Goal

Get recommendations and best practices to operate perfSONAR in a deployment in a secure manner

Background

Following initial discussions regarding scope of the below-mentioned perfSONAR security audit task with GÉANT security team (led by Marcin Wolski) and subsequent discussion within the perfsonar-leads group, the scope has been narrowed down to recommendations and best practices to operate perfSONAR in a deployment in a secure manner. In order to set expectations and agree on a set of acceptance criteria for this task, let us have a meeting during the coming weeks

With over 1400 pS nodes around the world, it is of paramount importance that pS group stay up-to-date on security practices, to ensure continued reliability and robustness pS' operation

Requirements

 The aim of this exercise is to work together to get recommendations for security best practices to operate pS. This includes process, policies and best practices - documentation to operate pS node in secure manner. pS is different from few other software as it is a multi-deployment appliance:

All the above considered - we would like to improve the process, and hence this exercise 

Key actors in the process

RoleName
SDA representative/Lead Developer

Lætitia Antoine Delvaux (Geant) + 3 more SDA from the US side

Andrew Lake (ESNet), Mark Feit (Internet2), Daniel Doyle (IU)

(optionally) SDA for the Lookup Service

Testing manager (SA4 T1)Marcin Wolski + Gerard Frankowski(security)
Product ManagerTrupti Kulkarni (Geant) + 3 other PMs from US

Brian Tierney (ESNet)
Eric Boyd (Internet2)
Jennifer Schopf, Luke Fowler (IU)

SA4/SA2 Activity LeaderMarina Adomeit

Input documents

Documentation on security that I am aware of, I have shared with you previously. Here are those links once again:

Schedule

Communication between the teams

Documentation

Maintenance and updates

Automated management: http://www.perfsonar.net/deploy/automated-management/

Security considerations: http://www.perfsonar.net/deploy/security-considerations/

Different installation packages: http://docs.perfsonar.net/install_options.html , and also Installation procedure.

Deployment map of perfSONAR nodes: http://stats.es.net/ServicesDirectory/  

Vulnerability management process  

Current vulnerability management: http://www.perfsonar.net/deploy/vulnerability-archive/

More information about deployment can be found here: http://www.perfsonar.net/deploy/ , and generic user guide - which may be too detailed and lot of it out of scope for this exercise, but still given here if you have any specific questions - is here: http://docs.perfsonar.net/index.html

Security audit report