prom oting security best practice
play

Prom oting security best practice Rom ain W artel rd EGEE - PowerPoint PPT Presentation

Enabling Grids for E-sciencE Prom oting security best practice Rom ain W artel rd EGEE conference, Athens, 18-22 April 2005 3 www.eu-egee.org W hy? Most sites have sim ilar security issues Heterogeneous groups of system s adm


  1. Enabling Grids for E-sciencE Prom oting security best practice Rom ain W artel rd EGEE conference, Athens, 18-22 April 2005 3 www.eu-egee.org

  2. W hy? • Most sites have sim ilar security issues • Heterogeneous groups of system s adm inistrators • Experience from security incidents is extrem ely useful • Good ideas should be spread am ongst the com m unity Guidelines & best practice should be advertised *BUT* • Inform ation m ust be kept up-to-date • A single source of inform ation is not enough • Maintaining coherent inform ation am ongst m any sites is difficult rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 2

  3. System architecture feedback diffusion Guidelines & best practice repository e-Science Centre rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 3

  4. Authoring m echanism  W eb interface, currently using Serendipity  Using Gridsite authentication (x509 certificates)  Contributions centralized and published by “trusted” people rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 4

  5. Publication m echanism Guidelines & Contributions best practice repository W eb pages M ailing list • The inform ation is published via: – W eb pages – email – RSS feed rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 5

  6. Getting the inform ation on the W eb 1/3 rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 6

  7. Getting the inform ation on the W eb 2/3 rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 7

  8. Getting the inform ation on the W eb 3/3 rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 8

  9. Getting the inform ation via RSS rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 9

  10. Getting the inform ation by em ail rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 10

  11. Current architecture sum m ary • XML based, recognized standard • W idespread technology: m any clients and APIs • Enables injecting security inform ation within existing W ebsites • Enables filtering of the inform ation • Any webm aster can use the feed • Coherent, up-to-date inform ation is available • Design up to W ebm asters, but som e layout can be pushed However: • RSS requires a server-side m echanism • W ebm asters need to trust the authors or perform m anual updates rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 11

  12. Future W e need to: • Provide better, m ore targeted content • Provide a second layer of inform ation, via external W eb pages • Receive contributions from the com m unity • Deploy the m echanism am ongst m ore sites • Im prove the way the inform ation is sorted rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 12

  13. Q&A Questions? rd EGEE Conference, 18-22 April 2005, Athens, Greece 15:07 3 13

Recommend


More recommend