Enabling Grids for E-sciencE Prom oting security best practice Rom ain W artel rd EGEE conference, Athens, 18-22 April 2005 3 www.eu-egee.org
W hy? • Most sites have sim ilar security issues • Heterogeneous groups of system s adm inistrators • Experience from security incidents is extrem ely useful • Good ideas should be spread am ongst the com m unity Guidelines & best practice should be advertised *BUT* • Inform ation m ust be kept up-to-date • A single source of inform ation is not enough • Maintaining coherent inform ation am ongst m any sites is difficult rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 2
System architecture feedback diffusion Guidelines & best practice repository e-Science Centre rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 3
Authoring m echanism W eb interface, currently using Serendipity Using Gridsite authentication (x509 certificates) Contributions centralized and published by “trusted” people rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 4
Publication m echanism Guidelines & Contributions best practice repository W eb pages M ailing list • The inform ation is published via: – W eb pages – email – RSS feed rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 5
Getting the inform ation on the W eb 1/3 rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 6
Getting the inform ation on the W eb 2/3 rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 7
Getting the inform ation on the W eb 3/3 rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 8
Getting the inform ation via RSS rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 9
Getting the inform ation by em ail rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 10
Current architecture sum m ary • XML based, recognized standard • W idespread technology: m any clients and APIs • Enables injecting security inform ation within existing W ebsites • Enables filtering of the inform ation • Any webm aster can use the feed • Coherent, up-to-date inform ation is available • Design up to W ebm asters, but som e layout can be pushed However: • RSS requires a server-side m echanism • W ebm asters need to trust the authors or perform m anual updates rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 11
Future W e need to: • Provide better, m ore targeted content • Provide a second layer of inform ation, via external W eb pages • Receive contributions from the com m unity • Deploy the m echanism am ongst m ore sites • Im prove the way the inform ation is sorted rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 12
Q&A Questions? rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 13
Recommend
More recommend