EGEE-II INFSO-RI-031688 Enabling Grids for E-sciencE www.eu-egee.org EGEE and gLite are registered trademarks EGEE and JSPG activities David Kelsey CCLRC/RAL.

Slides:



Advertisements
Similar presentations
Grid Security Policy GridPP18, Glasgow David Kelsey 21sr March 2007.
Advertisements

Grid Security Policy David Kelsey (RAL) 1 July 2009 UK HEP SYSMAN Security workshop david.kelsey at stfc.ac.uk.
GGF16, Athens AuthZ Interoperability Here and Now Workshop, 16 Feb 2006.
Grid Security Users, VOs, Sites OSG Collaboration Meeting University of Washington Bob Cowles August 23, 2006 Work supported.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
Joining the Grid Andrew McNab. 28 March 2006Andrew McNab – Joining the Grid Outline ● LCG – the grid you're joining ● Related projects ● Getting a certificate.
INFSO-RI Enabling Grids for E-sciencE Operational Security OSCT JSPG March 2006 Ian Neilson, CERN.
Grid Trust Fabric TNC 2006, Catania 16 May 2006 David Kelsey CCLRC/RAL, UK
EGEE ARM-2 – 5 Oct LCG Security Coordination Ian Neilson LCG Security Officer Grid Deployment Group CERN.
INFSO-RI Enabling Grids for E-sciencE SA1: Cookbook (DSA1.7) Ian Bird CERN 18 January 2006.
GGF12 – 20 Sept LCG Incident Response Ian Neilson LCG Security Officer Grid Deployment Group CERN.
LCG/EGEE Security Update HEPiX, Fall 2004 BNL, 18 October 2004 David Kelsey CCLRC/RAL, UK
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
JSPG: User-level Accounting Data Policy David Kelsey, CCLRC/RAL, UK LCG GDB Meeting, Rome, 5 April 2006.
INFSO-RI Enabling Grids for E-sciencE EGEE/LCG Joint Security Policy Group David Kelsey, CCLRC/RAL, UK EGEE.
Responsibilities of ROC and CIC in EGEE infrastructure A.Kryukov, SINP MSU, CIC Manager Yu.Lazin, IHEP, ROC Manager
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Ake Edlund EGEE Sec Head 9th MWSG meeting, SLAC,
Security Policy Update LCG GDB Prague, 4 Apr 2007 David Kelsey CCLRC/RAL
13-Jul-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint LCG/EGEE Security Group) CERN 13 July 2004 David Kelsey CCLRC/RAL,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
23-Oct-03D.P.Kelsey, LCG Security Update, HEPiX1 LCG Security Update HEPiX-HEPNT, TRIUMF, 23 October 2003 David Kelsey CCLRC/RAL, UK
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and OSG: Common Security Policies? OSG.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Next steps with EGEE EGEE training community.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks JSPG Status and plans EGEE’06 Conference.
INFSO-RI Enabling Grids for E-sciencE External Projects Integration Summary – Trigger for Open Discussion Fotis Karayannis, Joanne.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Linda Cornwall CCLRC (RAL) FP6 Security workshop.
LCG/EGEE Security Operations HEPiX, Fall 2004 BNL, 22 October 2004 David Kelsey CCLRC/RAL, UK
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
9-Oct-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) FNAL 9 October 2003 David Kelsey CCLRC/RAL, UK
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
INFSO-RI Enabling Grids for E-sciencE EGEE SA1 in EGEE-II – Overview Ian Bird IT Department CERN, Switzerland EGEE.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Dr Linda Cornwall CCLRC (RAL) FP6 Security workshop.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks ROC Security Contacts R. Rumler Lyon/Villeurbanne.
Security Operations David Kelsey GridPP Deployment Board 3 Mar 2005
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
INFSO-RI Enabling Grids for E-sciencE An overview of EGEE operations & support procedures Jules Wolfrat SARA.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
June 6, 2006OSG - Draft VO AUP1 Open Science Grid Trust as a Foundation June 6, 2006 Keith Chadwick.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
INFSO-RI Enabling Grids for E-sciencE The EGEE Project Owen Appleton EGEE Dissemination Officer CERN, Switzerland Danish Grid Forum.
Security EGEE/SA1 ROC Managers ARM-3 meeting Lyon, 17 March 2005 David Kelsey CCLRC/RAL, UK
EGEE ARM-2 – 5 Oct LCG/EGEE Security Coordination Ian Neilson Grid Deployment Group CERN.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
12-Jun-03D.P.Kelsey, CA meeting1 CA meeting Minimum Requirements CERN, 12 June 2003 David Kelsey CCLRC/RAL, UK
18-May-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) Barcelona 18 May 2004 David Kelsey CCLRC/RAL, UK
SEE-GRID The SEE-GRID initiative is co-funded by the European Commission under the FP6 Research Infrastructures contract no SEE-GRID.
Security Policy Update WLCG GDB CERN, 8 Dec 2010 David Kelsey STFC/RAL david.kelsey AT stfc.ac.uk.
Planning for LCG Emergencies HEPiX, Fall 2005 SLAC, 13 October 2005 David Kelsey CCLRC/RAL, UK
Last update 13/03/ :11 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD Status of the Task Force for User Registration of LHC Experiment Users
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
7-May-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Issues and Planning or Report from the Security Group CERN, 8 May 2003 David Kelsey CCLRC/RAL, UK.
LCG User, Site & VO Registration in EGEE/LCG Bob Cowles OSG Technical Meeting Dec 15-17, 2004 UCSD.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE Operations: Evolution of the Role of.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
Security Bob Cowles
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Ake Edlund for JRA3 EGEE EU Review (CERN) May 23-24, 2006.
Grid Security Policy: EGEE to EGI David Kelsey (RAL) 16 Sep 2009 JSPG meeting, DFN Berlin david.kelsey at stfc.ac.uk.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
Security Policy Update WLCG GDB CERN, 11 June 2008 David Kelsey STFC/RAL
Bob Jones EGEE Technical Director
David Kelsey CCLRC/RAL, UK
Open Science Grid Consortium Meeting
LCG Security Status and Issues
David Kelsey CCLRC/RAL, UK
Ian Bird GDB Meeting CERN 9 September 2003
David Kelsey CCLRC/RAL, UK
Presentation transcript:

EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and JSPG activities David Kelsey CCLRC/RAL

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 2 Overview Joint Security Policy Group The set of Security Policy documents LCG, WLCG, EGEE – who is who? Recent & current work Operational Security Coordination Team Some recent security issues More general issues

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 3 History LCG Security Group was created in early 2003 Mandate To advise and make recommendations to the Grid Deployment Manager and LCG GDB on all matters related to Security –Policies are agreed and adopted by GDB for LCG To produce and maintain –Policies and procedures on Registration, Authentication, Authorization and Security Where necessary recommend the creation of focussed task-forces made-up of appropriate experts –E.g. Task force on LCG User Registration

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 4 JSPG Following first EGEE collaboration meeting, scope of group extended –To include a proposed EGEE SA1 Site Security Group Joint Security Policy Group (JSPG) –“Joint” initially means EGEE and LCG –Strong participation by USA Open Science Grid –Now “Joint” = EGEE/OSG/WLCG An activity of EGEE SA1 –Discusses all documents with ROC Managers –Participation of site managers/security officers Strong links to EGEE Middleware Security Group (and JRA1) New “task force” (added after EGEE-2 meeting) –SA1 Operational Security Coordination Team (OSCT)  See later

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 5 JSPG membership Application representatives/VO managers –Discussions with VO managers as/when required Site Security Officers –Bob Cowles (SLAC), Denise Heagerty (CERN), & in the past - Dane Skow (FNAL) Site/Resource Managers/Security Contacts –Dave Kelsey (RAL) – Chair –Miguel Cardenas Montes (Spain) Security middleware experts/developers –Joni Hahkala (JRA3), David Groep (JRA3), Andrew McNab (GridPP), Yuri Demchenko (JRA3) CERN Deployment team –Maria Dimou, Ian Neilson (Security Officer) Now expanding to include other EU Grid projects –SEE-Grid, DEISA, Diligent Other EU Infrastructure projects use our policies –BalticGrid, EELA, EUMedGrid, EUChinaGrid

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 6 JSPG Meetings, Web etc Meetings - Agenda, presentations, minutes etc JSPG Web site Membership of the JSPG mail list is closed, BUT –Requests to join stating reasons to D Kelsey –Volunteers to work with us are always welcome! Policy documents at

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 7 EGEE/LCG Policy Security & Availability Policy Site & VO Registration Certification Authorities Audit Requirements Incident Response User Registration & VO Management Application Development & Network Admin Guide picture from Ian Neilson Grid & VO AUPs

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 8 LCG, WLCG and EGEE? Has been lots of confusion! LCG = “LHC Computing Grid” project WLCG = The “worldwide” collaboration doing this The four LHC VO’s are global in scale –ALICE, ATLAS, CMS, LHCb experiments –Use resources from both EGEE and OSG Sites join either EGEE or OSG –The operational infrastructures BUT… –There is an LCG Grid Deployment Board  All EGEE and OSG countries represented –And a WLCG Management Board –In addition to all the EGEE management groups JSPG reports to both LCG GDB and EGEE ROC Mgrs

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 9 Recent/Current JSPG work Recently approved –Grid AUP –VO Security Policy (requires a VO AUP) All other documents need updating (this year) Current work –Top-level Security Policy document –CA approval (use IGTF accredited) –VO Naming (use DNS style) –User-level Accounting data policy (privacy issues) A User Registration task force has worked on –VO Registration for the LHC experiments (VOMS) –VOMRS from FNAL (run at CERN) –Links to Experiment/HR databases at CERN

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 10 Grid AUP (1) By registering with the Virtual Organization (the "VO") as a GRID user you shall be deemed to accept these conditions of use: 1. You shall only use the GRID to perform work, or transmit or store data consistent with the stated goals and policies of the VO of which you are a member and in compliance with these conditions of use. 2. You shall not use the GRID for any unlawful purpose and not (attempt to) breach or circumvent any GRID administrative or security controls. You shall respect copyright and confidentiality agreements and protect your GRID credentials (e.g. private keys, passwords), sensitive data and files. 3. You shall immediately report any known or suspected security breach or misuse of the GRID or GRID credentials to the incident reporting locations specified by the VO and to the relevant credential issuing authorities.

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 11 Grid AUP (2) 4. Use of the GRID is at your own risk. There is no guarantee that the GRID will be available at any time or that it will suit any purpose. 5. Logged information, including information provided by you for registration purposes, shall be used for administrative, operational, accounting, monitoring and security purposes only. This information may be disclosed to other organizations anywhere in the world for these purposes. Although efforts are made to maintain confidentiality, no guarantees are given. 6. The Resource Providers, the VOs and the GRID operators are entitled to regulate and terminate access for administrative, operational and security purposes and you shall immediately comply with their instructions. 7. You are liable for the consequences of any violation by you of these conditions of use.

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 12 Example VO AUP This acceptable Use Policy applies to all members of Virtual Organization, hereafter referred to as the VO, with reference to use of the LCG/EGEE Grid infrastructure, hereafter referred to as the Grid. The Geant4-Spokesman, owns and gives authority to this policy. The goal of the VO is to validate the software they provide to their users (HEP experiments as ATLAS, CMS, LHCb, Babar, etc, Astrophysics applications, biomedical communities) twice per year within the Grid environment. This procedure should cover a wide range of parameters and physical models which are high CPU demanding. At the same time they are planning to use regularly the LCG/EGEE resources to make analysis and studies of their toolkit. Members and Managers of the VO agree to be bound by the Grid Acceptable Use Policy, VO Security Policy and other relevant Grid Policies, and to use the Grid only in the furtherance of the stated of the VO.

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 13 OSCT Operational Security Coordination Team –Members:  Security Coordinators from each ROC  Chaired by Security Officer in SCG (Ian Neilson) –Roles:  Members coordinate security Grid at sites within Regions Handling of Security tickets Security contact management  Coordination of Grid Incident Handling Process Incident Handling and Response Guide from JSPG Cooperation with peer Grids  Execution of Security Service Challenges SSC1 – job audit (completed March 2006) SSC2 – data management audit planned –Meetings:  First face to face meeting planned 21 June slides from Ian Neilson

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 14 OSCT

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 15 Recent Security issues Proxy lifetime policy Requirements for Grid PMA’s –User full name in DN –But other statements required  (OSG has written such a document) Audit requirements (discussed here yesterday) Data privacy issues (accounting, auditing etc) –EU Data Privacy directives VOMRS policy –read access to registration, group/role membership data

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 16 More general issues There is work (EGEE TCG sub-group) on “Job priorities” using VOMS roles/groups –Proposing how VO can centrally control Job priorities Federation issues –Linking in to more general AAI’s –Shibboleth and Grid integration  EGEE (Switch) working on gLite/Shib GGF Security Interoperability –AuthN via IGTF –GIN (Grid Interoperability Now) activity –TONIC for AuthZ – will this take off? Need to review the Security Risk Analysis Have looked at Emergency Procedures for LCG ops –Needs more work

Enabling Grids for E-sciencE EGEE-II INFSO-RI EGEE & JSPG - D Kelsey 17 Some advice from the EU review Would like to see strong management commitment –Including resource allocation! Security technology is good –would be happy if a normal medium sized enterprise would have this in place More important issues are operational and human related factors –Should implement awareness and training programs for all project members and customers The EU ISSeG project is working in this area –