It's gone a bit quiet over here at the NGS blog lately mainly because I was completely caught up in writing a bid which took over my life for a few weeks. As it was all I did for a couple of weeks I didn't have much to blog about. Hopefully the bid will be successful and we'll have some exciting news for you in the near future!
Apart from that I have been working with colleagues at SSI in preparation for their Collaborations Workshop which will take place on the 21st - 22nd of March. There has been a great response with maximum attendance and a great range of people attending. One of the purposes of the workshop is to get researchers and software engineers working networking to find where they can help each other out. There aren't many conferences out there where the aim is to get everyone talking to each other all day instead of just a few people doing the talking!
In completely different news I just posted an article to the NGS website from EGI. The EGI are showcasing their users research much the same as the NGS user case studies do (wonder where they got the idea from...?). They are doing their case studies in the form of video interviews and the first one focuses on the research of Henry Hocking of the CONCO project who used the grid to analyse naturally occurring molecules in venoms used by marine snails to immobilise their prey. You never would have guessed that one!
Thursday, 8 March 2012
Tuesday, 14 February 2012
On email addresses in distinguished names
Those of you who are sysadmins know we have email addresses in host certificates, in their distinguished names (DNs). The origin of this decision is lost in the mists of time - it certainly pre-dates the UK e-Science CA - I seem to remember something about host certificates being used as clients and the email address of the contact appearing in the log file, as a forerunner of "robot" certificates - which can't quite be right because initially we did not give host certificates client extensions. But hosts have been used in this way to implement portals.
In any case, the practice is now deprecated, mainly because much of our software (strictly speaking incorrectly) depends on the string representation of the DN, and different software stringifies emailaddress in different ways. We have been meaning to get rid of it for a while, waiting only for some code changes and an update to the policy.
In fact the policy needs updating because in a (very small) number of cases we are doing things that are not consistent with the policy - but which are nonetheless wholly consistent with IGTF. Actually the only examples I can think of is that we have permitted two "software robots," a practice which is permitted by IGTF now but wasn't when our policy was written.
The proposal is now that we remove email addresses from DNs, before the policy rewrite is finished (its about 2/3 done since you ask.) Removing email addresses is clearly consistent with IGTF, but deviates from our historical practice of preserving the end entity DN across all generations of CA certificates. Having an out of date policy is of course not consistent with IGTF...
The trouble is, how do we know whether people depend on the email address in the DN? We have no way of knowing how the certificates are being used. Of course we could take the approach that if the certificate is being used for unsupported purposes, then you're on your own. OTOH, we have usually strived not to do that, even if grid software makes that quite difficult (see GFD.125 again, or every rollover).
So we need to leave it to the "owner" of the certificate to decide. The easiest way of doing this is JK's proposal, that we remove email address from new certificates, but keep them on renewal. For host certificates, getting a new certificate is often the same amount of work as a renewal. Existing certificates are not affected but if you want your certificate to be affected you could revoke it and get a new one.
And of course all this applies only to hosts, there is no change for personal certificates.
Friday, 10 February 2012
Bits and pieces
It's been one of those weeks with a lot of bits and pieces going on. Busy and varied is how I'd probably sum it up!Tuesday was the NGS Collaboration Board meeting which was held at the University of Birmingham thanks to the kind hospitality of Paul Hatton. The theme of the meeting was reaching out and engaging with potential new communities and existing user communities. Mike Jones gave a presentation on SaRONGS to show how we are making it easier for people to access grid resources and I gave a presentation on the Campus and Community Champions networks. Following on neatly from my presentation was Rebecca Notman who is one of our Community Champions. Rebecca spoke about her role and how the NGS has played a part in her research. There was also plenty of time for discussion with each of our Collaboration Board members updating us on new and activities from their institutions. It seems to be a busy time in the world of research computing!
Wednesday was the next seminar in our short series. This time it was the turn of John Kewley from STFC Daresbury who is the NGS helpdesk manager. After a few technical issues, John spoke about the Certificate Wizard - a tool that the NGS produced to help people manage their grid certificate more easily and it seems to have worked. There have been less helpdesk queries regarding certificates since the introduction of the tool.
Yesterday morning I took part in the steering group for the forthcoming Software Sustainability Institute Collaboration Workshop. This is always a really enjoyable conference as it's 2 days of full interactive discussion and networking. If you go to a conference to get peace and quiet to read your email then this isn't for you! Every session is a group discussion session apart from when the groups report back to the conference as a whole. There are some really interesting topics for discussion this year, all of which have been suggested by the attending delegates. If you would like to attend and you are a software developer then have a look at this as you may be able to get a free place and a contribution towards your expenses.
Thursday, 2 February 2012
One down two to go
Yesterday saw the first presentation in our short seminar series concentrating on the recent developments in the UK for accessing and managing grid resources.I'm pleased (and relieved!) to say that it went well with Mike Jones from the University of Manchester giving a presentation on "Shibboleth Access to Resources on the NGS". We had 28 individuals join us on Evo from all over the world including Russia, Italy, USA and Switzerland. It was good to see that our seminar was of interest to people internationally as well.
The next seminar will take place on Wednesday 8th Feb at 10.30am (GMT) and will be looking at the Certificate Wizard which makes it easier for users to manage their certificates. If you would like to take part in the seminar either by Access Grid or Evo then please see the event listing on our website. You can also RSVP on our Facebook event page.
The seminars have been recorded and it is our aim to have these recordings available on the NGS website at the end of the seminar series.
Thursday, 26 January 2012
Interested in accessing and managing grid resources?
If so then read on!
The NGS is hosting a short but sweet seminar series starting next Wednesday (1st Feb). There will be 3 seminars over the 3 weeks each lasting approximately 30 minutes and the best thing about them is that you can join in no matter where you are - all you need is the internet!
We wanted to make the seminars as open to everyone as we possibly could and, after some deliberation, we decided to use the Evo technology. This is free for everyone to use - all you have to do is to register and I recommend doing this at least the day before. This isn't anything to do with Evo's registration process more that it took several hours for my university email system to allow my confirmation email through...
So what are the topics that we will be discussing?
1st February - Shibboleth Access to Resources on the NGS – Mike Jones, NGS, University of Manchester
This talk will demonstrate how it is possible to access and use NGS resources using institutional login credentials (via the UK Access Management Federation). It will describe how the UK's two main e-Science authentication systems are combined to form an easy to use yet robust identity management environment. It will discuss how this mechanism links together with system, project and Virtual Organisation (VO) registration procedures.
8th February - Certificate Management in the UK - John Kewley, NGS, STFC Daresbury Laboratory
The NGS helpdesk receives many tickets relating to certificates (and certificate renewal in particular): largely due to browser incompatibilities. In order to tackle this problem, the NGS has devised CertWizard which is a browser-independent certificate tool. The presentation will give an introduction to the UK e-Science CA, which has issued over 30,000 certificates, and its associated software and interfaces, including CertWizard.
It will show how modernisations are being made at various stages of the certificate lifecycle, making it easier than ever for users to manage their e-Science Certificate.
15th February - Moonshot - next generation federated identity - Josh Howlett, JANET
Federated identity yields significant benefits for users and services by increasing the usability of services, reducing identity management costs and improving regulatory compliance.
A number of different technical strategies for federating identity have emerged during the past decade, with differing levels of success. These technologies address different types of use case, resulting in significant complexity for both users, services and trust infrastructure providers.
This complexity impedes the adoption of services and increasing operational costs. Moreover, there are many use cases where these technologies do not provide a solution.
Project Moonshot is an ambitious Janet-led initiative, building on existing deployed technologies, that aim to develop a single unified and standardised approach that satisfies all of the authentication and authorisation requirements of the education & research community. Much of the technology has now been implemented, and is now being tested within the Janet Moonshot Technology Pilot.
This presentation will provide an overview of some of the motivating use cases for Moonshot and an overview of the technology and the implementation.
Full details of how to join the seminars are available on the NGS website event page but if you have any queries then please contact the helpdesk and we will do our utmost to help you join in.
The NGS is hosting a short but sweet seminar series starting next Wednesday (1st Feb). There will be 3 seminars over the 3 weeks each lasting approximately 30 minutes and the best thing about them is that you can join in no matter where you are - all you need is the internet!
We wanted to make the seminars as open to everyone as we possibly could and, after some deliberation, we decided to use the Evo technology. This is free for everyone to use - all you have to do is to register and I recommend doing this at least the day before. This isn't anything to do with Evo's registration process more that it took several hours for my university email system to allow my confirmation email through...
So what are the topics that we will be discussing?
1st February - Shibboleth Access to Resources on the NGS – Mike Jones, NGS, University of Manchester
This talk will demonstrate how it is possible to access and use NGS resources using institutional login credentials (via the UK Access Management Federation). It will describe how the UK's two main e-Science authentication systems are combined to form an easy to use yet robust identity management environment. It will discuss how this mechanism links together with system, project and Virtual Organisation (VO) registration procedures.
8th February - Certificate Management in the UK - John Kewley, NGS, STFC Daresbury Laboratory
The NGS helpdesk receives many tickets relating to certificates (and certificate renewal in particular): largely due to browser incompatibilities. In order to tackle this problem, the NGS has devised CertWizard which is a browser-independent certificate tool. The presentation will give an introduction to the UK e-Science CA, which has issued over 30,000 certificates, and its associated software and interfaces, including CertWizard.
It will show how modernisations are being made at various stages of the certificate lifecycle, making it easier than ever for users to manage their e-Science Certificate.
15th February - Moonshot - next generation federated identity - Josh Howlett, JANET
Federated identity yields significant benefits for users and services by increasing the usability of services, reducing identity management costs and improving regulatory compliance.
A number of different technical strategies for federating identity have emerged during the past decade, with differing levels of success. These technologies address different types of use case, resulting in significant complexity for both users, services and trust infrastructure providers.
This complexity impedes the adoption of services and increasing operational costs. Moreover, there are many use cases where these technologies do not provide a solution.
Project Moonshot is an ambitious Janet-led initiative, building on existing deployed technologies, that aim to develop a single unified and standardised approach that satisfies all of the authentication and authorisation requirements of the education & research community. Much of the technology has now been implemented, and is now being tested within the Janet Moonshot Technology Pilot.
This presentation will provide an overview of some of the motivating use cases for Moonshot and an overview of the technology and the implementation.
Full details of how to join the seminars are available on the NGS website event page but if you have any queries then please contact the helpdesk and we will do our utmost to help you join in.
Thursday, 19 January 2012
It's that time of year again...
My inbox seems to be full of emails regarding conference calls for papers, early bird registrations, conference deadlines etc. Yes it's conference preparation season and its in full swing!
I received confirmation today that I'll be giving a paper at the forthcoming EGI Community Forum on our champions networks. I'll be talking about both our Campus and Community champion networks and how we work with each other to promote e-infrastructure in the UK. Several other NGS staff have also had papers accepted on topics including "Linking Authenticating and Authorising Infrastructures in the UK NGI (SARoNGS)" (Mike Jones) and "Tweaking the Certificate Lifecycle for the UK eScience CA" (John Kewley).
Also in my inbox this week was an announcement from the Software Sustainability Institute (SSI) announcing that registration for their Collaboration Workshop 2012 (CW) is now open. This is on of my favourite events as, unlike most conferences, you don't sit passively listening. The CW consists of breakout groups where you discuss topics submitted by the attendees and there's always one of interest to me in every session. After the discussion a member of the break out group volunteers to report back to the CW as a whole. This means that you get to hear what all the other break out groups were talking about and you can still feedback on their outcomes as well.
It's a really lively meeting and you leave after 2 days feeling tired but feeling that you've achieved something worthwhile! It's also a great place for networking with new people as there are researchers from a wide variety of research areas, IT people, community support people and people like myself who represent national initiatives. To see some of the topics already suggested for discussion visit the event website.
I received confirmation today that I'll be giving a paper at the forthcoming EGI Community Forum on our champions networks. I'll be talking about both our Campus and Community champion networks and how we work with each other to promote e-infrastructure in the UK. Several other NGS staff have also had papers accepted on topics including "Linking Authenticating and Authorising Infrastructures in the UK NGI (SARoNGS)" (Mike Jones) and "Tweaking the Certificate Lifecycle for the UK eScience CA" (John Kewley).
Also in my inbox this week was an announcement from the Software Sustainability Institute (SSI) announcing that registration for their Collaboration Workshop 2012 (CW) is now open. This is on of my favourite events as, unlike most conferences, you don't sit passively listening. The CW consists of breakout groups where you discuss topics submitted by the attendees and there's always one of interest to me in every session. After the discussion a member of the break out group volunteers to report back to the CW as a whole. This means that you get to hear what all the other break out groups were talking about and you can still feedback on their outcomes as well.
It's a really lively meeting and you leave after 2 days feeling tired but feeling that you've achieved something worthwhile! It's also a great place for networking with new people as there are researchers from a wide variety of research areas, IT people, community support people and people like myself who represent national initiatives. To see some of the topics already suggested for discussion visit the event website.
Thursday, 12 January 2012
Just incase you missed it....
A new edition of the quarterly NGS newsletter was released in December so if you missed it in the pre-Christmas rush, now is a chance to catch up!
This edition featured articles on -
This edition featured articles on -
- the adoption of Globus Online by the NGS
- NGS involvement in the EGI Federated Cloud Task Force and the benefits for NGS users
- NGS user case study - Scalable Road Traffic Monitoring using Grid Computing
- ...and more!
Subscribe to:
Posts (Atom)