IPv4 network addresses are running out and the deployment of IPv6 networking in many places is now well underway. Following the work of the HEPiX IPv6 Working Group, a growing number of sites in the Worldwide Large Hadron Collider Computing Grid (WLCG) are deploying dual-stack IPv6/IPv4 services. The aim of this is to support the use of IPv6-only clients, i.e. worker nodes, virtual machines or containers. The IPv6 networking protocols while they do contain features aimed at improving security also bring new challenges for operational IT security. The lack of maturity of IPv6 implementations together with the increased complexity of some of the protocol standards raise many new issues for operational security teams. The HEPiX IPv6 Working Group is producing guidance on best practices in this area. This paper considers some of the security concerns for WLCG in an IPv6 world and presents the HEPiX IPv6 working group guidance for the system administrators who manage IT services on the WLCG distributed infrastructure, for their related site security and networking teams and for developers and software engineers working on WLCG applications.
The fraction of Internet traffic carried over IPv6 continues to grow rapidly. IPv6 support from network hardware vendors and carriers is pervasive and becoming mature. A network infrastructure upgrade often offers sites an excellent window of opportunity to configure and enable IPv6.
The world is rapidly running out of IPv4 addresses; the number of IPv6 end systems connected to the internet is increasing; WLCG and the LHC experiments may soon have access to worker nodes and/or virtual machines (VMs) possessing only an IPv6 routable address. The HEPiX IPv6 Working Group has been investigating, testing and planning for dual-stack services on WLCG for several years. Following feedback from our working group, many of the storage technologies in use on WLCG have recently been made IPv6-capable. This paper presents the IPv6 requirements, tests and plans of the LHC experiments together with the tests performed on the group’s IPv6 test-bed. This is primarily aimed at IPv6-only worker nodes or VMs accessing several different implementations of a global dual-stack federated storage service. Finally the plans for deployment of production dual-stack WLCG services are presented.
The HEPiX (http: //www.hepix.org) IPv6 Working Group has been investigating the many issues which feed into the decision on the timetable for the use of IPv6 (http://www.ietf.org/rfc/rfc2460.txt) networking protocols in High Energy Physics (HEP) Computing, in particular in the Worldwide Large Hadron Collider (LHC) Computing Grid (WLCG). RIPE NCC, the European Regional Internet Registry (RIR), ran out of IPv4 addresses in September 2012. The North and South America RIRs are expected to run out soon. In recent months it has become more clear that some WLCG sites, including CERN, are running short of IPv4 address space, now without the possibility of applying for more. This has increased the urgency for the switch-on of dual-stack IPv4/IPv6 on all outward facing WLCG services to allow for the eventual support of IPv6-only clients. The activities of the group include the analysis and testing of the readiness for IPv6 and the performance of many required components, including the applications, middleware, management and monitoring tools essential for HEP computing. Many WLCG Tier 1/2 sites are participants in the group's distributed IPv6 testbed and the major LHC experiment collaborations are engaged in the testing. We are constructing a group web/wiki which will contain useful information on the IPv6 readiness of the various software components and a knowledge base (http://hepix-ipv6.web.cern.ch/knowledge-base). This paper describes the work done by the working group and its future plans.
Identifying technology-agnostic requirements from an ever-evolving Federated Identity Management (FIM) landscape, which has shifted from its original conception of an arrangement that allows subscribers from multiple organisations to use the same identi!cation data to obtain access to the secured resources of all organisations in the group, to an ecosystem which now comprises an increasing variety of technologies provided by participating organisations.
The start-up of the Large Hadron Collider (LHC) at CERN, Geneva, presents a huge challenge in processing and analysing the vast amounts of scientific data that will be produced. The architecture of the worldwide grid that will handle 15 PB of particle physics data annually from this machine is based on a hierarchical tiered structure. We describe the development of the UK component (GridPP) of this grid from a prototype system to a full exploitation grid for real data analysis. This includes the physical infrastructure, the deployment of middleware, operational experience and the initial exploitation by the major LHC experiments.
GridPP is a 33m pound, 6-year project funded by PPARC that aims to establish a Grid for UK Particle Physics in time for the turn on of the CERN Large Hadron Collider (LHC) in 2007. Over the last three years, a prototype Grid has been developed and put into production with computational resources that have increased by a factor of 100. GridPP is now about halfway through its second phase, the move from prototype to production is well underway though many challenges remain.
The GridPP Collaboration is building a UK computing Grid for particle physics, as part of the international effort towards computing for the Large Hadron Collider. The project, funded by the UK Particle Physics and Astronomy Research Council (PPARC), began in September 2001 and completed its first phase 3 years later. GridPP is a collaboration of approximately 100 researchers in 19 UK university particle physics groups, the Council for the Central Laboratory of the Research Councils and CERN, reflecting the strategic importance of the project. In collaboration with other European and US efforts, the first phase of the project demonstrated the feasibility of developing, deploying and operating a Grid-based computing system to meet the UK needs of the Large Hadron Collider experiments. This note describes the work undertaken to achieve this goal.
We study the polarizations with respect to the normal to the production plane for a very clean sample of 27217 LAMBDA0/LAMBDA0BAR hyperons produced in 230 GeV/c pi--Cu interactions. In general we find P(LAMBDA0) almost-equal-to P(LAMBDA0BAR) almost-equal-to 0 except for x(F) > 0, p(T) > 1 GeV/c where P(LAMBDA(0)) = -0.28 +/- 0.09(stat.) +/- 0.02(syst.).
In the CERN NA32 experiment a high-resolution silicon vertex detector and a purely topological approach were used to collect 557 events consistent with associated charm production, both decay vertices being observed. The pseudorapidity gap distribution appears to be nearly independent of the nature of the charmed hadrons. This distribution is reasonably consistent with the next-to-leading order QCD calculations. However the azimuthal-angle distribution is significantly broader than the above predictions.
In the CERN NA32 experiment a high-resolution silicon vertex detector and a purely topological approach were used to collect a clean sample of A(c)+ decays into pK-pi+ with or without additional neutral particles. We study the subresonant structure of the LAMBDA(c)+ peak obtaining BR (LAMBDA(c)+ --> pKBAR*0(892)) = 0.35(-0.07)0.06 +/-0.03 with respect to the total LAMBDA(c)+ --> pK-pi+ decay. We also determine branching ratios for some channels with neutral decay products, namely BR(LAMBDA(c)+ --> pK-pi+pi0)=0.73+/-0.12+/-0.05 and BR(LAMBDA(c)+ --> pK-pi+pi0pi0)=0.16+/-0.07+/-0.03, again with respect to the total LAMBDA(c)+ --> pK-pi+decay.
In the CERN NA32 experiment a high-resolution silicon vertex detector and a purely topological approach were used to collect 557 events consistent with associated charm production, both decay vertices being observed. The pseudorapidity gap distribution appears to be nearly independent of the nature of the charmed hadrons. This distribution is reasonably consistent with the next-to-leading order QCD calculations. However the azimuthal-angle distribution is significantly broader than the above predictions.
In the CERN NA32 experiment a high-resolution silicon vertex detector and a purely topological approach were used to collect a clean sample of λ+c decays into pK−π+ with or without additional neutral particles. We study the subresonant structure of the λc+ peak obtaining BR(λc+ → pK∗0(892)) = 0.35−0.07+0.06±0.03 with respect to the total λc+ → pK−π+ decay. We also determine branching ratios for some channels with neutral decay products, namely BR(λc+ → pK−π+π0) = 0.73±0.12±0.05 and BR(λc+ → pK−π+π0π0 = 0.16±0.07±0.03, again with respect to the total λc+ → pK−π+ decay.
Using a high-resolution silicon vertex detector we have observed a very clean signal of 127 D∗+. After a careful study of the experimental resolution of our apparatus we have measured m(D∗++)−m(D0) = 145.39±0.06±0.03 MeV. We have also obtained a 90% CL upper limit to γ(D∗+) of 131 keV.
Using data from the NA32 experiment at CERN we have studied the Λ+c decays containing a Σ+ among the decay products. The interactions of 230 GeV π− with a Cu target were analysed using a precise vertex telescope (charge-coupled devices and silicon microstrip detectors) and the ACCMOR spectrometer. We have found eleven Λ+c→Σ+π+π−, one Λ+c→Σ+K+K−, two Λ+c→Σ+K+π− and one Λ+c→Σ+π+π−π+π− decays practically without any backgroun d. We have measured the branching ratios with respect to the Λ+c→pK−π+ channel.
We combine highly complementary information on branching fractions of charmed mesons D0, D+ and D(s)+ coming from two experiments both yielding double-charm samples. The NA32 experiment provided exclusive branching fractions for channels with at least two charged decay products while a recent Mark III paper provides results on inclusive charm decay properties. The knowledge of channels with K0's in the former is used to recalculate the charged multiplicity distribution in the latter. We obtain [n(ch)] = 2.25 +/- 0.08 for D0, [n(ch)] = 1.96 +/- 0.08 for D+ and [n(ch)] = 2.41 +/- 0.38 for D(s)+. In tum the knowledge of the charged multiplicity improves the overall normalization of exclusive branching fractions. This reanalysis yields model-independent results for charmed mesons. In particular we obtain branching fractions for 16 D(s)+ decay channels including BF(D(s)+ --> phi-pi+) = (4.4(-1.8)+2.3)%.
We have studied the hadronic production of charmed mesons in the NA 32 experiment at CERN. A special trigger together with a high resolution vertex detector consisting of charge coupled devices and silicon microstrip detectors allowed the selection of very clean samples of charmed mesons. We have collected 852 fully reconstructed decays: 60D s + →K+K−π+, 543D°→K−π+ andK−π+π−π+ as well as 249D+→K−π+π+ (or charge conjugate). 147 mesons out of our\({{D^0 } \mathord{\left/ {\vphantom {{D^0 } {\bar D^0 }}} \right. \kern-\nulldelimiterspace} {\bar D^0 }}\) sample were produced via chargedD* state. For all charmed mesons we determine the total production cross-section and study thex F andp t 2 distributions.
We have studied the hadronic production of charmed mesons in the NA 32 experiment at CERN. A special trigger together with a high resolution vertex detector consisting of charge coupled devices and silicon microstrip detectors allowed the selection of very clean samples of charmed mesons. We have collected 852 fully reconstructed decays: 60 D(s)+ --> K+ K- pi+, 543 D0 --> K- pi+ and K- pi+ pi- pi+ as well as 249 D+ --> K- pi+ pi+ (or charge conjugate). 147 mesons out of our D0/DBAR0 sample were produced via charged D* state. For all charmed mesons we determine the total production cross-section and study the x(F) and p(t)2 distributions.