EMI Security Workshop

Europe/Zurich
CERN

CERN

Description

The EMI Security Workshop will take place on

25th May 14:00 to 18:00: Building 32, 1st Floor, Room A24 (32-1-A24) and

26th May 9:00 to 12:00: Building 31, 3rd Floor, Room 004 (31-3-04) .

 

We are pleased to announce, in conjunction with the EMI Kick-off meeting, the Security Workshop on 25/26th May.
 
We hope to have representatives from each of ARC, gLite and UNICORE present to be able to comment on these subjects and provide an authorized position in order to make the first decisions in the Security task.
 
This workshop is the first milestone of the EMI JRA1 and will cover the following subjects (from the EMI Description of Work):
 
- The removal of GSI for replacement by SSL/TLS. For this subject it will be necessary to confirm and tabulate the components that are still dependent on GSI and which will benefit from this standardization. This includes non-security components.
 
For the removal of GSI for replacement by SSL/TLS we will need input (presentations) from VOMS, Data management and delegation (for job management), also the exposure and plans of relevant ARC components.
 
- Common authentication libraries. At this stage we should be able to project whether the common library should be X.509 only or include SAML support. The use-cases within each stack must be presented.
 
Here we need input from a representative of each middleware stack.
 
- The usage of the SAML-enabled VOMS service within ARC/gLite must be understood and a medium-term plan for possible replacement or coexistence of attribute certificates with SAML made.
 
Related to the above topic. Presentations from VOMS, job management (gLite and ARC) and the projected standard Authorization system, Argus.
 
- A review of the Authorization decision mechanisms of all job management systems. A plan for any necessary integration with the common libraries and security tokens made.
 
Presentations from gLite WMS, CE(s) (gLite and ARC))
 
 The results of the security workshop will be presented and taken into account in the first deliverable document, Security Area Work Plan and Status Report. This document will present the status of the security infrastructures and components, the integration plan and a work plan for the first year of the project as requested in the Evaluation Report.
 
 
Related Information:
* How to reach CERN
* CERN Hostel offers basic rooms with shower and WC on the CERN campus. Please make sure you book early, as these rooms are often fully booked. Should the CERN Hostel ask for contact person at CERN, please indicate Yasemin Hauser.
* Hotels in the local area
* A dinner is organised on 27 May at Auberge Communale de Satigny. For registration, go to the EMI Kick-off Meeting event page.

CERN is closed on Monday 24th May. Contact
project-eu-emi-po@cern.ch if you need a CERN pass for the 24th, or other information.
 


 

<o:p></o:p>


 


 

 
 

Participants
  • Aleksandr Konstantinov
  • Andrea Ceccanti
  • Cecchi Marco
  • Christoph Witzig
  • Daniel Kouril
  • John White White
  • Krzysztof Benedyczak
  • Linda Cornwall
  • Mattias Ellert
  • Miika Tuisku
  • Oliver Keeble
  • Oscar Koeroo
  • Paolo Andreetto
  • Ricardo Rocha
  • sara bertocco
  • Vincenzo Ciaschini
  • Zsolt Molnár
    • 14:00 14:20
      Welcome and Objectives 20m 32/1-A24

      32/1-A24

      CERN

      40
      Show room on map
      Speaker: Dr Alberto Di Meglio (CERN)
      Slides
    • 14:20 15:50
      GSI in EMI 32/1-A24

      32/1-A24

      CERN

      40
      Show room on map

      An overall goal in the EMI stack is to remove proprietary technology
      where possible for replacement by standard components. In particular this session
      focuses on the removal of GSI for replacement by SSL/TLS.

      Each presenter should indicate the usage of GSI in their overall middleware stack or set of components and outline a plan for removal or reasons why removal is not feasible or beneficial.

      • 14:20
        GSI Status in VOMS 20m
        Speaker: Dr Vincenzo Ciaschini (INFN CNAF)
        Slides
      • 14:40
        GSI Usage in Data Management 20m
        Speakers: Patrick Fuhrmann (Unknown), Dr Patrick Fuhrmann (DESY)
        Slides
      • 15:00
        Delegation and Proxy-Renewal 20m
        Speaker: Daniel Kouril (Unknown)
        Slides
      • 15:20
        GSI in ARC 20m
        Speaker: Mr Aleksandr Konstantinov (VILNIUS UNIVERSITY)
        Slides
    • 15:50 16:10
      Coffee 20m
    • 16:10 17:30
      SAML usage in EMI 32/1-A24

      32/1-A24

      CERN

      40
      Show room on map

      A medium-term plan for possible replacement or coexistence of attribute certificates with SAML should be made. The current SAML usage capabilities and experience/needs
      should be outlined.

      • 16:10
        Status of VOMS-SAML 20m
        Speaker: Andrea Ceccanti (Unknown)
        Slides
      • 16:30
        SAML and ARC 20m
        Speaker: Mr Aleksandr Konstantinov (VILNIUS UNIVERSITY)
        Slides
      • 16:50
        SAML and UNICORE 20m
        Speaker: Mr Krzysztof Benedyczak
        Slides
      • 17:10
        SAML and Argus 20m
        Speakers: Andrea Ceccanti (Unknown), Andrea Ceccanti (Unknown)
        Slides
    • 09:00 10:20
      Common EMI authentication libraries. 32/1-A24

      32/1-A24

      CERN

      40
      Show room on map

      A common set of EMI authentication libraries. At this stage we should be able to
      project whether the common library should be X.509 only or include SAML
      support. The use-cases within each MW stack will be presented.

      • 09:00
        Common AuthN in gLite 15m
        Speaker: Dr Vincenzo Ciaschini (INFN CNAF)
        Slides
      • 09:15
        ARC 15m
        Postponed to next session.
        Speaker: Mr Aleksandr Konstantinov (VILNIUS UNIVERSITY)
      • 09:30
        UNICORE 15m
        Speaker: Mr Krzysztof Benedyczak
        Slides
      • 09:45
        Discussion 35m
    • 10:20 10:40
      Coffee 20m
    • 10:40 12:00
      Job management AuthZ IT Auditorium

      IT Auditorium

      CERN

      Presentations that give a review of the Authorization decision mechanisms of all job management systems. These will form the basis for any integration with the common libraries and security tokens. Presentations from gLite WMS, CE(s) (gLite and ARC))

      • 10:40
        ARC CE 15m
        Speaker: Mr Aleksandr Konstantinov (VILNIUS UNIVERSITY)
        Slides
      • 10:55
        UNICORE AuthZ 15m
        Speaker: Mr Krzysztof Benedyczak
        Slides
      • 11:10
        gLite CREAM 10m
        Speaker: Paolo Andreetto (Unknown)
        Slides
      • 11:20
        gLite WMS 10m
        Speaker: Marco Cecchi (Unknown)
        Slides
      • 11:30
        Argus AuthZ Service 15m
        Speakers: Andrea Ceccanti (Unknown), Andrea Ceccanti (Unknown)
        Slides
      • 11:45
        Discussion 15m
    • 12:00 12:20
      Summary IT Auditorium

      IT Auditorium

      CERN

      A summary of any decisions reached and also where more work needs to be done.

      • 12:00
        Security Vulnerabilities in EGI 15m
        Speaker: Linda Ann Cornwall (Particle Physics-Rutherford Appleton Laboratory-STFC - Science &)
        Slides
      • 12:15
        Summary 5m
        Speaker: John White White (Helsinki Institute of Physics HIP)