Assessing Combined Assurance

Similar documents
Assessing Combined Assurance

Keeping EGI secure. EGI CSIRT: Prevention - Response - Training

Tier-2. Joint Annual Meeting of ÖPG/SPS/ÖGAA - Innsbruck /48. Austrian Federated WLCG

Cisco SIP Proxy Server (CSPS) Compliance Information

LISP-DDT implementation status and deployment considerations

THE WONDERLAND OF OPERATING THE ALICE EXPERIMENT. The Challenges of Operating a Large Physics Experiment

Establishing the European Grid Initiative Organization (EGI.eu)

High usability and simple configuration or extensive additional functions the choice between Airlock Login or Airlock IAM is yours!

CRL Processing Rules. Santosh Chokhani March

Purpose. Scope. Process flow OPERATING PROCEDURE 07: HAZARD LOG MANAGEMENT

Security & Stability Advisory Committee. Update of Activities

Your Roadmap to Single IRB Review Getting Started with SMART IRB & the Online Reliance System

Osceola County Property Appraiser GIS Modernization: An Enterprise Implementation

A Guide to SMART IRB s Resources for IRB and HRPP Personnel

A GUIDE TO RISK ASSESSMENT IN SHIP OPERATIONS

Advanced SOC. Key Technologies for Security Operations. RSA Security Summit 2014 Advanced SOC. RSA Security Summit, 24 april 2014 Marcel Knippen

TLN WRO Document. Back to Back CAS support

Your Roadmap to Single IRB Review Getting Started with SMART IRB & the Online Reliance System

Crypto Sportz white paper

New Chapter Guide. Contents. 2 Organizing a Chapter. 3 General Guidelines. 4 ICF Chapter Requirements. 5 ICF Charter Chapter Requirements

Opening remarks for the International Forum for Sports Integrity. 15 February Check against delivery-

Smart Card based application for IITK Swimming Pool management

Diver Training Options

CLOSING LOCATION: Proposals must be submitted by to

Dr. Ramakrishnan Nara V.P. Product Safety & Research Perry Johnson Registrar Food Safety Inc., (PJR, USA)

Best practice with OJS a partial view

Work Health and Safety Management Plan

[XACT INTEGRATION] The Race Director. Xact Integration

PEDESTRIAN ACTION PLAN

BC Taekwondo Canadian Sport for Life Implementation Plan

Comparative Politics

St. Catharines Rowing Club Mother s Day High School Regatta Package. Sunday May 11, 2014

Planning for tennis in your Local Government Area. A resource from Tennis Australia

Organising the National Technology Needs Assessment (TNA) Process: An Explanatory Note

Foreword 3. Mission & Objectives 4. Financial Overview 8. Money In 10. Money Out 11. Delivering Services 12. Services Explained 13

Operation and safety of tramways in interaction with public space. COST Action TU1103 «STATE OF THE ART» On behalf of the action: Matus Sucha

Virtual Breadboarding. John Vangelov Ford Motor Company

Digital empowerment for the Olympic Games

Following the Radio Sailing fleet

Final Project Report (NHL Cumulative Game by Game Visualization) Patrick Wong April 24, Motivation & Audience for Visualization

Tel: October 2013

Sustainable Fishery Certification: MAFAC Recommendations on a role for NOAA? Keith Rizzardi Marine Fisheries Advisory Committee

November 30, Efficient Startup of Multi-site Research Studies: Central IRBs and National IRB Reliance Platforms

APP NOTES Onsight Connect Cisco Integration. July 2016

Redesign of the International Timetabling Process (TTR) Ljubljana, 19 February 2019

What is Scrum? Scrum is a framework that allows you to create your own lightweight process for developing new products.

RoboCup German Open D Simulation League Rules

Submitted by the Coordinators of the Working group on the General Status and Operation of the Convention (Bosnia and Herzegovina and Switzerland)

SOUTH AFRICAN QUALIFICATIONS AUTHORITY REGISTERED UNIT STANDARD:

Community Development and Recreation Committee. General Manager, Parks, Forestry and Recreation. P:\2015\Cluster A\PFR\CD AFS#22685

5/25/2018 Clone of PCC ACSTH Application with Client Coaching Experience Attestation

SoundCast Design Intro

in Hull Richard Green

SSAC Activities Update. Patrik Fältström, SSAC Chair ICANN-53 June 2015

Formula E Statistics Feeds

Who takes the driver seat for ISO and DO 254 verification?

2015 YMCA Pennsylvania Central District Swimming Championship Hosted by the York YMCA Aquatic Club. General Information:

NATIONAL COMPUTER SECURITY CENTER TRUSTED DATABASE MANAGEMENT SYSTEM INTERPRETATION

Case Study. PayPal s Sparkline Case Study. About Sparkline

A General, Flexible Approach to Certificate Revocation Dr. Carlisle Adams & Dr. Robert Zuccherato Entrust, Inc.

Registering Your Team for the First Time In a Seasonal Year

Accelerate Your Riverbed SteelHead Deployment and Time to Value

FedRAMP Plan of Actions and Milestones (POA&M) Template Completion Guide. Version 2.0

OCTOBER 2018 EXECUTIVE SUMMARY

An IOOS Operational Wave Observation Plan Supported by NOAA IOOS Program & USACE

Where and How Data is Stored

This document is to serve as a tool for submitting the Classic Team Commitment Form.

Free QA! David Golden

DETAILED BUSINESS CASE

Developing a Birmingham Transport Space Allocation policy. David Harris Transport Policy Manager Economy Directorate Birmingham City Council

#19 MONITORING AND PREDICTING PEDESTRIAN BEHAVIOR USING TRAFFIC CAMERAS

RESEARCH PROTECTIONS OFFICE

FDOT s Bicycle & Pedestrian Focused Initiative

Small Vessel Compliance Program for Fishing Vessels not more than 15 Gross Tonnage (SVCP-F)

U.S. Formula 5000 Revival Races Rules & Regulations Updated 1/1/2015

Company Surge TM for. Installation Guide v4.0 January

ISLAND BAY UNITED TALENT DEVELOPMENT PROGRAMME

AFFILIATION & MEMBERSHIP PROCEDURES

BYE-LAWS TO ARTICLE 56 DUTIES OF THE COMMISSIONS AND WORKING GROUPS

Competition Management Online User Guide for Basketball

Evaluation. Monitoring and 8.0

INSTITUTIONAL REVIEW BOARD (IRB) PROCEDURES

Open Badge Network. O2A2 European Open Badge Infrastructure. Outcome O1A3 Associate Partners. Document information

Role Profile. Chief Executive of Blackburn Youth Zone. Chair and Board of Blackburn Youth Zone

WEB RE-DESIGN SCHEDULE

SOP 801: Investigator Qualifications and Responsibilities

Specifically, the main place of residence for each player. Exceptions can be made for teams competing overseas, at tournament officials discretion.

3 FRAMEWORK FOR IMPLEMENTATION OF LAKE-TO-LAKE CYCLING ROUTE

TN-ITS implementation in Flanders. ITS Congress - 29/09/2017 Bert Boterbergh

Information on the implementation of Commission Regulation (EC) No 504/2008 on the identification of equidae

THE LIVING CAPOEIRA PROGRAMME: STRENGTHENING CULTURAL HERITAGE POLICY

STATEMENT BY GRAND CHIEF DR. ABEL BOSUM TO THE STANDING SENATE COMMITTEE ON ABORIGINAL PEOPLES

Races will be held on Lake Natoma in Rancho Cordova, CA, on a seven-lane 2000 meter buoyed course with starting platform.

Operating Committee Strategic Plan

Rules of Soccer Simulation League 2D

Date: September To the McLeod Membership,

Strategy, Developments & Outlook SESP September 2010 ESTEC, Noordwijk, The Netherlands

Adaptability and Fault Tolerance

Huntsman Polyurethanes smart simulation software. Process optimization by simulation

December MTS Houston Luncheon. Hoover Offshore Oil Pipeline System (HOOPS) GA-A244 Bypass and Wye Inspection

Transcription:

Assessing Combined Assurance David Groep Nikhef Introducing composites of DOGWOOD and BIRCH/CEDAR in EGI and beyond co-supported by the Dutch National e-infrastructure coordinated by SURF, and by EGI Core Services

EGI Combined Assurance use case IOTA AP assurance level DOGWOOD is different, but remainder of the assurance can be taken up somebody else the user community or the registrar for the Access Platform Only thing you get is an opaque ID Stepping up to adequate assurance: Real names from pseudonyms Enrolling users in a community Keeping audit records Auditability and tracing Incident response Identity elements identifier management re-binding and revocation binding to entities traceability of entities emergency communications regular communications rich attribute assertions correlating identifiers access control Evolving the EGI Trust Fabric - Bari 2015

lcg-ca or explicit configuration The wlcg IOTA CA by-pass For EGI-only sites nothing changed For EGI sites also under wlcg policy and installed post-egee: just install both policy packages egi-core and lcg ca-policy-egi-core IGTF Classic IGTF MICS IGTF SLCS ca-aegis ca-tcs ca-dfn-aai ca-policy-lcg IGTF Classic IGTF MICS IGTF SLCS ca-aegis ca-tcs ca-dfn-aai ca-cern- LCG-IOTA Evolving the EGI Trust Fabric - Bari 2015

Project MinE (ALS) use case Access traditional global grid resources from the CLI By users that have no PKIX experience but are all properly vetted and registered (in the SURFsara CUA) Case comparable to LHC VOs (and to ELIXIR) Give access based on DOGWOOD CUA ID and prepopulate a VOMS server based on CUA details

Thanks to Mischa Sallé INTERLUDE 22 September 2017 Leveraging the IGTF registration network for research

additional info: Mischa Sallé, msalle@nikhef.nl A proxy from the TTS: the ad-hoc way

additional info: Mischa Sallé, msalle@nikhef.nl A one-time URL giving a shell script

additional info: Mischa Sallé, msalle@nikhef.nl Register your ssh public key like in gitlab, sourceforge, &c

additional info: Mischa Sallé, msalle@nikhef.nl Hiding PKIX just like KRB Implicit retrieval of proxies using ssh-agent Resulting proxies can decorated with VOMS without need for passphrases or other credentials Predictable RCauth subject naming (USR) allows pre-registering in VOMS, COmanage, &c

Beyond DOGWOOD (CERN IOTA, RCauth, CILogon Basic) Old model: CERN STS tight VO binding model With the EGI and WLCG specific exception EGI combined assurance model Make assurance combination part of service AuthZ Implemented by major AuthZ frameworks: Argus (1.7.1+), LCMAPS, dcache (3.1+) Configuration shipped via EGI and WLCG But: which other assurance providers qualify?

Distributed Responsibilities I: Trusted Third Party Evolving the EGI Trust Fabric - Bari 2015

Distributed Responsibilities II: Collaborative Assurance & Traceability Evolving the EGI Trust Fabric - Bari 2015

IOTA in the EGI context EGI by design - supports loose and flexible user collaboration 300+ communities Many established bottom-up with fairly light-weight processes Membership management policy* is deliberately light-weight Most VO managers rely on naming in credentials to enroll colleagues Only a few VOs are special LHC VOs: enrolment is based on the users entry in a special (CERNmanaged) HR database, based on a separate face-to-face vetting process and eligibility checks, including government photo ID + institutional attestations Only properly registered and active people can be listed in VOMS

Developing an assessment framework

The need for guidance

Assessment Matrix Mapping for PKIX/RFC3647 is trivial How to apply out BIRCH/CEDAR guidance to community registries? https://wiki.eugridpma.org/main/assuranceassessment Relevant for COmanage & VOMS communities, but maybe wider?

Discussion! BUILDING A GLOBAL TRUST FABRIC Leveraging the IGTF registration network for research