 Aug 2012 David Kelsey STFC.
Grid Security Policy: EGEE to EGI David Kelsey (RAL) 16 Sep 2009 JSPG meeting, DFN Berlin david.kelsey at stfc.ac.uk.
News from EUGridPMA EGI OMB, 22 Jan 2013 David Kelsey (STFC) Using notes from David Groep 22/01/20131EUGridPMA News.
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
Security Policy Update WLCG GDB CERN, 11 June 2008 David Kelsey STFC/RAL
David Kelsey CCLRC/RAL, UK
David Kelsey CCLRC/RAL, UK
Ian Bird GDB Meeting CERN 9 September 2003
David Kelsey CCLRC/RAL, UK
Update - Security Policies
Presentation transcript:

Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL

Overview JSPG meeting (Jan 08) New mandate for JSPG Policy Management for Grid Authorization JSPG Future plans 14 May 20082JSPG - D Kelsey

14 May 2008JSPG - D Kelsey3 JSPG meeting JSPG meeting was held at CERN –28/29 Jan 2008 –One day workshop cancelled Bob Cowles (OSG/SLAC) leaves JSPG clash with OSG/EGEE and EGI_DS meetings –Less progress than hoped! Policy documents (almost) ready for formal approval –VO Operations Policy –Pilot Jobs Policy –Traceability and Logging Policy –CA Approval (new IGTF profiles)

JSPG mandate For EGEE-III as move towards EGI/NGIs OSG requested clarity wrt their membership New mandate (main points) –Jointly owned by/recommends to WLCG & EGEE –Policy for WLCG designed to be applied to all of its Grid infrastructures in so far as this relates to WLCG activities i.e. OSG, NDGF and other national Grids and/or individual Grid sites which participate in WLCG –May also provide advice on any security matter –Aim for simple/general policies that are useable by NGIs –JSPG does not formally approve policies but recommends to management bodies Plans for next two years –Need to revitalise membership (More ROCs, NGIs and VOs) New OSG member is Jim Basney –Review all policy documents to make even more simple/general 14 May 20084JSPG - D Kelsey

Policy Management for Grid Authorization 14 May 20085JSPG - D Kelsey

AuthZ WG - Introduction Authorization is as (more?) important as (than) Authentication –Gives access to resources! In world of national academic federations –AuthZ and Identity attributes are rather similar Many Grid VOs are global (e.g. LHC!) –or at least span two or more Grids –impossible for one Grid to set the standards JSPG agreed some time ago –We need “minimum requirements” for running VOMS –CAs very well controlled, not so for VOMS The minimum requirements are similar to an IGTF AuthN profile No other large group of experts is out there waiting to take this on! A global trust problem International Grid Trust Federation – good name for AuthZ too –Don’t want to create a separate IGTF for AuthZ EU Grid PMA has created a working group on this topic –DPK chairs 14 May 2008JSPG - D Kelsey6

AuthZ WG mandate and aims To prepare recommendations on policy and global trust issues related to Grid Authorisation (AuthZ) The initial list of issues will include –Minimum requirements and best practice for the operation of a Grid AuthZ attribute authority –Minimum requirements and best practice for Virtual Organisation user and service membership management –Accreditation of Attribute Authorities (AA) –Accreditation of Virtual Organisations and their membership management procedures 14 May 2008JSPG - D Kelsey7

Mandate (2) –Repositories and distribution of accredited AA and VO roots of trust –Technical details of attribute signing and trust validation To recommend how IGTF could handle the definition of AuthZ policy and related accreditation during the next 3 to 5 years, taking into account the move towards a sustainable EU Grid Infrastructure and constituent national Grids Aim is to tackle the scaling problem of VOs establishing trust with many Grids and hundreds of Sites 14 May 2008JSPG - D Kelsey8

Min Requirements for Attribute Authories User/service registration and renewal procedures –Vetting of rights and identity –Assignment of groups and roles Operational Requirements for running an AA service Repository of AA roots of trust –And distribution mechanisms Note –Unlike CA’s the person/site running the AA service is not (in general) the same as the VO management responsible for attribute assignment 14 May 2008JSPG - D Kelsey9

Attribute signing and trust validation IGTF has concerns about the current VOMS practice –Host or Service certificate Neither is appropriate Where is the root of trust? –It currently appears to be the CA –Special AA certificates could be issued –How is trust validation performed? OSG just written paper on AC validation WG will propose a solution 14 May 2008JSPG - D Kelsey10

Accreditation of AAs and VOs How will accreditation be done? –By existing PMA’s Far too many VOs so does not scale –IGTF defines the standards and others do the accreditation Grid infrastructures (EGEE, OSG)? National Grids? Each VO could have a “home Grid” WG will propose an approach 14 May 2008JSPG - D Kelsey11

14 May 2008JSPG - D Kelsey12 Future JSPG plans Next face to face JSPG meeting –29/30 May at CERN Agenda will include –Update old VO security policy documents VO Security Policy User registration and VO membership requirements –Finalise user-level accounting –Look again at Grid Portal policy –Plan for next two years VOLUNTEERS VERY WELCOME!

14 May 2008JSPG - D Kelsey13 JSPG Meetings, Web etc Meetings - Agenda, presentations, minutes etc JSPG Web site Membership of the JSPG mail list is closed, BUT –Requests to join stating reasons to D Kelsey –Volunteers to work with us are always welcome! Policy documents at security/documents.html