Presentation is loading. Please wait.

Presentation is loading. Please wait.

10-May-01D.P.Kelsey, WP6 Security1 Certificates/Authorisation for DataGrid Testbeds David Kelsey CLRC/RAL, UK

Similar presentations


Presentation on theme: "10-May-01D.P.Kelsey, WP6 Security1 Certificates/Authorisation for DataGrid Testbeds David Kelsey CLRC/RAL, UK"— Presentation transcript:

1 10-May-01D.P.Kelsey, WP6 Security1 Certificates/Authorisation for DataGrid Testbeds David Kelsey CLRC/RAL, UK d.p.kelsey@rl.ac.uk

2 10-May-01D.P.Kelsey, WP6 Security2 Members of WP6 CA group Luca dell AgnelloINFN, Italy Roberto AlfieriINFN, Italy Jean-Luc ArchimbaudCNRS, France Roberto CecchiniINFN, Italy Jorge GomesLIP, Portugal David GroepNIKHEF, NL Denise HeagertyCERN Dave Kelsey(Chair)RAL, UK Daniel KourilCesnet, Czech Rep. Rafael MarcoSpain Pietro Paolo MartucciCERN Andrew SansumRAL, UK Others joining soon

3 10-May-01D.P.Kelsey, WP6 Security3 Meetings 4/5 December 2000, CERN 2 March 2001, CERN Next meeting: 5 June 2001, CERN

4 10-May-01D.P.Kelsey, WP6 Security4 CA status National CA already in operation for DataGrid Testbed0 –CERN –Czech Republic –France –Italy –Netherlands –Nordic –Portugal –Spain –UK Not on WP6 web yet (Czech Republic, Spain, Nordic) Sites not represented?

5 10-May-01D.P.Kelsey, WP6 Security5 Certificates for users/hosts All testbed users should obtain a certificate from their own national CA. Same for host certificates See WP6 web page –http://marianne.in2p3.fr Countries not yet running a CA –Implement one or –Find an existing CA willing to issue certificates Globus certificates are still OK for Testbed0 but should be avoided if possible –Will be removed in Testbed 1 (M9)

6 10-May-01D.P.Kelsey, WP6 Security6 User accounts for Testbed0 Certificates from national CA Requests for “GRID” accounts via WP managers –For definite need only –WP manager gives list to WP6 –WP6 will arrange for accounts on Testbed0 sites And entry in grid mapfile –groups in testbed0? (WP number?) This does not scale! –We need to plan for for M9/Testbed 1 –Longer term – different approach

7 10-May-01D.P.Kelsey, WP6 Security7 Acceptable use policy? Do we need an acceptable use policy or other document? – Can show to management to convince them that they should allow an unknown set of people to run programs on computers at a testbed site? Who are the users? Why should they use a testbed site? Do we envisage trusting someone who defines the list of people we will allow to run jobs, access data etc? Will such lists be signed etc?

8 10-May-01D.P.Kelsey, WP6 Security8 Configuration of systems See WP6 web Needs to be part of the standard distribution –To configure complete list of trusted CA’s –To configure the certificate request mechanism –To update CRL’s Local site is free to accept trusted CA’s or not. –We will check CPS of each CA to define “trust”

9 10-May-01D.P.Kelsey, WP6 Security9 Authorisation CAS from Globus –May not be ready/tested for testbed1 –So plan on not using it Authorisation via Grid mapfile –gid, uid UNIX security mechanisms –INFN LDAP tool for group membership –Andrew McNab patch for leasing generic accounts –Need input from WP8-10 for group structure


Download ppt "10-May-01D.P.Kelsey, WP6 Security1 Certificates/Authorisation for DataGrid Testbeds David Kelsey CLRC/RAL, UK"

Similar presentations


Ads by Google