SlideShare a Scribd company logo
MWSG Meeting, Stanford Linear Accelerator Laboratory

Privilege Project
Recent Updates

MWSG Meeting
June 5-6, 2006
Stanford Linear Accelerator Laboratory

Vikram Reddy Andem

1
Vikram Reddy Andem, Fermilab

Privilege Management

June 06, 2006
MWSG Meeting, Stanford Linear Accelerator Laboratory

Where does Privilege fit in Grid Services

Privilege
Infrastructure
Naturally fits
Here.

2
Vikram Reddy Andem, Fermilab

Privilege Management

June 06, 2006
MWSG Meeting, Stanford Linear Accelerator Laboratory

Project Goals

The primary goal of the project was to deliver the execution call-out for
finer-grained authorization of processing resources

3
Vikram Reddy Andem, Fermilab

Privilege Management

June 06, 2006
MWSG Meeting, Stanford Linear Accelerator Laboratory

Privilege Architecture – Compute Element

Proposed architecture (Dane Skow, Markus Lorch, Ian Fisk) 04//2004

Vikram Reddy Andem, Fermilab

Privilege Management

4
June 06, 2006
MWSG Meeting, Stanford Linear Accelerator Laboratory

Privilege Architecture (continued)

VOMS

Execution site
Compute Element

Gatekeeper
GRAM
gridFTP

PRIMA

SAZ
site
GUMS
Server

Storage Element

SRM/
dCache

gPLAZMA

Storage
Authorization
Service

5
Vikram Reddy Andem, Fermilab

Privilege Management

June 06, 2006
MWSG Meeting, Stanford Linear Accelerator Laboratory

Project Achievements
• Privilege has delivered an infrastructure that has been deployed on OSG
- The authorization system has been deployed on all CMS-T2 centers, the T1
at FNAL, FermiGrid, BNL, etc.
- CMS and ATLAS have defined roles that can be implemented within VOMS
- VOMS extended proxy is parsed by the callout and given to GUMS for
authentication

• The release for the pre-web service globus-gatekeeper callout is stable
- Relatively light operations support
- A couple of tickets a month, so far rapidly solved

6
Vikram Reddy Andem, Fermilab

Privilege Management

June 06, 2006
MWSG Meeting, Stanford Linear Accelerator Laboratory

Recent Advances and News
• Prima Web services callout for GT4 has been developed and is currently
distributed with VDT 1.3.9
• Prima 64-bit callout version has been developed and is currently distributed
with VDT 1.3.9
• As a part of the Policy, Publication and Trust Project we delivered
- VO Policy Template for Open Science Grid
- Site Policy Template for Open Science Grid

• Transition of Privilege Project leadership (Gabriele Garzoglio)
- gPLAZMA (Abhishek Rana, UCSD / Ted Hesselroth, FNAL)
- GUMS (John Hover, BNL)
- PRIMA (Vikram Andem)
- SAZ (Valery Sergeev, FNAL)
- SRM/d-Cache (DESY/FNAL teams)
- VOMS (INFN team, Italy)
• Working with Igor Sfiligoi (INFN) on Glexec SAML callout to GUMS
7
Vikram Reddy Andem, Fermilab

Privilege Management

June 06, 2006
MWSG Meeting, Stanford Linear Accelerator Laboratory

Current Activities
• Support PRIMA and GUMS code for 32/64 bits for GT2 and GT4 for
CMS T1&2 + OSG VO (best effort) (50% Vikram)
• Deploy and support gPlazma infrastructure for CMS Tier 1&2
(important for SRM v2 deployment) (50% Ted for 3 mo)

• Fix GUMS memory management problems
(John Hover et al.: up to .5 FTE for 3 weeks)

• Stress test of the GT4 PRIMA call-out

(John W.: 5 FTE days)

• Integration of gLexec with Privilege (8.5 FTE weeks)
• Integrate GUMS with a monitoring/alarm infrastructure

(.2 FTE/2 mo)
8

Vikram Reddy Andem, Fermilab

Privilege Management

June 06, 2006
MWSG Meeting, Stanford Linear Accelerator Laboratory

Future Plans – Ideas ?

• Simplify / Aggregate architecture
- Update communication protocols (from extended SAML v1.1 to SAML v2.0)
- Improve PRIMA build process

• Publication of role-based privilege policy (with EGEE)
• Extend privilege enforcing to network management
• Long term directions
- Investigate direct DN rights enforcement (no UID mapping)
- Integrate Privilege Project with Policy Discovery Services

9
Vikram Reddy Andem, Fermilab

Privilege Management

June 06, 2006
MWSG Meeting, Stanford Linear Accelerator Laboratory

Questions ?

10
Vikram Reddy Andem, Fermilab

Privilege Management

June 06, 2006

More Related Content

Similar to Privilege Project Vikram Andem (20)

PPTX
The Pacific Research Platform
Larry Smarr
 
PDF
Geospatial Synergy: Amplifying Efficiency with FME & Esri ft. Peak Guest Spea...
Safe Software
 
PDF
Geospatial Synergy: Amplifying Efficiency with FME & Esri
Safe Software
 
PDF
Join the Java Evolution Portland Oregon
Heather VanCura
 
PDF
Fast radio follow-up of GRBs
Tim Staley
 
PPT
OGCE Review for Indiana University Research Technologies
marpierc
 
PPT
OGCE RT Rroject Review
marpierc
 
PPTX
Indiana University's Advanced Science Gateway Support
marpierc
 
PPT
Systems Engineering Update - Dr. Ron Sega
INCOSE Colorado Front Range Chapter
 
PDF
awards competences talks
Stefano Colafranceschi
 
PPT
六合彩,香港六合彩
bwsibh
 
PPT
香港六合彩 » SlideShare
irglygks
 
PPT
香港六合彩
vbmlrn
 
PPT
香港六合彩
dsageg
 
PPT
六合彩-香港六合彩
dscvsj
 
PPT
香港六合彩|六合彩
twieat
 
PDF
Join the Java Evolution Columbus Ohio
Heather VanCura
 
PDF
F1041028_George_Chen_Resume_9_with_Publications_Training
Wei-Su Chen
 
PDF
BDW16 London - Ingrid Funie, Imperial College London - Machine Learning and F...
Big Data Week
 
The Pacific Research Platform
Larry Smarr
 
Geospatial Synergy: Amplifying Efficiency with FME & Esri ft. Peak Guest Spea...
Safe Software
 
Geospatial Synergy: Amplifying Efficiency with FME & Esri
Safe Software
 
Join the Java Evolution Portland Oregon
Heather VanCura
 
Fast radio follow-up of GRBs
Tim Staley
 
OGCE Review for Indiana University Research Technologies
marpierc
 
OGCE RT Rroject Review
marpierc
 
Indiana University's Advanced Science Gateway Support
marpierc
 
Systems Engineering Update - Dr. Ron Sega
INCOSE Colorado Front Range Chapter
 
awards competences talks
Stefano Colafranceschi
 
六合彩,香港六合彩
bwsibh
 
香港六合彩 » SlideShare
irglygks
 
香港六合彩
vbmlrn
 
香港六合彩
dsageg
 
六合彩-香港六合彩
dscvsj
 
香港六合彩|六合彩
twieat
 
Join the Java Evolution Columbus Ohio
Heather VanCura
 
F1041028_George_Chen_Resume_9_with_Publications_Training
Wei-Su Chen
 
BDW16 London - Ingrid Funie, Imperial College London - Machine Learning and F...
Big Data Week
 

More from Information Security Awareness Group (20)

PDF
Big data analysis concepts and references
Information Security Awareness Group
 
PPT
Authorization Policy in a PKI Environment Mary Thompson Srilekha Mudumbai A...
Information Security Awareness Group
 
PPT
Introduction to distributed security concepts and public key infrastructure m...
Information Security Awareness Group
 
PDF
OThe Open Science Grid: Concepts and Patterns Ruth Pordes, Mine Altunay, Bria...
Information Security Awareness Group
 
PDF
Optimal Security Response to Attacks on Open Science Grids Mine Altunay, Sven...
Information Security Awareness Group
 
PDF
THE OPEN SCIENCE GRID Ruth Pordes
Information Security Awareness Group
 
PPT
Open Science Grid security-atlas-t2 Bob Cowles
Information Security Awareness Group
 
PPT
Security Open Science Grid Doug Olson
Information Security Awareness Group
 
PPTX
Open Science Group Security Kevin Hill
Information Security Awareness Group
 
PDF
Xrootd proxies Andrew Hanushevsky
Information Security Awareness Group
 
PPT
DES Block Cipher Hao Qi
Information Security Awareness Group
 
PPT
Cache based side_channel_attacks Anestis Bechtsoudis
Information Security Awareness Group
 
PDF
Rakesh kumar srirangam
Information Security Awareness Group
 
PPT
Digital Signature Algorithm Der-Chyuan Lou, Jiang Lung Liu, Chang-Tsun Li
Information Security Awareness Group
 
PPT
Proxy cryptography Anca-Andreea Ivan , Yevgeniy Dodis
Information Security Awareness Group
 
PPT
Quan nguyen symmetric versus asymmetric cryptography
Information Security Awareness Group
 
PPT
Elliptic curvecryptography Shane Almeida Saqib Awan Dan Palacio
Information Security Awareness Group
 
Big data analysis concepts and references
Information Security Awareness Group
 
Authorization Policy in a PKI Environment Mary Thompson Srilekha Mudumbai A...
Information Security Awareness Group
 
Introduction to distributed security concepts and public key infrastructure m...
Information Security Awareness Group
 
OThe Open Science Grid: Concepts and Patterns Ruth Pordes, Mine Altunay, Bria...
Information Security Awareness Group
 
Optimal Security Response to Attacks on Open Science Grids Mine Altunay, Sven...
Information Security Awareness Group
 
THE OPEN SCIENCE GRID Ruth Pordes
Information Security Awareness Group
 
Open Science Grid security-atlas-t2 Bob Cowles
Information Security Awareness Group
 
Security Open Science Grid Doug Olson
Information Security Awareness Group
 
Open Science Group Security Kevin Hill
Information Security Awareness Group
 
Xrootd proxies Andrew Hanushevsky
Information Security Awareness Group
 
DES Block Cipher Hao Qi
Information Security Awareness Group
 
Cache based side_channel_attacks Anestis Bechtsoudis
Information Security Awareness Group
 
Rakesh kumar srirangam
Information Security Awareness Group
 
Digital Signature Algorithm Der-Chyuan Lou, Jiang Lung Liu, Chang-Tsun Li
Information Security Awareness Group
 
Proxy cryptography Anca-Andreea Ivan , Yevgeniy Dodis
Information Security Awareness Group
 
Quan nguyen symmetric versus asymmetric cryptography
Information Security Awareness Group
 
Elliptic curvecryptography Shane Almeida Saqib Awan Dan Palacio
Information Security Awareness Group
 
Ad

Recently uploaded (20)

PDF
Economic Impact of Data Centres to the Malaysian Economy
flintglobalapac
 
PPTX
Agile Chennai 18-19 July 2025 Ideathon | AI Powered Microfinance Literacy Gui...
AgileNetwork
 
PDF
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
PPTX
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
PDF
State-Dependent Conformal Perception Bounds for Neuro-Symbolic Verification
Ivan Ruchkin
 
PPTX
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
PPTX
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
PDF
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 
PPTX
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
PPTX
What-is-the-World-Wide-Web -- Introduction
tonifi9488
 
PPTX
Agentic AI in Healthcare Driving the Next Wave of Digital Transformation
danielle hunter
 
PDF
Researching The Best Chat SDK Providers in 2025
Ray Fields
 
PPTX
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
PDF
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
PPTX
AVL ( audio, visuals or led ), technology.
Rajeshwri Panchal
 
PPTX
The Future of AI & Machine Learning.pptx
pritsen4700
 
PDF
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
PDF
GDG Cloud Munich - Intro - Luiz Carneiro - #BuildWithAI - July - Abdel.pdf
Luiz Carneiro
 
PDF
TrustArc Webinar - Navigating Data Privacy in LATAM: Laws, Trends, and Compli...
TrustArc
 
PPTX
Agile Chennai 18-19 July 2025 | Emerging patterns in Agentic AI by Bharani Su...
AgileNetwork
 
Economic Impact of Data Centres to the Malaysian Economy
flintglobalapac
 
Agile Chennai 18-19 July 2025 Ideathon | AI Powered Microfinance Literacy Gui...
AgileNetwork
 
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
State-Dependent Conformal Perception Bounds for Neuro-Symbolic Verification
Ivan Ruchkin
 
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
What-is-the-World-Wide-Web -- Introduction
tonifi9488
 
Agentic AI in Healthcare Driving the Next Wave of Digital Transformation
danielle hunter
 
Researching The Best Chat SDK Providers in 2025
Ray Fields
 
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
AVL ( audio, visuals or led ), technology.
Rajeshwri Panchal
 
The Future of AI & Machine Learning.pptx
pritsen4700
 
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
GDG Cloud Munich - Intro - Luiz Carneiro - #BuildWithAI - July - Abdel.pdf
Luiz Carneiro
 
TrustArc Webinar - Navigating Data Privacy in LATAM: Laws, Trends, and Compli...
TrustArc
 
Agile Chennai 18-19 July 2025 | Emerging patterns in Agentic AI by Bharani Su...
AgileNetwork
 
Ad

Privilege Project Vikram Andem

  • 1. MWSG Meeting, Stanford Linear Accelerator Laboratory Privilege Project Recent Updates MWSG Meeting June 5-6, 2006 Stanford Linear Accelerator Laboratory Vikram Reddy Andem 1 Vikram Reddy Andem, Fermilab Privilege Management June 06, 2006
  • 2. MWSG Meeting, Stanford Linear Accelerator Laboratory Where does Privilege fit in Grid Services Privilege Infrastructure Naturally fits Here. 2 Vikram Reddy Andem, Fermilab Privilege Management June 06, 2006
  • 3. MWSG Meeting, Stanford Linear Accelerator Laboratory Project Goals The primary goal of the project was to deliver the execution call-out for finer-grained authorization of processing resources 3 Vikram Reddy Andem, Fermilab Privilege Management June 06, 2006
  • 4. MWSG Meeting, Stanford Linear Accelerator Laboratory Privilege Architecture – Compute Element Proposed architecture (Dane Skow, Markus Lorch, Ian Fisk) 04//2004 Vikram Reddy Andem, Fermilab Privilege Management 4 June 06, 2006
  • 5. MWSG Meeting, Stanford Linear Accelerator Laboratory Privilege Architecture (continued) VOMS Execution site Compute Element Gatekeeper GRAM gridFTP PRIMA SAZ site GUMS Server Storage Element SRM/ dCache gPLAZMA Storage Authorization Service 5 Vikram Reddy Andem, Fermilab Privilege Management June 06, 2006
  • 6. MWSG Meeting, Stanford Linear Accelerator Laboratory Project Achievements • Privilege has delivered an infrastructure that has been deployed on OSG - The authorization system has been deployed on all CMS-T2 centers, the T1 at FNAL, FermiGrid, BNL, etc. - CMS and ATLAS have defined roles that can be implemented within VOMS - VOMS extended proxy is parsed by the callout and given to GUMS for authentication • The release for the pre-web service globus-gatekeeper callout is stable - Relatively light operations support - A couple of tickets a month, so far rapidly solved 6 Vikram Reddy Andem, Fermilab Privilege Management June 06, 2006
  • 7. MWSG Meeting, Stanford Linear Accelerator Laboratory Recent Advances and News • Prima Web services callout for GT4 has been developed and is currently distributed with VDT 1.3.9 • Prima 64-bit callout version has been developed and is currently distributed with VDT 1.3.9 • As a part of the Policy, Publication and Trust Project we delivered - VO Policy Template for Open Science Grid - Site Policy Template for Open Science Grid • Transition of Privilege Project leadership (Gabriele Garzoglio) - gPLAZMA (Abhishek Rana, UCSD / Ted Hesselroth, FNAL) - GUMS (John Hover, BNL) - PRIMA (Vikram Andem) - SAZ (Valery Sergeev, FNAL) - SRM/d-Cache (DESY/FNAL teams) - VOMS (INFN team, Italy) • Working with Igor Sfiligoi (INFN) on Glexec SAML callout to GUMS 7 Vikram Reddy Andem, Fermilab Privilege Management June 06, 2006
  • 8. MWSG Meeting, Stanford Linear Accelerator Laboratory Current Activities • Support PRIMA and GUMS code for 32/64 bits for GT2 and GT4 for CMS T1&2 + OSG VO (best effort) (50% Vikram) • Deploy and support gPlazma infrastructure for CMS Tier 1&2 (important for SRM v2 deployment) (50% Ted for 3 mo) • Fix GUMS memory management problems (John Hover et al.: up to .5 FTE for 3 weeks) • Stress test of the GT4 PRIMA call-out (John W.: 5 FTE days) • Integration of gLexec with Privilege (8.5 FTE weeks) • Integrate GUMS with a monitoring/alarm infrastructure (.2 FTE/2 mo) 8 Vikram Reddy Andem, Fermilab Privilege Management June 06, 2006
  • 9. MWSG Meeting, Stanford Linear Accelerator Laboratory Future Plans – Ideas ? • Simplify / Aggregate architecture - Update communication protocols (from extended SAML v1.1 to SAML v2.0) - Improve PRIMA build process • Publication of role-based privilege policy (with EGEE) • Extend privilege enforcing to network management • Long term directions - Investigate direct DN rights enforcement (no UID mapping) - Integrate Privilege Project with Policy Discovery Services 9 Vikram Reddy Andem, Fermilab Privilege Management June 06, 2006
  • 10. MWSG Meeting, Stanford Linear Accelerator Laboratory Questions ? 10 Vikram Reddy Andem, Fermilab Privilege Management June 06, 2006