# \#security

**URL:** https://ask.cyberinfrastructure.org/tag/security/102.md

[Latest](https://ask.cyberinfrastructure.org/latest.md) · [Categories](https://ask.cyberinfrastructure.org/categories.md) · [Tags](https://ask.cyberinfrastructure.org/tags.md)

---

## [DUO for Multi-Factor Authentication on HPC Systems](https://ask.cyberinfrastructure.org/t/duo-for-multi-factor-authentication-on-hpc-systems/268)

<div class="topic-metadata">

**Author:** [@toreliza](https://ask.cyberinfrastructure.org/u/toreliza)\
**Replies:** 10\
**Last updated:** [March 14, 2023, 6:45pm UTC](https://ask.cyberinfrastructure.org/t/duo-for-multi-factor-authentication-on-hpc-systems/268 "2023-03-14T18:45:25Z")

</div>

We’re planning to implement multi-factor authentication (DUO specifically) on our HPC systems. It seems like it should be relatively straight-forward if user authentication at login (via the head/login nodes) is the onl…

---

## [Directory or file-level permissions on OSN s3 buckets](https://ask.cyberinfrastructure.org/t/directory-or-file-level-permissions-on-osn-s3-buckets/2352)

<div class="topic-metadata">

**Author:** [@pibion](https://ask.cyberinfrastructure.org/u/pibion)\
**Replies:** 4\
**Last updated:** [September 30, 2022, 8:22pm UTC](https://ask.cyberinfrastructure.org/t/directory-or-file-level-permissions-on-osn-s3-buckets/2352 "2022-09-30T20:22:04Z")

</div>

It would be nice to have sub-bucket permissions on s3 storage (specifically the OSN). This seems impossible given the flat storage model, but I thought I would ask here! Here is the use case I have in mind: We have di…

---

## [Security Compliance Analyst at UCSF School of Medicine](https://ask.cyberinfrastructure.org/t/security-compliance-analyst-at-ucsf-school-of-medicine/2371)

<div class="topic-metadata">

**Author:** [@jamie.lam](https://ask.cyberinfrastructure.org/u/jamie.lam)\
**Replies:** 0\
**Last updated:** [June 2, 2022, 6:49pm UTC](https://ask.cyberinfrastructure.org/t/security-compliance-analyst-at-ucsf-school-of-medicine/2371 "2022-06-02T18:49:27Z")

</div>

UCSF School of Medicine is hiring a Security Compliance Analyst to help us develop and launch our Research Security Program. We are looking for a candidate passionate about supporting researchers and gaining experience i…

---

## [Protecting files on an s3 bucket from deletion](https://ask.cyberinfrastructure.org/t/protecting-files-on-an-s3-bucket-from-deletion/2353)

<div class="topic-metadata">

**Author:** [@pibion](https://ask.cyberinfrastructure.org/u/pibion)\
**Replies:** 3\
**Last updated:** [May 19, 2022, 3:54pm UTC](https://ask.cyberinfrastructure.org/t/protecting-files-on-an-s3-bucket-from-deletion/2353 "2022-05-19T15:54:11Z")

</div>

I am storing data for my collaboration on OSN, an s3 data store. This has worked great for access, but it’s very easy for anyone with the access credentials to accidentally delete a lot of data. We have quite a few peo…

---

## [What sort of approaches work well for providing encrypted storage for research computing environments?](https://ask.cyberinfrastructure.org/t/what-sort-of-approaches-work-well-for-providing-encrypted-storage-for-research-computing-environments/105)

<div class="topic-metadata">

**Author:** [@KrisP](https://ask.cyberinfrastructure.org/u/KrisP)\
**Replies:** 1\
**Last updated:** [May 10, 2019, 3:01pm UTC](https://ask.cyberinfrastructure.org/t/what-sort-of-approaches-work-well-for-providing-encrypted-storage-for-research-computing-environments/105 "2019-05-10T15:01:48Z")

</div>

Research groups often have data that is in some way sensitive, for example, data containing gambling information, data containing educational interventions (concerns minors), or medical data. For example a state agency m…

---

## [What is the correct procedure for setting ssh keys up to interface with github and servers outside of the campus cluster?](https://ask.cyberinfrastructure.org/t/what-is-the-correct-procedure-for-setting-ssh-keys-up-to-interface-with-github-and-servers-outside-of-the-campus-cluster/857)

<div class="topic-metadata">

**Author:** [@aculich](https://ask.cyberinfrastructure.org/u/aculich)\
**Replies:** 1\
**Last updated:** [April 21, 2019, 12:36am UTC](https://ask.cyberinfrastructure.org/t/what-is-the-correct-procedure-for-setting-ssh-keys-up-to-interface-with-github-and-servers-outside-of-the-campus-cluster/857 "2019-04-21T00:36:55Z")

</div>

We have our own small research group small cluster called groupcluster, but we have also begun using the main shared campus cluster. Sometimes we ssh into our groupcluster from the campus cluster, but we also want to use…

---

## [InCommon Federation for HPC Clusters](https://ask.cyberinfrastructure.org/t/incommon-federation-for-hpc-clusters/125)

<div class="topic-metadata">

**Author:** [@syockel](https://ask.cyberinfrastructure.org/u/syockel)\
**Replies:** 2\
**Last updated:** [November 19, 2018, 3:05pm UTC](https://ask.cyberinfrastructure.org/t/incommon-federation-for-hpc-clusters/125 "2018-11-19T15:05:40Z")

</div>

What is the InCommon Federation and how can I use it to simplify authentication and access control for an HPC Cluster?
