{"id":23433,"date":"2020-11-16T16:30:59","date_gmt":"2020-11-16T21:30:59","guid":{"rendered":"https:\/\/www.rc.fas.harvard.edu\/?page_id=23433"},"modified":"2023-07-31T15:40:10","modified_gmt":"2023-07-31T19:40:10","slug":"access-and-authorization","status":"publish","type":"page","link":"https:\/\/www.rc.fas.harvard.edu\/services\/access-and-authorization\/","title":{"rendered":"Access &#038; Authorization"},"content":{"rendered":"\n<h3><b>Description<\/b><span style=\"font-weight: 400;\">\u00a0<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">FASRC provides a number of services including cluster computing, data storage, and virtual machines.\u00a0 Each of these services all share the same FASRC authentication services. \u00a0 As well FASRC works directly with PIs to create various access groups for data and services.\u00a0 A number of common technical components are needed to access the different services, which are detailed below.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Key Features and Benefits <\/b><span style=\"font-weight: 400;\">\u00a0<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">FASRC maintains its own authentication services, which allows it to easily provide collaborators access to these shared services.\u00a0 We are also able to maintain accounts for researchers like grad students and postdocs during their time of transition to a new institution without disruption in access.\u00a0\u00a0\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Definitions:<\/b><\/h3>\n<p><span style=\"font-weight: 400;\"><strong>Active-Directory (AD)<\/strong>:\u00a0 FASRC maintains its own Windows Active Directory service in accordance with HUIT AD security practices for identity management.\u00a0 All information and access on users and groups for all services is maintained in a cluster of domain controllers across all data center sites.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Virtual Private Network (VPN)<\/strong>:\u00a0 A user can run a network client (like Cisco Anyconnect) to connect to a non-local network, which updates its current network routes to effectively join the remote network.\u00a0 FASRC maintains its own separate VPN infrastructure to support remote secure access to storage, VMs, and other services not available to the public network.\u00a0 Separate VPN realms can also be created to further segregate users, which are commonly required when dealing with controlled or confidential data.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Two-factor (2fa)<\/strong>: Authentication beyond just a username and password, both which are static information, is a requirement for increased security.\u00a0 A two-factor token is typically registered to a device and an account, and has a short-term use (30 seconds).\u00a0 All FASRC services require two-factor authentication.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Account Types:<\/b><\/h3>\n<p><span style=\"font-weight: 400;\"><strong>User account<\/strong>:\u00a0 Every person that wants access to FASRC services must have their own unique user account.\u00a0 Each user has a unique user ID (UID) that all UNIX based data and access controls are based upon.\u00a0 The FASRC user account is separate from the HUID based account.\u00a0 Every user is responsible for following <\/span><a href=\"https:\/\/policy.security.harvard.edu\/policies\"><span style=\"font-weight: 400;\">Harvard Information Security Policy<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0 The addition of all non-PI users accounts requires the sponsorship of a PI, as well all closure of user accounts is vetted with the PI.\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Course\/temporary Account<\/strong>:\u00a0 Accounts for courses (or other temporary accounts) are given an expiration upon creation, typically for the duration of the course or other required period of access.\u00a0 Access to the Academic Cluster is controlled through HUIT maintained Canvas instances, and are automatically created.\u00a0 Course\/temporary accounts are separate from a researchers user account and cannot be re-used.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Service account<\/strong>: In the rare occasion an instrument or software needs a single account, we can create a service account.\u00a0 These accounts will never have a home directory and are distinct from user accounts in use and creation.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Administrative Account<\/strong>: \u00a0 Administrative accounts allow a person full control over the systems, network, software, and data, which are needed to provision and continue to maintain the suite of FASRC services. We follow the principle of least privilege access, and thus, a limited number of FASRC staff have administrative access to perform duties as needed for these services.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Lab Group<\/strong>: \u00a0 All PIs (both faculty or non-faculty) will have a logical lab group created in AD.\u00a0 Typically this is named using a standard nomenclature of <\/span><i><span style=\"font-weight: 400;\">pi_lab<\/span><\/i><span style=\"font-weight: 400;\">.\u00a0 In FASRC, all service usage and requests are aggregated under this Lab Group.\u00a0 Users may belong to and collaborate with multiple lab groups, but are tied a single primary group which sponsors them.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Access Group<\/strong>:\u00a0 This is a group of users to control access to resources.\u00a0 This can be in SLURM for computing resources, this can be for restricting access to data folders, this could be for access to VPN or database.\u00a0 For data this group can be given read-access.\u00a0 All changes to access groups require PI approval.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Data Use Agreements (DUA)<\/strong>: Some data providers have extra or specific sets of restrictions upon access of the data.\u00a0 FASRC maintains special access control groups for every DUA.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Portal<\/strong>: FASRC maintains its own <\/span><a href=\"https:\/\/portal.rc.fas.harvard.edu\/\"><span style=\"font-weight: 400;\">portal<\/span><\/a><span style=\"font-weight: 400;\"> to handle a number of the routine business operations like account creation, support requests, storage requests, search for software modules, \u2026\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>PI account<\/strong>:\u00a0 Within the FASRC portal the PI (faculty or non-faculty PI) is the Sponsor that is responsible for approving account requests and access group changes.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><strong>Approver<\/strong>:\u00a0 A PI can designate another research or administrative staff to be the approver for accounts<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Service Expectations and Limits:<\/b><span style=\"font-weight: 400;\">\u202f\u00a0<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">At FASRC, availability, uptime, and backup schedule is provided as best effort with staff that do not have rotating 24\/7\/365 shifts<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Available to:<\/b><span style=\"font-weight: 400;\">\u00a0<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Available to all PIs and their group members at supported Harvard schools: <\/span><a href=\"https:\/\/docs.rc.fas.harvard.edu\/kb\/account-qualifications\/\"><span style=\"font-weight: 400;\">https:\/\/docs.rc.fas.harvard.edu\/kb\/account-qualifications\/<\/span><\/a><\/p>\n<p><span style=\"font-weight: 400;\">All\u00a0access\u00a0requests should follow the direction provided at: x<\/span><\/p>\n<p><a href=\"https:\/\/docs.rc.fas.harvard.edu\/kb\/how-do-i-get-a-research-computing-account\/\"><span style=\"font-weight: 400;\">https:\/\/docs.rc.fas.harvard.edu\/kb\/how-do-i-get-a-research-computing-account\/<\/span><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Service manager:\u00a0<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Service Manager: <a href=\"https:\/\/www.rc.fas.harvard.edu\/about\/people\/maggie-mcfee\/\">Maggie McFee<\/a>, Associate Director of Research Computing Services<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Offerings (Tiers of Service)<\/b><span style=\"font-weight: 400;\">\u00a0<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">FASRC Account (non-cluster) - No cluster login access, mainly used for access to services such as instruments or for storage-only access<\/span><\/p>\n<p><span style=\"font-weight: 400;\">FASRC Cluster Account - An account for which cluster login and job submission is also enabled<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Course-specific temporary accounts - Provides temporary access for users to the cluster or other FASRC services<\/span><\/p>\n<p><span style=\"font-weight: 400;\">FAS Science Core Facilities access - Integration with core facilities Instrument Sign-up and utilization<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Self-Service signup and approval - The FASRC Portal allows users and PIs access to manage some portions of their or their lab members\u2019 access<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p class=\"lead\">Description\u00a0 FASRC provides a number of services including cluster computing, data storage, and virtual machines.\u00a0 Each of these services all share the same FASRC authentication services. \u00a0 As well FASRC works directly with PIs to create various access groups for data and services.\u00a0 A number of common technical components are needed to access the different services, which are detailed below.&hellip;<\/p>\n<p class=\"more-link-p\"><a class=\"btn btn-primary\" href=\"https:\/\/www.rc.fas.harvard.edu\/services\/access-and-authorization\/\">Read more<\/a><\/p>\n","protected":false},"author":111,"featured_media":0,"parent":8926,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"categories":[156],"tags":[],"class_list":["post-23433","page","type-page","status-publish","hentry","category-services"],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/P42YvN-65X","_links":{"self":[{"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/pages\/23433","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/users\/111"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/comments?post=23433"}],"version-history":[{"count":5,"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/pages\/23433\/revisions"}],"predecessor-version":[{"id":24878,"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/pages\/23433\/revisions\/24878"}],"up":[{"embeddable":true,"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/pages\/8926"}],"wp:attachment":[{"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/media?parent=23433"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/categories?post=23433"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/tags?post=23433"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}