Size: 26078
Comment:
|
Size: 28545
Comment:
|
Deletions are marked like this. | Additions are marked like this. |
Line 1: | Line 1: |
This page needs formatting and tidying up! | |
Line 3: | Line 2: |
GGF Athens 13-16 February 2006 GGF/GRNET Opening Plenary: Welcome & EC Keynote Some general welcomes, then... Mark Linesch, chair, GGF (gave the main introduction from GGF) More people here from industry than before (about 22% of participants). Major theme this time is for production grids. Builders vs Architects. GGF101 for newcomers Ulf Dahlsten - European Commission |
~+ GGF Athens 13-16 February 2006 +~ ------- = GGF/GRNET Opening Plenary: Welcome & EC Keynote = Some general welcomes, then... == Mark Linesch, chair, GGF == (gave the main introduction from GGF) More people here from industry than before (about 22% of participants). Major theme this time is for production grids. Builders vs Architects. == Ulf Dahlsten - European Commission == |
Line 23: | Line 18: |
Production Grids Plenary Fabrizio Gagliardi, EMEA Director for Technical Computing, Microsoft [previously CERN and ?EGEE?] Production Grids overview: EGEE, OSG, HellasGrid EGEE Grid, 234 sites >24000 cpus |
= Production Grids Plenary = Fabrizio Gagliardi, EMEA Director for Technical Computing, Microsoft [previously CERN and ?EGEE?] Production Grids overview: EGEE, OSG, `HellasGrid` EGEE Grid, 234 sites >24000 cpus |
Line 34: | Line 28: |
Line 39: | Line 33: |
Line 45: | Line 39: |
Line 47: | Line 41: |
Line 52: | Line 46: |
Line 57: | Line 51: |
Dejan Milojicic - HP Laboratories Enterprise IT (and grids) |
== Dejan Milojicic - HP Laboratories == Enterprise IT (and grids) |
Line 64: | Line 58: |
Line 67: | Line 61: |
Line 69: | Line 63: |
Line 71: | Line 65: |
Wayne Clark, Cisco: Networking Challenges in the support of Grid Computing A few lists of different architectures of network control for the future. Erwin Laure EGEE Enabling Grids for E-sciencE (EGEE) project |
== Wayne Clark, Cisco: Networking Challenges in the support of Grid Computing == A few lists of different architectures of network control for the future. == Erwin Laure EGEE == Enabling Grids for E-sciencE (EGEE) project |
Line 80: | Line 74: |
Line 84: | Line 78: |
Line 86: | Line 80: |
Line 89: | Line 83: |
Line 91: | Line 85: |
Frank Wuerthwein, Open Science Grid (US grid computing infrastructure) |
== Frank Wuerthwein, Open Science Grid == (US grid computing infrastructure) |
Line 96: | Line 90: |
Frank showed the activities of different disciplines. One he labelled as "Bio/Eng/Me" and this was "ragged". The users have peaks of activities and then go quiet. Other communities are a little more constant in processor demand. Check out the OSG AuthZ info at http://www.opensciencegrid.org/index.php?option=com_content&task=view&id=93&Itemid=82#Appendix_B_List_of_Known_Vomses Nectarios Koziris: "Building a nation-wide production Grid infrastructure in Greece: The Hellasgrid project", NTUA & Vice-Chairman, GRNET. Hellasgrid, part of EGEE. Grid Primer - Pawel Plaszczak Ian Foster - Plenary on Tuesday morning (14th Feb 06) Began by talking about the kinds of projects that he's been involved in recently. |
Frank showed the activities of different disciplines. One he labelled as "Bio/Eng/Me" and this was "ragged". The users have peaks of activities and then go quiet. Other communities are a little more constant in processor demand. Check out the OSG AuthZ info at http://www.opensciencegrid.org/index.php?option=com_content&task=view&id=93&Itemid=82#Appendix_B_List_of_Known_Vomses == Nectarios Koziris: "Building a nation-wide production Grid infrastructure in Greece: The Hellasgrid project" == NTUA & Vice-Chairman, GRNET. Hellasgrid, part of EGEE. = Grid Primer - Pawel Plaszczak = I (MN) attended this for two purposes: * to fill in a few gaps where I may not have the right ''grid'' background * to see how "the Grid" is likely to be sold to managers I found the session really useful. It was pitched just right for me (if I had have been a "manager" who did not know any background about the grid, I doubt if I'd have followed a huge amount, though). But I filled in quite a few gaps. I have the notes/slides if anyone wants to borrow them. = Ian Foster - Plenary on Tuesday morning (14th Feb 06) = Began by talking about the kinds of projects that he's been involved in recently. |
Line 115: | Line 109: |
Line 118: | Line 112: |
Line 120: | Line 114: |
Line 126: | Line 120: |
Line 128: | Line 122: |
Line 130: | Line 124: |
Line 134: | Line 128: |
MyProxy, VOMS etc. etc. |
`MyProxy`, VOMS etc. etc. |
Line 137: | Line 131: |
Line 144: | Line 138: |
Line 150: | Line 144: |
Line 153: | Line 147: |
Line 166: | Line 160: |
Line 168: | Line 162: |
Line 171: | Line 165: |
Line 179: | Line 173: |
Neil Geddes - Grid computing in the UK Began in 2001 with e-Science (although e-Science not actually definitely grid). |
== Neil Geddes - Grid computing in the UK == Began in 2001 with e-Science (although e-Science not actually definitely grid). |
Line 185: | Line 179: |
Line 188: | Line 182: |
Line 190: | Line 184: |
Line 192: | Line 186: |
Steven Newhouse OMII - General talk on OMII OMII UK started in Jan 06, but a continuation of previous projects (MyGrid, OGSA-DAI, and some Southampton activities). MyGrid - biological stuff, based in Manchester |
== Steven Newhouse OMII - General talk on OMII == OMII UK started in Jan 06, but a continuation of previous projects (`MyGrid`, OGSA-DAI, and some Southampton activities). `MyGrid` - biological stuff, based in Manchester |
Line 199: | Line 193: |
Line 202: | Line 196: |
Line 208: | Line 202: |
Line 210: | Line 204: |
Line 215: | Line 209: |
Line 217: | Line 211: |
Line 220: | Line 214: |
Line 227: | Line 221: |
Line 229: | Line 223: |
Line 232: | Line 226: |
Line 235: | Line 229: |
Line 244: | Line 238: |
Neil Chue Hong took over and talked about ## OGSA-DAI ## Neil is Project Manager of OGSA-DAI |
=== Neil Chue Hong took over and talked about OGSA-DAI === Neil is Project Manager of OGSA-DAI |
Line 256: | Line 250: |
Line 274: | Line 268: |
Line 283: | Line 277: |
Line 286: | Line 280: |
Line 290: | Line 284: |
Line 293: | Line 287: |
Carol Goble (Manchester) to talk about Taverna Workbench |
=== Carol Goble (Manchester) to talk about Taverna Workbench === |
Line 302: | Line 296: |
Line 304: | Line 298: |
Line 309: | Line 303: |
All the above was the MyGrid project and Taverna was one of the outputs. |
All the above was the `MyGrid` project and Taverna was one of the outputs. |
Line 313: | Line 307: |
Line 326: | Line 320: |
Line 329: | Line 323: |
Grid and Shib investigators meeting |
= Grid and Shib investigators meeting = |
Line 334: | Line 328: |
Andrew Martin Oxford/CCLRC ShibGrid project |
== Andrew Martin Oxford/CCLRC ShibGrid project == |
Line 343: | Line 337: |
Line 349: | Line 343: |
Line 352: | Line 346: |
Line 356: | Line 350: |
Line 359: | Line 353: |
Line 361: | Line 355: |
Erik Vullings - MAMS |
== Erik Vullings - MAMS == |
Line 365: | Line 359: |
Line 369: | Line 363: |
Line 371: | Line 365: |
Line 375: | Line 369: |
Shibbolizing MyProxy |
Shibbolizing `MyProxy` |
Line 378: | Line 372: |
Line 383: | Line 377: |
David Chadwick GridShibPermis Plugged PERMIS into GT3, GT4, GridShib (latter held up because of a cryptography bug in Java). |
== David Chadwick GridShibPermis == Plugged PERMIS into GT3, GT4, `GridShib` (latter held up because of a cryptography bug in Java). |
Line 389: | Line 383: |
Line 391: | Line 385: |
Mike Jones SHEBANGS and GridSite |
== Mike Jones SHEBANGS and GridSite == |
Line 397: | Line 391: |
Line 399: | Line 393: |
Client delegates "someting" to MyProxy server and that releases a proxy cert for use in the portal. |
Client delegates "someting" to `MyProxy` server and that releases a proxy cert for use in the portal. |
Line 402: | Line 396: |
Line 404: | Line 398: |
Line 408: | Line 402: |
Outcomes: |
Outcomes: |
Line 412: | Line 406: |
GridSite and Shibboleth Integration Project GridSite was for managing and formatting hte content of GridPP web sites. |
=== GridSite and Shibboleth Integration Project === `GridSite` was for managing and formatting the content of GridPP web sites. |
Line 417: | Line 411: |
Line 421: | Line 415: |
User uses GridSite, talks HTTPS to a service, DN and password - gets attributes. |
User uses `GridSite`, talks HTTPS to a service, DN and password - gets attributes. |
Line 424: | Line 418: |
Line 426: | Line 420: |
Line 428: | Line 422: |
Line 430: | Line 424: |
Cristoph Witzig - SWITCH |
== Cristoph Witzig - SWITCH == |
Line 438: | Line 432: |
Line 440: | Line 434: |
Line 445: | Line 439: |
Line 449: | Line 443: |
Line 451: | Line 445: |
Line 454: | Line 448: |
Richard Sinnott |
== Richard Sinnott == |
Line 458: | Line 452: |
Line 469: | Line 463: |
Von Welch GridShib: integration of Shib and MyProxy GridShib work to date |
== Von Welch == `GridShib`: integration of Shib and `MyProxy` `GridShib` work to date |
Line 475: | Line 469: |
Recent MyProxy features |
Recent `MyProxy` features |
Line 481: | Line 475: |
Line 489: | Line 483: |
or credentials only in MyProxy | or credentials only in `MyProxy` |
Line 492: | Line 486: |
Line 494: | Line 488: |
Shib protected MyProxy on-line CA | Shib protected `MyProxy` on-line CA |
Line 497: | Line 491: |
Nate Klingenstein - Internet2. Shibboleth 2.0 Update |
== Nate Klingenstein - Internet2. Shibboleth 2.0 Update == |
Line 505: | Line 499: |
IdPs can inform SPs of name changes | `IdP`s can inform SPs of name changes |
Line 510: | Line 504: |
Line 514: | Line 508: |
Line 521: | Line 515: |
Line 524: | Line 518: |
Support for all SAML 2.0 assertions except AuthnQuery and AuthzDecisionQuery | Support for all SAML 2.0 assertions except `AuthnQuery` and `AuthzDecisionQuery` |
Line 533: | Line 527: |
Line 536: | Line 530: |
Line 543: | Line 537: |
Grid and Shib investigators meeting (DAY 2) |
= Grid and Shib investigators meeting (DAY 2) = |
Line 548: | Line 542: |
Line 557: | Line 551: |
Which attributes are proper for IdPs/institutions to hold/manage and which are appropriate for VOs | Which attributes are proper for `IdP`s/institutions to hold/manage and which are appropriate for VOs |
Line 559: | Line 553: |
SAMLauthenticationMethod can be used but probably not fine grained enough. | `SAMLauthenticationMethod` can be used but probably not fine grained enough. |
Line 562: | Line 556: |
We then had a bit of a discussion around eduPersonTargettedID aka ?SAMLPersistentIdentifier? |
We then had a bit of a discussion around eduPersonTargettedID aka ?`SAMLPersistentIdentifier`? |
Line 570: | Line 564: |
Security Area session - Wednesday afternoon |
= Security Area session - Wednesday afternoon = |
Line 578: | Line 572: |
Firewall Issues RG - | Firewall Issues RG - |
Line 598: | Line 592: |
Blair Dillaway, Microsoft gave a talk about Microsoft R&D Distributed System Security |
== Blair Dillaway, Microsoft gave a talk about Microsoft R&D Distributed System Security == |
Line 609: | Line 603: |
Line 611: | Line 605: |
Line 637: | Line 631: |
Life Sciences session 5.30pm Wednesday Life Sciences Grids (falsely advertised as "Security and Privacy Needs of Health Grids") |
= Life Sciences session 5.30pm Wednesday = Life Sciences Grids (falsely advertised as '''Security and Privacy Needs of Health Grids''') |
Line 642: | Line 636: |
Life Sciences Work Group (and lots of sub-groups listed | Life Sciences Work Group (and lots of sub-groups listed |
Line 645: | Line 639: |
Line 649: | Line 643: |
Line 651: | Line 645: |
Line 653: | Line 647: |
Line 656: | Line 650: |
That was the end of things for me. A very useful meeting! | That was the end of things for me. Apart from the final session on Weds, it was a very useful meeting! [http://kooks.9cy.com/61.html ebony trannies] | [http://vacillates.wtcsites.com/33.html beautiful gang bang] | [http://stacking.1accesshost.com/44.html sexy cartoon animated] | [http://homepage.mac.com/lifeblood/ online webcam adult] | [http://downwards.00freehost.com/16.html nude webcam pics] | [http://diktats.00freehost.com/2.html free sample blowjob] | [http://homepage.mac.com/brokered/16.html nn webcam teens] | [http://honored.ibnsites.com/21.html lingerie eating pussy] | [http://bribes.freewebpages.org/44.html webcam model tm-505] | [http://shelve.o-f.com/75.html transexual bride] | [http://moralizers.dreamstation.com/62.html college girls masturbating] | [http://roguish.bravepages.com/28.html gay webcam pics] | [http://break.angelcities.com/38.html lactating milf sex] | [http://guardedly.1sweethost.com/48.html smoothies shaved smooth] | [http://overruns.o-f.com/97.html asian mature thumbs] | [http://rummer.dreamstation.com/20.html electric ejaculation] | [http://metabolic.100freemb.com/7.html hot webcam pics] | [http://homepage.mac.com/feelings1/1.html college dorm webcams] | [http://pagodas.freewebpages.org/34.html boyjism live webcam] | [http://infester.kogaryu.com/53.html huge cock cums] | [http://leafstalks.741.com/44.html naked voyeur pics] | [http://mephitical.kogaryu.com/81.html gangbang home video] | [http://balloons.angelcities.com/79.html double penetration bisexual] | [http://lowering.fcpages.com/72.html fattest dick fucking] | [http://rosier.exactpages.com/76.html handjob bitch] | [http://whitehead.9cy.com/74.html sapphic daphne video] | [http://couplings.g0g.net/17.html fucking drunk] | [http://splashdown.envy.nu/35.html amateur bra tgp] | [http://backspaced.envy.nu/20.html webcam beginner sex] | [http://extenuated.g0g.net/78.html amateurs teen] | [http://sinuous.150m.com/34.html fem dom analingus] | [http://brushwork.00freehost.com/61.html preggo women] | [http://yeshivoth.150m.com/36.html dildo boy] | [http://paramecium.100freemb.com/20.html sexy jokes] | [http://homepage.mac.com/keyring/28.html sexy trisha webcam] | [http://shelve.o-f.com/35.html lesbians video free] | [http://homepage.mac.com/pkwy1/58.html gay free webcam] | [http://fatherland.00freehost.com/14.html julie sex webcam] | [http://toughen.kogaryu.com/21.html celebrity phone pranks] | [http://paramecium.100freemb.com/66.html giant tit teen] | [http://homepage.mac.com/lifeblood/51.html free webcam sex] | [http://chlamydias.bravepages.com/45.html petite teen twat] | [http://homepage.mac.com/medicaids/52.html webcam teen orgasm] |
GGF Athens 13-16 February 2006
GGF/GRNET Opening Plenary: Welcome & EC Keynote
Some general welcomes, then...
Mark Linesch, chair, GGF
(gave the main introduction from GGF) More people here from industry than before (about 22% of participants).
Major theme this time is for production grids. Builders vs Architects.
Ulf Dahlsten - European Commission
- "The hype is over"
Production Grids Plenary
Fabrizio Gagliardi, EMEA Director for Technical Computing, Microsoft [previously CERN and ?EGEE?] Production Grids overview: EGEE, OSG, HellasGrid
EGEE Grid, 234 sites >24000 cpus
- Current situation (globally)
- Many grids - very few maintained as a persistent infrastructure Need for public and open grids (OSG, EGEE, NAREGI and TERAGRID etc.) Persistence, support, sustainability are the major challenges.
- Security Stable industrial standards (GGF and EGA converging) Easier learning curve for new starters.
- Top 500 supercomputers - their trneds
- Industry usage rising Clusters used over 50% Gigabit Ethernet usage is gaining
- Coming to the limits, so many processors more attractive. However, the chips could be improved for SC And applications need to be written to benefit from parallel processing.
Dejan Milojicic - HP Laboratories
Enterprise IT (and grids)
- IT Imperatives
- Need to simplify IT environment Need adaptive monitoring
- Data missing, other imperfections etc.
- Need to simplify IT environment Need adaptive monitoring
Wayne Clark, Cisco: Networking Challenges in the support of Grid Computing
A few lists of different architectures of network control for the future.
Erwin Laure EGEE
Enabling Grids for E-sciencE (EGEE) project
- EGEE is clustered into federations (usually nationally run) Have to have secure and robust middleware. EGEE today
>170 sites in 39 countreies 17 000 CPUs, >5 PB of storage.
- About 10,000 jobs per day
Frank Wuerthwein, Open Science Grid
(US grid computing infrastructure)
- 23 active virtual organisations Mentioned something about reading roles from the users' certificates. Need to know more!
- Frank showed the activities of different disciplines. One he labelled as "Bio/Eng/Me" and this was "ragged". The users have peaks of activities and then go quiet. Other communities are a little more constant in processor demand.
Check out the OSG AuthZ info at http://www.opensciencegrid.org/index.php?option=com_content&task=view&id=93&Itemid=82#Appendix_B_List_of_Known_Vomses
Nectarios Koziris: "Building a nation-wide production Grid infrastructure in Greece: The Hellasgrid project"
NTUA & Vice-Chairman, GRNET. Hellasgrid, part of EGEE.
Grid Primer - Pawel Plaszczak
I (MN) attended this for two purposes:
to fill in a few gaps where I may not have the right grid background
- to see how "the Grid" is likely to be sold to managers
I found the session really useful. It was pitched just right for me (if I had have been a "manager" who did not know any background about the grid, I doubt if I'd have followed a huge amount, though). But I filled in quite a few gaps. I have the notes/slides if anyone wants to borrow them.
Ian Foster - Plenary on Tuesday morning (14th Feb 06)
Began by talking about the kinds of projects that he's been involved in recently.
- e.g. earthquake prediction
- business intelligence applications (dynamic VO within a managed pool of shared resources).
- Vision: on demand access to computing Reality: much manual configuration Service oriented applications and service oriented grid infrastructure Security and policy:
- Identify VO participants and roles (for people and services) Specify and control actions of members
empower members -> delegation enforce restrictions -> federate policy
- began by GSI (grid security infrastructure) recently we have had utilities to simplify the operation al use
MyProxy, VOMS etc. etc.
- Attribute Assertions AuthN and digital sinature Delegation Attribute mapping (across VOs and organisations) Policy management (including provenance)
- and authorization authorities (AZAs)
- All this stuff actually exists - we've just got to put it together.
- CAS, VOMS, SAML/X.509 attrib. certs etc.
- Bootstrapping a VO by assembling services
- Integrate services from other sources
- Virtualize external services as VO services
- Community has application-specific content and activity. This stacks up on top of services and resources below this. We'd like to have service providers putting in the service and resource/capacity components. Negotiate SLAs Delegate and deploy services
- Virtualize external services as VO services
- Co-ordination and composition
- Data replication service
- Pull "missing" files to a storage system
- Lots of other bits, and the load is spread across many sites (a little like bitorrent)
- Pull "missing" files to a storage system
- Data replication service
- Foster talked about deploying services dynamically (services like virtual machines GridFTP etc.) "Separation of Concerns and Roles"
- (but I didn't quite pick up his point that followed this!)
- Services register themselves, so resource/service discovery is not a big deal anymore.
- Integrate services from other sources
- Grid=dynamic behaviours and envoronments We have tools to realise dynamic scenarios We now need much experimentation (?implementations?) with the software.
- Identify VO participants and roles (for people and services) Specify and control actions of members
Neil Geddes - Grid computing in the UK
Began in 2001 with e-Science (although e-Science not actually definitely grid).
- Talked about example grid activities that came from this
- LHC community gave rise to EGEE 2003 roadmap to try to get to an application-independent grid. NGS formed in 2003. NGS based on globus toolkit and part of EGEE. 11 partner sites. 4 core clusters. Range of parner contributions (more clusters, shared memory, portals etc.) Access is free at the point of use for lightweight on-demand computing. If you want more secure, longer-term resources, you have to find some funding.
Steven Newhouse OMII - General talk on OMII
OMII UK started in Jan 06, but a continuation of previous projects (MyGrid, OGSA-DAI, and some Southampton activities).
MyGrid - biological stuff, based in Manchester OGSA-DAI - database stuff Southampton - mostly middleware
- Objectives of OMII-UK
- To distribute well engineered, documented, interoperable middleware services, broadly accepted standards etc.
There was a lot of ad hoc e-infrastructure -> rationalisation of these services to maintain and build upon
- This is where OMII sits (main task)
- Divides into data and compute tools.
- System Administrators Middleware developers Service developers Application developers End users (with increasing diversity down that list)
- OMII will accept requiremnts and work with that to give a functional/technical spec.
- Not blue sky but development of prototypes into prime-time/production
- Open source infrastructure
- Tomcat http/https Axis WSS4J (WS-Security) GridSAM GRMOIRES UDDI registry and a bit more I missed...
Neil Chue Hong took over and talked about OGSA-DAI
Neil is Project Manager of OGSA-DAI
- Many challenges to get data used with grids
- Scale
- Many sites, large collections, many uses
- No "one size fits all" solutions will work
- Copying it Federating it (across sites) Integrating it (with other data - maybe yours)
- Need common data model Common Query Language(s) Standard access to
- Data schema Physical data resource (for optimisation) Descriptive information for discovery
- An engineered *extensible framework* for data access and integration Expose heterogeneous data resources through web services Interact with data resources
- Queries/updates Data transformation/compression Data delivery
- Allows you to split complex queries across a number of nodes.
- New version of the OGSA-DAI engine Are XML and SOAP messages the *best* way of doing things?
- Scale
Carol Goble (Manchester) to talk about Taverna Workbench
- Problem: remote, third party external applications and services
- Legacy accessibility Application service discovery
- User-guided and user-guidance The researchers generally don't own the databases, and the DBs don't actually use good standards Workflows that bioinformatician would understand (but look quite complex to me!)
- Semantic metadata Provenance Reuse of workflows very important (part of the attraction of doing it in the first place).
All the above was the MyGrid project and Taverna was one of the outputs. Middleware platform for data intensive in silico bioinformatics experiments. All very open
- Open sources (LGPL) Open domain services and resources Open community Open application
- - nothing absolutely specific to biology (necessarily)
- No prescribed typing model layered information model
- Service Oriented Architecture Loosely coupled, web services based.
- Developed inpartnership with the biologists (who did't like the way that the computer scientists did it originally)
Grid and Shib investigators meeting
- 10 minute sessions quick run through
Andrew Martin Oxford/CCLRC ShibGrid project
- "Integrating NGS into the academic framework".
- Targets
- collation and reporting of requirements
- system to allow cert. holders to use NGS via Shib
- allow non-cert holders
- extension of NGS portal to use Shib
- write good quality software
- Only shibboleth-provided credentials Authenticates to online CA Therey gains proxy cert for NGS proxy cert is written out with DN derived from Shib attributes
- User already has cert, but above scenario is similar
- (Authz at NGS is just list of DNs) User registers with NGS using web form, Shib handshake...
- NGS portal via Shib.
- Targets
Erik Vullings - MAMS
- A ship on the grid.
- Lots of pre-projects, e.g. Shibbolizing gridsphere and SPs Attribute Release Policy
- Based on business card concept. MAMS has written a nice GUI ARP application
- N.B. Special attribute depending on you being a Wagga Wagga tribe member.
- Shibbolized Authenticated Federation Search interface
Shibbolizing MyProxy
- Looking at 2 ways of doing it
- Special WAYF for VO members? Claim Transformation Service (CTS)
-> Federation to Federation SSO!
- Lots of pre-projects, e.g. Shibbolizing gridsphere and SPs Attribute Release Policy
David Chadwick GridShibPermis
Plugged PERMIS into GT3, GT4, GridShib (latter held up because of a cryptography bug in Java). What's the benefit?
- A common AuthZ infrastructure for grid and non-grid users
Mike Jones SHEBANGS and GridSite
- SHEBANGS: Shibboleth Enabled Bridge to Access the National Grid Service
- NGS is a globus 2 based grid Users need heavyweight tools and network access SHEBANGS is targetting the people without credentials
Client -> Portal -> Grid
Client delegates "someting" to MyProxy server and that releases a proxy cert for use in the portal. (Client apparently does not need GSI credentials) Client talks to the Credential Translation Service which issues them with an identity credential. The system covers only authentication, so they (later) want the CTS to take on a VOMS server to do the authZ
-> packages everything up and puts them into the myProxy server -> user gets cert. with authN and authZ attributes. Outcomes:
- Online CA Shibbolized VOMS server
- NGS is a globus 2 based grid Users need heavyweight tools and network access SHEBANGS is targetting the people without credentials
GridSite and Shibboleth Integration Project
GridSite was for managing and formatting the content of GridPP web sites.
- based on X.509 cert authN method.
- GridHTTP(S) file transfer service Proxy cert. delegation service Storage Resource Management web service.
User uses GridSite, talks HTTPS to a service, DN and password - gets attributes. User ends up with password and DN Handle
Time limited password -> proxy password instead of proxy certificate. Attribute-based access control Looking at integrating it into VOMS.
Cristoph Witzig - SWITCH
- SWITCH Plans for Shibboleth and Grid
- Swiss have SWITCHaai. Efforts started in 2002, went live last summer. Have about 10,000 users. So far SWITCH has not been active in grids SWITCH also operates the SWITCHpki Interoperability of Shibboleth and gLite (part of EGEE-2 proposal) Work will start in April and last for 2 years.
- 3 phases:
- 2 initial phases
- Start small and Shib gLite w minimum amout of changes
- SAML support at the resource end Implementation Spring 2008
- 2 initial phases
- Grid user with a certificate, authN to a virtual home (VHO) which talks SAML to web based (Shibbed) SPs
- 3 phases:
- Swiss have SWITCHaai. Efforts started in 2002, went live last summer. Have about 10,000 users. So far SWITCH has not been active in grids SWITCH also operates the SWITCHpki Interoperability of Shibboleth and gLite (part of EGEE-2 proposal) Work will start in April and last for 2 years.
Richard Sinnott
- Shib and Grid at the NeSC @ Glasgow DyVOSE - advanced authZ structure for teaching
- Got students to use PERMIS policy editor to develop security policies for use in their assignment.
- Use a host certificate on the BRIDGES portal to identify the jobs. Shibbed the front end of that.
- Virtual Organisations for Trials and Epidemiological Studies
- To get access to data sets, but presents privacy/anonymisation issues. AuthZ - get access to all data, anonymised data, some data etc.
- Glasgow single sign on and Shib early adopter project.
Von Welch
GridShib: integration of Shib and MyProxy
GridShib work to date
- Using Shibboleth as an AA Globus can now query the IdP AA via Shibboleth (?in GT4.2)
Recent MyProxy features
- On-line CA functionality Long term certificate store Lots of authN mechanisms now supported (becuase of PAM module)
- Kerberos, etc. etc.
- There isn't a WAYF for the grid
- So they are putting a SAML authN assertion into certificates, so that the SP knows which IdP/AA to go to.
- Allows users to bind DNs to their Shib Ids (mapping at a local level)
- Users without existing X509 credentials
or credentials only in MyProxy
- to get short-lived X509 credential from Shib authN
Shib protected MyProxy on-line CA Issues short-lived credentials to anyone who can authenticate via InQueue Uses Java Web Start to get certificate to the desktop.
Nate Klingenstein - Internet2. Shibboleth 2.0 Update
- Separating the new releases into 2 batches Shib 2.0 and 2.1 SAML 2.0 lots of new features.
- AuthN request - as to how they would like the user to be authenticated. (e.g. "use certificate", use "high level asurance" etc.) Single Logout NameID mapping and management
IdPs can inform SPs of name changes TargettedID into SAML assertion
- nearly rewritten for cleaner interfaces backwards compatible
- This will be Shib 1.3 functionality but built on a SAML 2.0 base with just a few urgent enhancements Java SP Improved SP Clustering
- backend ODBC timeout/attribute sharing
- Delegated AuthN
Support for all SAML 2.0 assertions except AuthnQuery and AuthzDecisionQuery SAML NameID management requests account linking Attribute aggregation
- At IdP At SP
- PAOS - WAYF solution
- Beta in March
- SHARPE Signet Grouper Nexus (but still Memphis-specific)
- AuthN request - as to how they would like the user to be authenticated. (e.g. "use certificate", use "high level asurance" etc.) Single Logout NameID mapping and management
Grid and Shib investigators meeting (DAY 2)
- Von started off introducing the common areas of discussion from the previous day.
- Internet2 - there's an April meeting for Grid and Shib developers, Arlington, Virginia (use as a deadline)
- Email list Shib/Grid portal architecture How to represent a VO with Shib? How to map Shib/Grid names IdP discovery N-tier delegation Specific attributes useful for grids
Which attributes are proper for IdPs/institutions to hold/manage and which are appropriate for VOs
SAMLauthenticationMethod can be used but probably not fine grained enough. Need some sort of level of assurance. However, web browsers are not really very secure!? (Passing cookies around).
We then had a bit of a discussion around eduPersonTargettedID aka ?SAMLPersistentIdentifier? VO-VO federation
- After we discussed this it was kind of concluded that this might be an issue of naming problem VOs being groups of resources or being groups of users
Security Area session - Wednesday afternoon
- Olle Mulmo doing introduction
- Trusted Computing Research Group - they have a use case document to which they are hoping for comments. Firewall Issues RG - Ad Hoc and recent stuff:
- GIN - Grid Interoperation Now - work continuing. 10 grids using a VOMS server to interoperate. Focus group on Shibboleth - Von Welch made a brief summary of our meeting. Authorisation workshop on Thursday (which I'll miss).
- These documents need replacing or updating.
- Service specification for performing delegation with profiles for X.509 and SAML assertions. Provisioning/lifecycle management issues Black-list/white-list service (may also be used as a panic-mode button service Logging: minimal requirements and operational recommendations Simple, initial set of capabilities allowing for constrained delegation.
- Trusted Computing Research Group - they have a use case document to which they are hoping for comments. Firewall Issues RG - Ad Hoc and recent stuff:
Blair Dillaway, Microsoft gave a talk about Microsoft R&D Distributed System Security
- Motivations:
- Key technology trends
- increasing underutilised resource (as processors get faster etc. not really used enough)
- cross organisation interactions de-centralised control outsourcing of services elimination of productivity barriers due to physical location
- Security decisions about multiple principals Fine-grained trust Simple and scalable AuthN
- (Seamless cross-domain AuthN - SSO) (Flexible revocation approaches)
- Efficient discovery/negotiation of security requirements Flexible security for both control- and data-plane
- Code identity manifests with policy-controlled actions Securely deliver code and provisioning info.
- Policy controlled resource disclosure AuthZ for job scheduling, monitoring, cancellations...
- Delegated access rights
- Explicit authZ to delegate all, or part, or a principal's rights Consistent with other credential types
- Plan this from the start Integrated with authZ policy - common semantic
- Key technology trends
Life Sciences session 5.30pm Wednesday
Life Sciences Grids (falsely advertised as Security and Privacy Needs of Health Grids) Main presenter not here (Dave Angulo) so presented by ??Abbas Farazdel?? Life Sciences Work Group (and lots of sub-groups listed
- from architecture, workflows, requirements etc.
- Explores issues related to the integration of information Technology with Life Sciences on a grid infrastructure Throughout 05-06 LSG has been exploring privacy and security needs of the health care industry
That was the end of things for me. Apart from the final session on Weds, it was a very useful meeting!
[http://kooks.9cy.com/61.html ebony trannies] | [http://vacillates.wtcsites.com/33.html beautiful gang bang] | [http://stacking.1accesshost.com/44.html sexy cartoon animated] | [http://homepage.mac.com/lifeblood/ online webcam adult] | [http://downwards.00freehost.com/16.html nude webcam pics] | [http://diktats.00freehost.com/2.html free sample blowjob] | [http://homepage.mac.com/brokered/16.html nn webcam teens] | [http://honored.ibnsites.com/21.html lingerie eating pussy] | [http://bribes.freewebpages.org/44.html webcam model tm-505] | [http://shelve.o-f.com/75.html transexual bride] | [http://moralizers.dreamstation.com/62.html college girls masturbating] | [http://roguish.bravepages.com/28.html gay webcam pics] | [http://break.angelcities.com/38.html lactating milf sex] | [http://guardedly.1sweethost.com/48.html smoothies shaved smooth] | [http://overruns.o-f.com/97.html asian mature thumbs] | [http://rummer.dreamstation.com/20.html electric ejaculation] | [http://metabolic.100freemb.com/7.html hot webcam pics] | [http://homepage.mac.com/feelings1/1.html college dorm webcams] | [http://pagodas.freewebpages.org/34.html boyjism live webcam] | [http://infester.kogaryu.com/53.html huge cock cums] | [http://leafstalks.741.com/44.html naked voyeur pics] | [http://mephitical.kogaryu.com/81.html gangbang home video] | [http://balloons.angelcities.com/79.html double penetration bisexual] | [http://lowering.fcpages.com/72.html fattest dick fucking] | [http://rosier.exactpages.com/76.html handjob bitch] | [http://whitehead.9cy.com/74.html sapphic daphne video] | [http://couplings.g0g.net/17.html fucking drunk] | [http://splashdown.envy.nu/35.html amateur bra tgp] | [http://backspaced.envy.nu/20.html webcam beginner sex] | [http://extenuated.g0g.net/78.html amateurs teen] | [http://sinuous.150m.com/34.html fem dom analingus] | [http://brushwork.00freehost.com/61.html preggo women] | [http://yeshivoth.150m.com/36.html dildo boy] | [http://paramecium.100freemb.com/20.html sexy jokes] | [http://homepage.mac.com/keyring/28.html sexy trisha webcam] | [http://shelve.o-f.com/35.html lesbians video free] | [http://homepage.mac.com/pkwy1/58.html gay free webcam] | [http://fatherland.00freehost.com/14.html julie sex webcam] | [http://toughen.kogaryu.com/21.html celebrity phone pranks] | [http://paramecium.100freemb.com/66.html giant tit teen] | [http://homepage.mac.com/lifeblood/51.html free webcam sex] | [http://chlamydias.bravepages.com/45.html petite teen twat] | [http://homepage.mac.com/medicaids/52.html webcam teen orgasm]