JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.

Slides:



Advertisements
Similar presentations
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks MyProxy and EGEE Ludek Matyska and Daniel.
Advertisements

Grid Security Policy GridPP18, Glasgow David Kelsey 21sr March 2007.
Grid Security Policy David Kelsey (RAL) 1 July 2009 UK HEP SYSMAN Security workshop david.kelsey at stfc.ac.uk.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI AAI in EGI Status and Evolution Peter Solagna Senior Operations Manager
Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
Authorization WG Update David Kelsey EU Grid PMA, Copenhagen 27 May 2008.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
INFSO-RI Enabling Grids for E-sciencE JRA3 2 nd EU Review Input David Groep NIKHEF.
Security Issues in Physics Grid Computing Ian Stokes-Rees OeSC Security Working Group 14 June 2005.
\ Grid Security and Authentication1. David Groep Physics Data Processing group Nikhef.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group Summary EGI TF David Kelsey 6/28/
Portals and Credentials David Groep Physics Data Processing group NIKHEF.
Trust and Security for FIM (Sirtfi/SCI) David Kelsey (STFC-RAL) FIM4R at CERN 4 Feb 2015.
The EPIKH Project (Exchange Programme to advance e-Infrastructure Know-How) Grid Engine Riccardo Rotondo
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group EGI Technical Forum Sep 2010 David Kelsey.
Federated Identity Management for HEP David Kelsey WLCG GDB 9 May 2012.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
JSPG: User-level Accounting Data Policy David Kelsey, CCLRC/RAL, UK LCG GDB Meeting, Rome, 5 April 2006.
INFSO-RI Enabling Grids for E-sciencE EGEE/LCG Joint Security Policy Group David Kelsey, CCLRC/RAL, UK EGEE.
Responsibilities of ROC and CIC in EGEE infrastructure A.Kryukov, SINP MSU, CIC Manager Yu.Lazin, IHEP, ROC Manager
Security Policy Update LCG GDB Prague, 4 Apr 2007 David Kelsey CCLRC/RAL
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
8-Jul-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) RAL, 8 July 2003 David Kelsey CCLRC/RAL, UK
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks JSPG Status and plans EGEE’06 Conference.
Pilot Jobs John Gordon Management Board 23/10/2007.
LCG Pilot Jobs + glexec John Gordon, STFC-RAL GDB 7 November 2007.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Linda Cornwall CCLRC (RAL) FP6 Security workshop.
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
9-Oct-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) FNAL 9 October 2003 David Kelsey CCLRC/RAL, UK
National Computational Science National Center for Supercomputing Applications National Computational Science GSI Online Credential Retrieval Requirements.
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Dr Linda Cornwall CCLRC (RAL) FP6 Security workshop.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
Authentication and Authorisation for Research and Collaboration Peter Solagna Milano, AARC General meeting Current status and plans.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
Security Operations David Kelsey GridPP Deployment Board 3 Mar 2005
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) WLCG GDB, CERN 10 Jul 2013.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
EGI-InSPIRE RI EGI EGI-InSPIRE RI Service Operations Security Policy the new generalised site operations security policy.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI SPG future work EGI Technical Forum Lyon, 21 Sep 2011 David Kelsey, STFC/RAL.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
WLCG Authentication & Authorisation LHCOPN/LHCONE Rome, 29 April 2014 David Kelsey STFC/RAL.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and JSPG activities David Kelsey CCLRC/RAL.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
12-Jun-03D.P.Kelsey, CA meeting1 CA meeting Minimum Requirements CERN, 12 June 2003 David Kelsey CCLRC/RAL, UK
Security Policy Update WLCG GDB CERN, 8 Dec 2010 David Kelsey STFC/RAL david.kelsey AT stfc.ac.uk.
Why a Commercial Provider should Join the Academic Cloud Federation David Blundell Managing Director 100 Percent IT Ltd Simple, Flexible, Reliable.
Grid Security Update David Kelsey (RAL) HEPiX, LBNL 28 Oct 2009.
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
7-May-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Issues and Planning or Report from the Security Group CERN, 8 May 2003 David Kelsey CCLRC/RAL, UK.
LCG User, Site & VO Registration in EGEE/LCG Bob Cowles OSG Technical Meeting Dec 15-17, 2004 UCSD.
LCG Pilot Jobs + glexec John Gordon, STFC-RAL GDB 7 December 2007.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI CSIRT Procedure for Compromised Certificates and Central Security Emergency.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI VOMS Proxy Lifetime UCB 21 Aug 2012 David Kelsey STFC.
EGI-InSPIRE RI SPG Tasks for Year 2011 Jan 2011 Kelsey/Security Policy Group1.
Security Bob Cowles
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Questionnaires to Cloud technology providers and sites Linda Cornwall, STFC,
CERN IT Department CH-1211 Geneva 23 Switzerland t OIS Operating Systems & Information Services CERN IT Department CH-1211 Geneva 23 Switzerland.
Grid Security Policy: EGEE to EGI David Kelsey (RAL) 16 Sep 2009 JSPG meeting, DFN Berlin david.kelsey at stfc.ac.uk.
News from EUGridPMA EGI OMB, 22 Jan 2013 David Kelsey (STFC) Using notes from David Groep 22/01/20131EUGridPMA News.
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
Security Policy Update WLCG GDB CERN, 11 June 2008 David Kelsey STFC/RAL
Open Science Grid Consortium Meeting
LCG Security Status and Issues
David Kelsey CCLRC/RAL, UK
Grid Security M. Jouvin / C. Loomis (LAL-Orsay)
Grid Engine Riccardo Rotondo
Grid Engine Diego Scardaci (INFN – Catania)
Presentation transcript:

JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009

31 Mar 09Kelsey, MWSG Zurich2 JSPG Joint Security Policy Group Prepares and maintains security policy –For EGEE –For WLCG Policies approved and adopted by Grid management Aim for general common policies useable by many Grids (OSG, NDGF, DEISA, Other EU Grids,…) –OSG has played key role here, e.g. Grid AUP Tackle scaling problems of large numbers of sites, and large number of VOs –Single policy applies to VO (at ALL sites)

Aims of Policy Written documents agreed to by all participants (in some cases “signed”) –Users, VOs, Sites, Operations, Security,… This policy gives authority for actions which may be carried out by certain individuals and bodies and places responsibilities on all participants. 31 Mar 09Kelsey, MWSG Zurich3

Interoperability User registers (once) with his/her VO –Must accept Grid AUP Sites willing to delegate registration to VO knowing that VO procedures must follow same VO policy –And that User will have accepted AUP Aim for simple, general and interoperable policies of use to many Grids Common policies –To allow VOs to easily use resources in multiple Grids as move to EGI, for example 31 Mar 09Kelsey, MWSG Zurich4

Security Policy Site & VO Policies Certification Authorities Traceability and Logging Security Incident Response Accounting Data Privacy Pilot Jobs and VO Portals Grid & VO AUPs 5Kelsey JSPG

2008 approved policies 4 approved policies –EGEE TMB meetings in Aug/Sep 2008 Approval of Certification Authorities Traceability and Logging VO Operations Multi User Pilot Jobs 6Kelsey JSPG

Current work 31 Mar 09Kelsey, MWSG Zurich7

Two draft VO Policies Virtual Organisation Registration Security Policy –Version 2.3, 22 Jan 2009 Virtual Organisation Membership Management Policy –Version 3.4, 22 Jan 2009 Clear responsibilities on VO managers –Sites delegate user registration to the VOs procedures must be of appropriate quality –E.g. VO managers must assist in incident response. 11 Mar 2009JSPG - D Kelsey8

User Level Job Accounting Grid Policy on the Handling of User-Level Job Accounting Data (Draft Policy) V0.7, 23 Jan Level_Job_Accounting_Data This document presents the minimum requirements and policy framework for the handling of user-level accounting data created, stored, transmitted, processed and analysed as a result of the execution of jobs on the Grid. 11 Mar 2009JSPG - D Kelsey9

VO Portal Policy New (draft) policy document –Based on Dutch BiG Grid policy –Ideas from the EGEE working group on portals V3.0, 23 Jan Mar 2009JSPG - D Kelsey10

Portals Policy applies to all Portals operated by Virtual Organisations that participate in the Grid infrastructure Defines 4 classes of web portals and 4 classes of User Some general policy plus class dependent statements Addresses private key protection and requires use of Robot certificates in some cases Robot: a software agent performing automatic functions on behalf of real person Robot certificate: Issued to a Robot with private key generated and stored on a secure hardware token (at least FIPS 140-1/2 level 2) 11 Mar 2009JSPG - D Kelsey11

Portal users Four classes of portal users: Anonymous –No unique credentials provided Pseudonymous –Human providing authenticated but non-identifying information to the Portal Identified –Authenticated personal information but not compatible or equivalent to Grid AuthN Strongly Identified –Portal can authenticate to Grid resources with valid Grid credentials belonging to the user 11 Mar 2009JSPG - D Kelsey12

Portal Classes 11 Mar 2009JSPG - D Kelsey13 Portal ClassExecutableParametersInput Simple one click Provided by portal ParameterProvided by portal Choose from limited set Choose from repository vetted by portal Data processing Provided by portal Choose from limited set Provided by user Job management Provided by user

Portal – General policy All portals must comply with VO Operations Policy VO, Portal and Portal manager all held responsible and accountable –Except where user is Strongly Indentified Must –Keep audit logs –Manager/operators must assist in incident response –Be capable of rate limiting job submissions Private keys (proxy or otherwise) –Must not be transferred across network (even if encrypted) –Must not store private keys on behalf of users if these can be used for Grid AuthN after > 1M seconds Data can only be stored in locations agreed between Portal and Resources and only as long as user is associated with portal If user Grid credential used then data may be stored anywhere user has permission 11 Mar 2009JSPG - D Kelsey14

Class specific portal policy See document The more tightly controlled the executable, input and parameters –The fewer requirements there are on quality of user identity management 31 Mar 09Kelsey, MWSG Zurich15

11 Mar 2009JSPG - D Kelsey16 Future JSPG plans Next face to face JSPG meeting is 14/15 May 2009 at CERN Complete Accounting and VO portals policies Revise the Grid User AUP –Some Grids use but have modified our text –Explore why and standardise where possible DEISA, TeraGrid, Australia, EU infrastructures, national Grids, … Revise security incident response policy Revise whole policy set (yet) again in next 12 months –More simple, general and consistent –More applicable to EGI world –Broaden the membership – include more NGIs and other Grids

11 Mar 2009JSPG - D Kelsey17 JSPG Meetings, Web etc Meetings - Agenda, presentations, minutes etc JSPG Web sites and Membership of the JSPG mail list is closed, BUT –Volunteers to work with us are always welcome! Policy documents at andhttp:// security/documents.html