R-GMA Security Stephen Hicks UK Cluster Security Middleware Security Group Meeting, 15/10/04 R-GMA Security Stephen Hicks UK Cluster Security www.eu-egee.org EGEE is a project funded by the European Union under contract IST-2003-508833
Contents Current progress Obstacles Priorities Middleware Security Group Meeting, 15/10/04 - 2
Current progress Time spent on Not much on Security in R-GMA API User interfaces to security in R-GMA General ideas in R-GMA Not much on Design/implementation of R-GMA specific security Integration with security infrastructure (Web Services, VOMS etc) Security in R-GMA API Defined access rules for R-GMA tables (based on views). Decided upon use of multiple VO’s in Producers and Consumers. Currently setting up basic Web Service infrastructure No security yet Middleware Security Group Meeting, 15/10/04 - 3
Obstacles Main obstacle has been complexity of R-GMA Design Interfaces to security infrastructure (VOMS, etc.) Multiple VO’s Delegation Implementation Streaming using Java NIO JSSE in JDK1.5 Middleware Security Group Meeting, 15/10/04 - 4
Priorities Finalise authorization rules Do they need to be in a common format? Understand interfaces to the security infrastructure for detailed authorization design. Understand use of multiple VO’s Can hierarchies exist? Understand the delegation portType Does it meet our requirements? Is delegation vital for R-GMA to be secure? WS security code for Java, C, C++ and Python Authentication sooner rather than later May not be installed without authentication Guidance on what libraries are required and how to integrate them Security code for Java NIO Middleware Security Group Meeting, 15/10/04 - 5