EMI Storage meets EMI security

Similar documents
GSI with OpenSSL. Vincenzo Ciaschini. Prague, 4-7/11/08. EGEE and glite are registered trademarks. egee EGEE-II INFSO-RI

QA Metrics Nightly Report

EMI Security Architecture

dcache, list of topics

dcache, a managed storage in grid

Vorgangsname M30 M30 M14 M20

The EDGeS project receives Community research funding

Globus Toolkit: Authentication and Credential Translation

Software Infrastructure Supplement for the OSG Proposal

A. Sim, CRD, L B N L 1

dcache, Software for Big Data

Data management in EGEE

Certificates in a Nutshell. Jens Jensen, STFC Leader of EUDAT AAI TF

Patrick Fuhrmann. The DESY Storage Cloud

Analisi di un servizio SRM: StoRM

IGI Portal architecture and interaction with a CA- online

Plateforme de Calcul pour les Sciences du Vivant. SRB & glite. V. Breton.

Bringing Federated Identity to Grid Computing. Dave Dykstra CISRC16 April 6, 2016

globus online Integrating with Globus Online Steve Tuecke Computation Institute University of Chicago and Argonne National Laboratory

Authorization Strategies for Virtualized Environments in Grid Computing Systems

Forschungszentrum Karlsruhe in der Helmholtz-Gemeinschaft. dcache Introduction

The glite File Transfer Service

EUROPEAN MIDDLEWARE INITIATIVE

2 Transport-level and Message-level Security

BeStMan-gateway Installation and Configuration for OSG Tier-2, Tier-3 sites

Processing big data by WS- PGRADE/gUSE and Data Avenue

GridSite 1.5.x update

Grid Engine. The EPIKH Project (Exchange Programme to advance e-infrastructure Know-How)

Esqu Science Experiments For Computer Network

GRIP:Creating Interoperability between Grids

Roadmap for Applying Hadoop Distributed File System in Scientific Grid Computing

The ENEA gateway approach providing EGEE/gLite access to unsupported platforms and operating systems

GridSite security update

Federated access to Grid resources

The DESY Big-Data Cloud System

Single Sign-on to the Grid

LIGO Identity Management: Questions I Wish We Would Have Asked

IVOA Single Sign-On security

Data Grid Storage Systems - An Analysis of Security

Direct Issuance of Proxy Certificate on P-GRADE Grid Portal Without Using MyProxy

The Big-Data Cloud. Patrick Fuhrmann. On behave of the project team. The BIG DATA Cloud 8 th dcache Workshop, DESY Patrick Fuhrmann 15 May

Single Sign-On: Reviewing the Field

Grid Data Management. Raj Kettimuthu

dcache Firewall Issue

HADOOP, a newly emerged Java-based software framework, Hadoop Distributed File System for the Grid

Retirement of glite3.1 and unsupported glite 3.2

File transfer in UNICORE State of the art

Managed GRID or why NFSv4.1 is not enough. Tigran Mkrtchyan for dcache Team

OIS. CERN s Experience with Federated Single Sign-On. Operating Systems & Information Services IT-OIS. June 9-10, 2011

SAP NetWeaver Single Sign-On. Product Management SAP NetWeaver Identity Management & Security June 2011

Federated Identity & Access Mgmt for Higher Education

A Survey Study on Monitoring Service for Grid

File Transfer Software and Service SC3

IT/CZ cluster meeting, Milano, September 23 24, CESNET Report. Aleš Křenek et al.

CERN local High Availability solutions and experiences. Thorsten Kleinwort CERN IT/FIO WLCG Tier 2 workshop CERN

Adoption of a SAML-XACML Profile for Authorization Interoperability across Grid Middleware in OSG and EGEE

The dcache Storage Element

Secure Federated Light-weight Web Portals for FusionGrid

Interoperability in Grid Computing

Crawl Proxy Installation and Configuration Guide

Recommendations for Static Firewall Configuration in D-Grid

Managing Credentials with

Angel Dichev RIG, SAP Labs

Storage Resource Managers: Recent International Experience on Requirements and Multiple Co-Operating Implementations

Three Case Studies InCommon Certificate Service

The DESY Big-Data Cloud Service

FermiGrid Highly Available Grid Services

dcache - Managed Storage - LCG Storage Element - HSM optimizer Patrick Fuhrmann, DESY for the dcache Team

The GISELA Science Gateway

Resume. Wenjing. Date of birth: June 11th, 1982 Nationality: Chinese Phone number: Cell phone:

Policy on ARCS eresearch Services Firewall Configuration Requests

Grid Security : Authentication and Authorization

Grid Computing: A Ten Years Look Back. María S. Pérez Facultad de Informática Universidad Politécnica de Madrid mperez@fi.upm.es

GRID COMPUTING Techniques and Applications BARRY WILKINSON

Open Source Identity Integration with OpenSSO

The Role of Federation in Identity Management

Security in OSG. Tuesday afternoon, 3:15pm. Igor Sfiligoi Member of the OSG Security team University of California San Diego

Management. Purdue University. CHEP Mar 2009, Prague, Czech Republic

XSEDE Service Provider Software and Services Baseline. September 24, 2015 Version 1.2

Using Globus Toolkit

CNR-INFM DEMOCRITOS and SISSA elab Trieste

Concepts and Architecture of the Grid. Summary of Grid 2, Chapter 4

Michael Thomas, Dorian Kcira California Institute of Technology. CMS Offline & Computing Week

Using the MyProxy Online Credential Repository

Australian Synchrotron, Storage Gateway

Grid Delegation Protocol

An approach to grid scheduling by using Condor-G Matchmaking mechanism

External Authentication with WebCT. What We ll Discuss

High Performance Computing Infrastructure in Japan

glibrary: Digital Asset Management System for the Grid

Gratia: New Challenges in Grid Accounting.

LHC schedule: what does it imply for SRM deployment? CERN, July 2007

TIBCO Spotfire Platform IT Brief

Mass Storage at GridKa

Measurement of BeStMan Scalability

Mid-Project Report August 14 th, Nils Dussart

GridFTP: A Data Transfer Protocol for the Grid

A Test Infrastructure for Inspecting the Availability of fgrid Resources

Program Grid and HPC5+ workshop

LIGO Authentication and Authorization 2.0

Transcription:

EMI Storage meets EMI security Component/ Middleware glite (LFC,FTS,DPM,GFAL) ARC UNICORE StoRM dcache Staff With kind contributions by Oliver Keeble, Jean- Philippe Baud Jon Kerr Nilsen Ralph Müller- Pfefferkorn Riccardo Zappi, Michele DibenedeOo Patrick Fuhrmann, Tigran Mkrtchyan Alex Sim (BeStMan, OSG)

Disclaimer No serious investigations yet. So many questions so little time.

Topics Motivation Possible Showstoppers, Open issues Migration Goal Identity Management Single Sign-on Call-outs to Authentication/Authorization services

Motivation Will be a big/expensive effort -> Good Justification First discussion on this (in storage) started 2 years ago in the context of the SRM (DESY SRM workshop) (How) would we profit from a GSI replacement? Well maintained security libraries (e.g. fast security bug fixes) Session re-use. Would clients benefit (FTS)? Avoid generating delegated proxies if not needed. Relevant services SRM How about gsiftp? Should we use FTPS(implicit/explicit) or https? Would fixing GSI give us similar benefits w/o too much hassle?

Certificates and Proxies with GSI CA CA Certificate Signed BY User Certificate Client EXT FQAN User Proxy VOMS server Server Delegated Proxy

Open questions, if we would move to SSL Proxies (voms-proxy-init) Would we use RFC compliant proxies only? Are proxies (certificates not signed by a CA) accepted by SSL libraries? Do SSL libraries make extensions available at the server side (FQAN)? Is this true for non CC/C++ frameworks (java, python?)

Open questions, if we would move to SSL Delegation Proxies Do we need delegation (FTS, SRM-copy, myproxy)? How can we achieve delegation w/o GSI? Common interface or common service? GridSiteDelegation(https://twiki.cern.ch/twiki/bin/view/EGEE/GridSiteDelegation) Globus MyProxy Delegation (http://grid.ncsa.illinois.edu/myproxy/delegation) They don t inter-operate Are there any other options?

Migration Does migration has to be globally coordinated, or can this be smoothly. Europe vers. US : VDT, BeStMan Can GSI and non GSI services be run at the same time (different addr.)? What would be the implications for e.g. catalogues? Are there any other implications e.g. order of FQANs in proxy?

GOAL X509 over https would be desirable for WLCG Other Certificate bases communities Other/Easier approaches for other communities (see next section) OSG/Alex would be very interested Who do we find out (EGI/NGI customers)

Identity Management Single Sign-On Single Sign-on mechanisms X509 Kerberos OpenID Shibboleth US : DOE Entrust, HSPD-12 (Govt) UNICORE using SAML-Assertion Do we have any experience with non X509 E.g. : OSG using OpenID for one community Do we have any policy/services for mapping between X509 and others.

Identity Management Identity services How important are central identity services for SE s? GUMS and SCAS moving away from SAML and XACML Migration should be completed this year. (2010) SAML/XACML : Only partially supported by EMI SE s ARGUS What are the benefits. We need to investigate : speed and other technical issues.