Www.egi.eu EGI-InSPIRE RI-261323 EGI www.egi.eu EGI-InSPIRE RI-261323 Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.

Slides:



Advertisements
Similar presentations
Usage of PGP in TACAR 19th OGF Meeting Chapel Hill, USA February 1, 2007 Licia Florio Project Development Officer
Advertisements

EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI GGUS user authentication Tiziana Ferrari/EGI.eu Peter Solagna/EGI.eu
David Groep Nikhef Amsterdam PDP & Grid Evolving Assurance – IGTF LoA generalisation David Groep Interoperable Global Trust Federation IGTF Documents at.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI - Identity Management Steven Newhouse Director, EGI.eu Federated Identity.
Authorization WG Update David Kelsey EU Grid PMA, Copenhagen 27 May 2008.
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
NRENs supporting Grids using current Grid technology TERENA NREN-GRID Workshop Amsterdam Milan Sova CESNET.
Authentication Policy David Kelsey CCLRC/RAL 15 April 2004, Dublin
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Policy Issues for Identity Management (and other attributes) EGI Technical.
David Groep EUGridPMA The International Grid Trust Federation enabling an interoperable global trust fabric also supported by EGI.eu EGI-InSPIRE RI ,
The EU Grid PMA David Kelsey CCLRC/RAL 16 April 2004, Dublin
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014 and now abbreviated.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group EGI Technical Forum Sep 2010 David Kelsey.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
LiveAP Towards Differentiated Identity Assurance David Groep, Nikhef supported by the Netherlands e-Infrastructure SURFsara, and EGI.eu O-E-15 and EGI-InSPIRE.
Security Update WLCG GDB CERN, 12 June 2013 David Kelsey STFC/RAL.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
TERENA TF-EMC2 Workshop David Groep,
EGI-InSPIRE RI EGI (IGTF Liaison Function) EGI-InSPIRE RI Towards Differentiated Identity Assurance as a collaborative.
Updates from the EUGridPMA David Groep, July 16 st, 2007.
EGEE is proposed as a project funded by the European Union under contract IST EU eInfrastructure project initiatives FP6-EGEE Fabrizio Gagliardi.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay OSG Security Officer.
AAI WG EMI Christoph Witzig on behalf of EMI AAI WG.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
White paper overview 2 nd eIRG meeting April, 16 th 2004 Fotis Karayannis, Editor GRNET - Greek Research & Technology Network
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
ESnet RAF and eduroam ™ Tony J. Genovese ATF Team ESnet/Lawrence Berkeley National Laboratory.
INFSO-RI Enabling Grids for E-sciencE External Projects Integration Summary – Trigger for Open Discussion Fotis Karayannis, Joanne.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks SA1: Grid Operations Maite Barroso (CERN)
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
Identity Management in DEISA/PRACE Vincent RIBAILLIER, Federated Identity Workshop, CERN, June 9 th, 2011.
IOTA AP Towards Differentiated Identity Assurance David Groep, Nikhef supported by the Netherlands e-Infrastructure and SURFsara.
Updates from the EUGridPMA David Groep, May 9 st, 2007.
NRENs, Grids and Integrated AAI In Search For the Utopian Solution Christos Kanellopoulos AUTH/GRNET October 17 th, 2005 skanct at physics.auth.gr 2nd.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
INFSO-RI Enabling Grids for E-sciencE An overview of EGEE operations & support procedures Jules Wolfrat SARA.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
WLCG Laura Perini1 EGI Operation Scenarios Introduction to panel discussion.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
EGI-InSPIRE RI EGI EGI-InSPIRE RI Service Operations Security Policy the new generalised site operations security policy.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI SPG future work EGI Technical Forum Lyon, 21 Sep 2011 David Kelsey, STFC/RAL.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
EGEE is a project funded by the European Union CA overview and requirements Ognjen Prnjat, Nikos Vogiatzis GRNET EGEE-SEE regional kick-off, April 7-8.
EGI-InSPIRE RI EGI (IGTF Liaison Function) EGI-InSPIRE RI IGTF EUGridPMA status update SHA-2, OCSP, and more David.
Why a Commercial Provider should Join the Academic Cloud Federation David Blundell Managing Director 100 Percent IT Ltd Simple, Flexible, Reliable.
TACAR Updates version David Groep, NIKHEF. 9 th EUGridPMA ‘RAL’ meeting – Jan David Groep – TACAR Aims  Trusted and.
David Groep Nikhef Amsterdam PDP & Grid Bring the WLCG federation Home Extending your trust options beyond bottom-up identity by collaborating with global.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Plans for PY2 Steven Newhouse Project Director, EGI.eu 30/05/2011 Future.
European Grid Initiative AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI UMD Roadmap Steven Newhouse 14/09/2010.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
Summary of Poznan EUGridPMA32 September EUGridPMA Poznan 2014 meeting – 2 David Groep – Welcome back at PSNC.
Security Bob Cowles
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Enabling SSO capabilities in the EGI Cloud services Peter Solagna – EGI.eu.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Ake Edlund for JRA3 EGEE EU Review (CERN) May 23-24, 2006.
Grid Security Policy: EGEE to EGI David Kelsey (RAL) 16 Sep 2009 JSPG meeting, DFN Berlin david.kelsey at stfc.ac.uk.
EGI-InSPIRE RI EGI (IGTF Liaison Function) EGI-InSPIRE RI IGTF & EUGridPMA status update SHA-2 – and more (David Groep,
IGTF in 10 years enabling the interoperable global trust federation Nikhef, Amsterdam supported the Dutch national e-Infrastructure funded and coordinated.
Bob Jones EGEE Technical Director
Open Science Grid Consortium Meeting
LCG Security Status and Issues
HellasGrid CA & euGridPMA
The IGTF Charter Name uniqueness throughout the IGTF is anchored in the Charter Current Charter assigns a namespace to an Authority, implying that the.
Supporting communities with harmonized policy
EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.
David Kelsey (STFC-RAL)
AAI in EGI Status and Evolution
Presentation transcript:

EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA David Groep, FOM-Nikhef and NL-NGI for EGI global task O-E-15 This work is supported by EGI-InSPIRE under NA2

EGI-InSPIRE RI Roles of authentication EUGridPMA and IGTF – international grid trust federation – are about authentication, i.e. establishing identity. Why do you need to establish identity? Access control to resources and services Incident management and auditing Accounting, auditing, &c… Here we focus on authenticating individuals natural persons, hosts, services, software agents Establishing identity in EGI2

EGI-InSPIRE RI Access Control Points Establishing identity in EGI3 Authentication each person globally unique name only identification persons may have more than ID Authorization based on the unique AuthN ID grants or denies access several control points - VO must be member of community only work within common AUP - site has list of VOs + ban list

EGI-InSPIRE RI Coordinating identity: the trust fabric Guaranteed uniqueness, authenticity, compliance with technical requirements for identity needs coordination –these guidelines constitute a (technical) policy –the group responsible for setting and verifying these is thus a Policy Management Authority (‘PMA’) needs to work across many grids (across NGIs, EGI, OSG, LCG, DEISA/PRACE, TeraGrid,...) –user communities span multiple infrastructures –so the coordination needs to be global as well Establishing identity in EGI4

EGI-InSPIRE RI The EUGridPMA The European Policy Management Authority for Grid Authentication in e-Science (EUGridPMA) is a body to establish requirements and best practices for grid identity providers to enable a common trust domain applicable to authentication of end-entities in inter-organisational access to distributed resources. The EUGridPMA itself does not provide identity assertions, but instead asserts that - within the scope of its charter – the assertions issued by the Accredited Authorities meet or exceed the relevant guidelines Establishing identity in EGI5

EGI-InSPIRE RI EUGridPMA organisation Established April 1 st 2004 by founding members –national identity authorities from the EU DataGrid and CrossGrid CA Coordination Group –EGEE, DEISA, SEE-GRID, TERENA as relying parties Today 46 members –5 cross-national relying parties (EGI,DEISA,OSG,TERENA,wLCG) –41 identity authorities (“CAs”) Establishing identity in EGI6

EGI-InSPIRE RI EUGridPMA Activities Establishing Authentication Guidelines –technical policies defining minimum requirements that authorities must meet or exceed –matches the level of assurance (LoA) needed for the authorization decisions by the relying parties (resource centres, data owners,...) Reviewing compliance of new authorities with respect to these guidelines Periodic peer-reviewed re-assessments Provide technical source of ‘trust anchors’ for accredited authorities –categorised by LoA, verification via TERENA TACAR Establishing identity in EGI7

EGI-InSPIRE RI Global coordination International Grid Trust Federation – IGTF Three ‘regionals’ EUGridPMA, APGridPMA, TAGPMA Strongly coordinated: accrediting to common standards Establishing identity in EGI8

EGI-InSPIRE RI Implementing the Acceptable CAs EGI policy on Approved Authorities all IGTF Authorities compliant with defined assurance level Grid participants in EGI are supposed to install all approved trust anchors –in as far as allowed by site, organisational, national policies –site, organisational, national policy takes precedence –report deviations to the EGI Security Officer as per the general Grid Security Policy Grid participants may install other trust anchors –e.g. authorities for site or national training purposes –local authorities or local translators (e.g. SARoNGS) Establishing identity in EGI9

EGI-InSPIRE RI EGI ‘CA distribution’ EGI policy supported by technical infrastructure: the ‘ca-policy-egi-core’ package –provided as a convenience service for sites/NGIs –originated in EUDataGrid/LCG/EGEE as ‘lcg-CA’ –collection of trust anchor certificate files & metadata –a re-distribution of the IGTF trust anchors –packaged as RedHat Package Manager (RPM) –provided, for as long as needed by the NGIs, via support (0.05FTE) by EGI-InSPIRE under SA1 –but several sites and NGIs already build their own Establishing identity in EGI10

EGI-InSPIRE RI Both adding trust anchors locally and sub-setting trust anchors is compliant with standing EGI policy today –when sub-setting: report to security officer, since it leads to unmanaged exceptions in infra operations –breaks intra- and inter-grid interoperability – so both site and its users have to deal with consequences Effect of sub-setting trust anchors may not be what you would expect, due to –jointness policy requirements for multi-grid affiliates –constituencies & scopes of identity providers in the IGTF and underlying academic federations Trust & AuthN implications 11 2/17/2016 Establishing identity in EGI

EGI-InSPIRE RI Authentication –basis for granting and denying access by VOs and resource centres –does not grant any access rights in or by itself –allows incident response & auditing of ‘undesired access attempts’ EUGridPMA and IGTF provide –a global authentication trust fabric across infrastructures, –according to scoped technical security policies, –based on many autonomous authentication authorities Standing EGI security policies leverage the IGTF –acknowledges site and national policy primacy –and sub-setting the endorsed set unlikely to have the expected effect Summary 12 2/17/2016 Establishing identity in EGI

EGI-InSPIRE RI EGI EGI-InSPIRE RI Discussion 2/17/ Establishing identity in EGI