Showing posts with label OGF. Show all posts
Showing posts with label OGF. Show all posts

Tuesday, 19 July 2011

Avoid meaningless pretty pictures

With the OGF science-in-the-cloud SAUCG workshop closing, it is time to reflect on the many interesting presentations, and try to identify common areas, next steps, etc.

How do we best provision resources for scientists? "Cloud" is a buzzword but there are drivers behind the push for it: increasing resource utilisation (maybe), service provision for small customers (the large, from the service provider perspective, being griddy), dynamically catching up with work and coping with the last-minute work prior to a conference. Lots of projects presented interesting stuff - see the slides - and expect an NGS surgery on the topic. To take this forward we now need to look at roadmaps - eg NIST and SIENA - identify gaps etc.

And the award for the quote-of-the-day goes to Etienne Urbah for the title of this post, and for his recommendation that "Passive sentences should be avoided."

PS. If you pronounce SAUCG "sausage" then it's entirely your own fault.

Tuesday, 5 April 2011

Multi-tasking NGS staff

Many people involved in the NGS don't just contribute to our organisation, they contribute to many more. For example our Technical Director, David Wallom who is based at the University of Oxford, is also heavily involved with the OGF as the Vice President of Community.

David recently attended the International Symposium on Grids and Clouds 2011 (ISGC 2011) where he was interviewed by the GridCast team regarding the future of the OGF. If you would like to see the interview video, see the GridCast blog post.

Wednesday, 2 February 2011

Private keys

The point about public key cryptography is that public keys are public: they are used to prove possession of a secret (namely, the private key) without revealing any information about secret. This is called a Zero Knowledge proof. In other words, much of the level of assurance in the infrastructure rests on management (not just protection) of private keys.

So this is why you have all generated your keys and protected them with strong passphrases.

Recently there has been some discussion among the grid CAs as to whether the rules can be relaxed, without lowering the level of assurance too much. Many people generate their keys on systems which are maintained by someone else: e.g. your desktop at work, or maybe even a UI.

This leads to the proposed loosening of the rules, or perhaps a better description of existing practices.

It is likely that in the future, we will support private keys generated by:
  • users themselves, on trusted systems (eg your own machine, or your desktop machine at work)
  • institutions, letting them pre-generate keys for their users (apparently some like to do this);
  • third parties: e.g. running a credential repository like MyProxy.
However, as with much change, it is easy to introduce new rules without fully understanding the problem. There are serious (but fixable) problems with the draft rules. For example, different CAs interpret "third parties" in different ways. Is the CA a third party? I would have thought not. Would the NGS count as a third party, despite the fact that it runs a CA? Probably.

Anyway; the upshot of this is that private key protection rules will be relaxed. What is currently missing is the in-depth understanding of the security aspects of the lifecycle of the private key. I have soapboxed on this topic before. More on this later. Stay tuned.

Monday, 21 June 2010

Keine Hexerei

It was good to see demos at the recent Open Grid Forum (OGF) in Chicago.

There was an OpenNebula deployed platform with associated cloud storage resources. The former used OGF Open Cloud Computing Interface (OCCI), and the latter used the Storage Networking Industry Association's (SNIA) Cloud Data Management Interface (CDMI). If I understood it right. It certainly looked nice. SNIA now have a reference implementation of CDMI - open source, too.

The grid filesystem demo worked fine - until they tried to show the resilience features . But they had a recording of a successful one. Seeing is believing.

In today's griddy and cloudy world, your work is somewhere else. To demonstrate your work to your colleagues, you need to access it. But conference networks may be flaky. Your laptop may suddenly decide to upgrade or virus check itself. You may expect to have a power socket nearby but you don't, and then you run out of battery. Of course you test it the day before but when it really matters, it doesn't work.

Jens' third law of computing: ``A succesful demo is indistinguishable from a rigged one.'' This is well known, of course: Arthur C. Clarke said "any sufficiently advanced technology is indistinguishable from magic."

Of course I am not accusing the successful demonstrators of cheating. They were probably just lucky.

Back in the old days, prestidigitators had to say "Keine Hexerei, nur Behändigkeit" (no witchcraft, only dexterity), to avoid accusations of witchcraft. These days in computing demos it's the other way around: no amount of dexterity alone will make it work, you need some magic or luck as well.

Monday, 15 June 2009

Another good OGF for NGS

OGF26 in Chapel Hill, NC, US, was fairly small by OGF standards, but it was yet another productive one.

It is interesting to have both industry and academic input, because we obviously have different priorities; this has turned out to be a positive outcome of the merger between the then GGF and EGA. Also interesting now is the interaction between the OGF and OGC who themselves have large and diverse communities - I see a potential for lots of fruitful collaborations.

Apart from our very own David Wallom being made VP of e-Research, I was made Area Director for security. This is an interesting challenge which I look forward to. For one thing, there are numerous security related projects building things for the NGS, and being able to chase them about using standards - or creating them when they don't exist - will be useful. Also interestingly, I had been given a grid security shopping list by some industry contacts.
  • The Storage Resource Manager (GSM-WG) made progress with standardisation of SRM 2.2.
  • More talk about digital repositories (more about this later), and a new research group is formed (DR-RG). The iRODS folks are also involved in this (iRODS being the next generation "data grid," SRB being the previous one.)
  • "Cloud" interfaces are now being standardised, slightly unfortunately as "OCCI" (Open Cloud Computing Interface or something to that effect) which is also Oracle's C++ API. As if there were not enough XTLAs (eXtended Three Letter Acronyms).
  • Again a fair number of interoperation activities - since the NGS is not homogeneous, interoperation is relevant to us.
  • More Certification Authority stuff - a whole day of it! - of more later.
It is hard to summarise a whole conference in a few bullet points; it is maybe worth picking out a few items and looking at them in detail in some appropriate forum. As a whole I believe it is good that the NGS is engaged in standardisation and interoperation between the grids.

Monday, 2 March 2009

Hello From Catania

The NGS staff are all here in Catania, Sicily at the EGEE User Forum / OGF 25 / OGF-Europe event. Several of us are currently on the UK and Ireland Federation stand so if you’re here pop by and see us.

Unfortunately most of the NGS material is “still in transit” thanks to the couriers but apparently it should appear today… Fingers crossed. However we do have some very nice NGS t-shirts in several styles to give away! The presentations have started and many sessions are currently underway although apparently many people are only travelling over today.

The weather here is gorgeous at the moment and the lunch being served outside has made the most of this. Coffee and tea has just been served so it’s time to investigate the tea situation. As a non-coffee drinker in Italy, it can sometimes be a struggle!