SURAgrid in-person meeting notes

September 7 & 8, 2005

With updates from discussions in the SURAgrid call that followed

on September 12

September 7 - Install Fest

Many sites came ready to install; some just to learn and observe. Of those installing, some were using the time to get started, with the bonus of the availability of peer support. Others had already made progress in installation but run into questions/problems at particular points. TACC and UVA were available to assist with node/portal presence and cross-certification, respectively. TACC also wanted feedback on features needed for the portal in the future. Note: UNCC, LSU and OleMiss had intended to come to the Install Fest as well as the next-day planning meeting but could not attend due to travel-related fall-out from Hurricane Katrina.

Learning/observing (not installing today):

Here to work on both getting in portal and cross-certifying:

UAB – Intending to update cross-certification and get resources into portal

TACC gave a tour of the portal to start us off, and Jim J. presented basics on cross-certification.

Update from September 12 SURAgrid call:

See slides from Jim for September 8. He had intended to send these for a sanity check before sending to the list but MFY jumped the gun ;-). Please send feedback to Jim if you have comments/changes for this presentation from the meeting.

Feedback on portal:

Feedback on Cross-certification:

Those that had not worked through Bridge CA or portal documentation began by doing that. Those with specific questions worked immediately with Jim, Warren or Ashok (and others that wanted to help).

Results: All but one site that came ready to install are now in the portal, some with 2 different resources: GSU (2), TACC (2), ULL, UKY, UVA, UAB, UArk, TAMU. Also see gridportal.sura.org.

Update from September 12 SURAgrid call:

Sites that are cross-certified are listed at https://www.pki.virginia.edu/nmi-bridge/certs. Currently includes UVA, UAB, TACC, LSU, USC, GSU, with UArk, UMich, TAMU in progress.

Next steps: (MFY thoughts after the meeting)

Update from September 12 SURAgrid call:

Several elements of the table are recorded in other areas/ways now – system specs in the portal, cross-cert status on Jim’s Bridge CA pages, apps info into application description template as they become “real” for running on SURAgried. However, table still provides a useful aggregate view and also a view of things that are in progress. MFY will examine the table for any potential changes, update for references to the portal where applicable and circulate for another update to be posted to the SURAgrid Web site.

Note since the call – this is now done. Copy on SURAgrid Web is the latest one.

September 8 – Project Planning

Grid Building - Facilitated by MFY, input from all

Did not define next steps for this but we need to start work. Would like to discuss immediate next steps in the 9/12 call.

Update from September 12 SURAgrid call:

Formed a working group to discuss the environment variable question (identification as well as potential minimum requirements) and provide a recommendation to the list in the October 10 SURAgrid call. Team will work on its own til then, with MFY providing phone bridge if needed. Group includes: Warren Smith, Ashok Adiga, John-Paul Robinson, Shawn McKee, Victor Bolet, Judith Utley, Jerry Perez.

Decided this would be the subject of a SURAgrid call over the next few weeks, with MFY integrating discussion-to-date into a strawman in advance to kick off discussion.

Update from September 12 SURAgrid call:

We had some additional discussion regarding this and agreed that MFY will draft a strawman for discussion in a (not to far in the) future SURAgrid call.

Update since the call – currently targeting the October 24 call for this discussion

Update from September 12 SURAgrid call:

Targeting late October or later for this discussion, once initial environment variable work is done.

Update from September 12 SURAgrid call:

We re-confirmed that this is still not a high priority and that we should stick with what we have specified to date (pre-Web Globus any version) until the fundamental next steps that have been identified (e.g., env variables, application readiness) are addressed. Will revisit this after the beginning of the next calendar year.

We addressed each of the above together but briefly since we needed to move on to the next topic area. In addition to the technical topics already mentioned, we decided that progress was needed in the following areas over the next few months:

Update from September 12 SURAgrid call:

MFY to work in development of strawman documents and schedule SURAgrid call discussions as noted above. Probably will slip into November vs. October, given other items already identified (prereqs, env. variables). Will begin thinking on timing of in-person meeting right away, possibly in conjunction with one of the SURA Cyberinfrastructure workshops coming up (December 2005, January 2006).

Next Steps in authN/authZ - led by Jim Jokl

Jim worked through the attached presentation, adding notes and action items throughout. Some related details and additional action items are noted below.

Update from September 12 SURAgrid call:

See slides from Jim for September 8. He had intended to send these for a sanity check before sending to the list but MFY jumped the gun ;-). Please send feedback to Jim if you have comments/changes for this presentation from the meeting.

State of SURAgrid policy elements:

Pieces needed:

SURAgrid practice

Best practice

Local CA Certificate Policy

Trust each site in terms of content

Document with content/format something like PKI-Lite

Bridge CA Certificate Policy

Basic practices documented as part of mechanics on Jim’s Web site

Document with content/format based on something like PKI-Lite, or less if needed since Bridge CA is interim

Local CA Certificate Practice

Currently integrated with policy

Covered in PKI-Lite format

Bridge CA Certificate Practice

Currently integrated with policy

Covered in PKI-Lite format

Certificate Profile

 

Recommended profiles at HEPKI

USC, http://www.usc.edu/hpcc/systems/account.php

Update from September 12 SURAgrid call:

MFY will add these to the AUP page as received.

Update from September 12 SURAgrid call:

MFY to work in development of strawman documents and schedule SURAgrid call discussions on governance & charter. Probably will slip to the end of the year given other items identified to address earlier on.

Update from September 12 SURAgrid call:

Will keep this on the list for future discussion but no action yet. Could probably use a simple format for sharing this information a - possibly just aggregating information into a database that can be queried - and it will be important to use GGF Accounting XML group schema for whatever we do.

12:30 – Lunch w/lunch speaker!!!

John-Paul Robinson spoke about one of his latest projects related to Shibboleth and used in conjunction with (among other things) UABgrid authN/authZ: OpenIDP, http://www.openidp.org. More from John-Paul if he wants to send it…

Catalyzing Applications - led by Art Vandenberg

Art – I really lost track of taking notes here since we were skipping around a bit. Please send important points you want “on the record” and I will incorporate them into the notes.

Below are some last minute points we pondered as to why institutions might get/stay involved in SURAgrid, from resource contribution and also application perspectives. Will incorporate these into the Participation documentation mentioned in earlier section on grid-building:

What would help most in getting your resources online?

What would help most in getting your applications online?