myproxy nmi integration
Download
Skip this Video
Download Presentation
MyProxy NMI Integration

Loading in 2 Seconds...

play fullscreen
1 / 12

MyProxy NMI Integration - PowerPoint PPT Presentation


  • 93 Views
  • Uploaded on

MyProxy NMI Integration. Jim Basney, NCSA Marty Humphrey, University of Virginia http://myproxy.ncsa.uiuc.edu/. MyProxy is an online repository for grid credentials. Secure credential storage Convenient credential access Flexible credential management. Examples of MyProxy in use:.

loader
I am the owner, or an agent authorized to act on behalf of the owner, of the copyrighted work described.
capcha
Download Presentation

PowerPoint Slideshow about ' MyProxy NMI Integration' - cargan


An Image/Link below is provided (as is) to download presentation

Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author.While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server.


- - - - - - - - - - - - - - - - - - - - - - - - - - E N D - - - - - - - - - - - - - - - - - - - - - - - - - -
Presentation Transcript
myproxy nmi integration

MyProxy NMI Integration

Jim Basney, NCSA

Marty Humphrey, University of Virginia

http://myproxy.ncsa.uiuc.edu/

myproxy is an online repository for grid credentials
MyProxy is an online repository for grid credentials.
  • Secure credential storage
  • Convenient credential access
  • Flexible credential management
credential mobility
Credential mobility:

Obtain certificate

tg-login.ncsa.teragrid.org

ca.ncsa.uiuc.edu

Store proxy

myproxy.teragrid.org

tg-login.caltech.teragrid.org

Retrieve proxy

tg-login.sdsc.teragrid.org

tg-login.uc.teragrid.org

grid portals
Grid portals:

MyProxy server

CHEF portal

Fetch proxy

Login

GridFTP server

Access data

proxy renewal
Proxy renewal:

Globus

gatekeeper

Workload management system

Submit job

Submit job

Refresh proxy

MyProxy server

Fetch proxy

long term credential storage
Long-term credential storage:

Certificate authority

Accounting system

Obtain user’s

certificate

Request account

Username, password

Load user’s

credentials

MyProxy server

Retrieve proxy

Change password

nmi integration
NMI integration:
  • MyProxy included in NMI R3 & R4
  • Packaged with GPT
  • Uses Globus Toolkit security libraries
  • Used by NMI components:
    • OGCE NMI portal
    • Condor-G

www.ogce.org

myproxy ogsi implementation
MyProxy OGSI implementation:
  • Initial release this month for GT 3.0
  • Designed to leverage OGSI functionality

CredentialManagerFactory

CredentialManager Instance

CredentialManager Instance

hardware secured myproxy
Hardware-secured MyProxy:

M. Lorch, J. Basney, and D. Kafura, "A Hardware-secured Credential Repository for Grid PKIs," 4th IEEE/ACM International Symposium on Cluster Computing and the Grid, April 2004.

MyProxy Server

IBM 4758

Proxy request

Retrieve proxy

Proxy certificate

ongoing work
Ongoing work:
  • Continued OGSA development
  • Credential access control (XACML, SAML)
  • Credential exchange protocols (WS-Trust)
  • Audit logging, monitoring, and event notification
  • Additional authentication methods (Kerberos, PAM, OTP, SRP)
  • Managing multiple credentials
acknowledgements
Shiva Chetan

Sumin Song

Feng Qin

Xiao Tu

Shaun Arnold

Jun Wang

Greg Mattes

Glenn Wasson

Jarek Gawor

Daniel Kouril

Jason Novotny

Miroslav Ruda

Benjamin Temko

Von Welch

Markus Lorch

Charles Severance

Acknowledgements:

Supported by NSF Middleware Initiative

ad