Middleware Security Group Meeting
Berkeley
-
-
09:00
→
12:35
Session 1: General security topics
-
09:00
Welcome, discussion of Agenda 15mSpeaker: Chairs (Bob C., C.Witzig)
- 09:15
- 09:30
- 09:45
-
10:15
break 30m
- 10:45
-
11:15
End-to-end security 30mGoal of the presentation: We want to draw attention to the problems the current trust model poses; i.e. the fact that all the middleware needs to be trusted. We will present our current view on how this could be changed, so that only the end points, i.e. the user and the execution machine, need to be trusted. We will have a proposal for a prototype implementation, and we would like to have a discussion with the other middleware developers.Speakers: Ian Aldermann, Igor Sfilioi
-
11:45
Email break 30m
-
09:00
-
12:15
→
13:30
lunch break
-
13:30
→
17:30
Session 2: Authorization
Goals of the Authorization sessions:
-
For end-to-end study:
a) Presentation of ideas based on end-to-end authorization study for EGEE-III
b) Input of OSG to these ideas
c) Identification of possible problems -
For authZ interoperability:
a) reviewing all fundamental areas of the work (even the ones settled and not discussed in several months) and reassuring ourselves that we are still on the same page everywhere
b) discuss the scope and release schedule for the development work in OpenSAML 2. The goal is gathering enough information to update our plans. After the MWSG, we will need to carefully evaluate if these changes of scope and schedule make the joint project still cost effective.
c) discuss communication channels w/ new development team and its management; discuss expectations for participation, response time, quality, etc.
d) agree on the draft profile to be distributed by Chad on Nov 30 (note: this will be done in a smaller group in a parallel session on Thu morning and Fri afternoon)
- 13:30
-
15:00
break 30m
- 15:30
- 15:50
- 16:10
- 16:30
-
16:50
AuthZ Interop: Discussion 40mSpeaker: all
-
-
09:00
→
12:35
-
-
09:00
→
13:15
Session 3: Authorization continued
- 09:00
- 09:30
-
10:15
break 30m
- 10:45
- 11:45
-
12:15
→
13:30
lunch break
-
13:30
→
16:00
Session 4: General security topics
-
13:30
CO-Manage and GridGrouper (cont) 30mSpeaker: Tom Barton
- 14:00
-
14:15
Security of VO schedulers 15mLarge VOs are deploying their own schedulers which interact directly with Worker Nodes. This raises the question whether these schedulers should be considered as part of the core middleware. The goal of this presentation is to find out whether the MWSG should investigate the security implications of VO specific schedulers. If so, how should the group proceed? There was a long discussion of how to control connections between the worker nodes and the Internet. Christoph asked for reactions to some standardization of a sort of proxy facility that schedulers would go through to fetch jobs. Oscar dug up his slides from 2004 were he had proposed a facility for controlling connections to the Internet. Those slides are attached.Speaker: Christoph Witzig
-
14:30
Proxy lifetime restrictions 30mSpeaker: Mine Altunay
-
15:00
Update on Security Token Service (STS) 15mSpeaker: Chad La Joie
-
15:15
Discussion, AOB 15m
-
13:30
-
09:00
→
13:15