Leveraging Campus Authentication for Grid Scalability Jim Jokl Marty Humphrey University of Virginia Internet2 Meeting April 2004.

Slides:



Advertisements
Similar presentations
1 ABCs of PKI TAG Presentation 18 th May 2004 Paul Butler.
Advertisements

Experiences with Massive PKI Deployment and Usage Daniel Kouřil, Michal Procházka Masaryk University & CESNET Security and Protection of Information 2009.
PKI Solutions: Buy vs. Build David Wasley, U. California (ret.) Jim Jokl, U. Virginia Nick Davis, U. Wisconsin.
MyProxy: A Multi-Purpose Grid Authentication Service
Grid Security Infrastructure Tutorial Von Welch Distributed Systems Laboratory U. Of Chicago and Argonne National Laboratory.
CSCE 715: Network Systems Security Chin-Tser Huang University of South Carolina.
1 HEPKI-TAG Update EDUCAUSE/Dartmouth PKI Summit July 26, 2005 Jim Jokl University of Virginia.
PKI in US Higher Education TAGPMA Meeting, March 2006 Rio De Janeiro, Brazil.
PKI Activities at Virginia January 2004 CSG Meeting Jim Jokl.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
David L. Wasley Information Resources & Communications Office of the President University of California Directories and PKI Basic Components of Middleware.
December 8 & 9, 2005, Austin, TX SURA Cyberinfrastructure Workshop Series: Grid Technology: The Rough Guide Authentication, Authorization, & Identity Issues.
16.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
Attributes, Anonymity, and Access: Shibboleth and Globus Integration to Facilitate Grid Collaboration 4th Annual PKI R&D Workshop Tom Barton, Kate Keahey,
Some Common Campus PKI Applications January 2004 CSG Meeting Jim Jokl.
Introduction to PKI Seminar What is PKI? Robert Brentrup July 13, 2004.
Interoperation Between a Conventional PKI and an ID-Based Infrastructure Geraint Price Royal Holloway University of London joint work with Chris Mitchell.
November 1, 2006Sarah Wahl / Graduate Student UCCS1 Public Key Infrastructure By Sarah Wahl.
CMSC 414 Computer and Network Security Lecture 20 Jonathan Katz.
Copyright, 1996 © Dale Carnegie & Associates, Inc. Digital Certificates Presented by Sunit Chauhan.
Identity Management and PKI Credentialing at UTHSC-H Bill Weems Academic Technology University of Texas Health Science Center at Houston.
HEBCA – Higher Education Bridge Certification Authority Presented by Scott Rea and Mark Franklin, Fed/Ed Meeting, 12/14/2005.
1 USHER Update Fed/ED December 2007 Jim Jokl University of Virginia.
1 11 th Fed/Ed PKI Meeting Some quick updates from recent HEPKI-TAG and SURA work Jim Jokl
Inside the PKI Framework: * Activating the Puzzle Pieces PKI Summit Snowmass August
Controller of Certifying Authorities Public Key Infrastructure for Digital Signatures under the IT Act, 2000 : Framework & status Mrs Debjani Nag Deputy.
1 Grids and PKI Bridges (Globus Toolkit) EDUCAUSE/Dartmouth PKI Summit July 26, 2005 Shelley Henderson - USC Jim Jokl - Virginia.
Technical Issues that Challenge PKI Deployments Jim Jokl University of Virginia PKI Meeting August 12, 2004.
HEPKI-TAG Activities & Globus and Bridges Jim Jokl University of Virginia Fed/ED PKI Meeting June 16, 2004.
1 PKI Update September 2002 CSG Meeting Jim Jokl
GridShib: Grid-Shibboleth Integration (Identity Federation and Grids) April 11, 2005 Von Welch
Digital Signatures A Brief Overview by Tim Sigmon August, 2000.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
NENA Development Conference | October 2014 | Orlando, Florida Security Certificates Between i3 ESInet’s and FE’s Nate Wilcox Emergicom, LLC Brian Rosen.
1 PKI & USHER/HEBCA Fall 2005 Internet2 Member Meeting Jim Jokl September 21, 2005.
Public Key Infrastructure (X509 PKI) Presented by : Ali Fanian.
Cryptography Encryption/Decryption Franci Tajnik CISA Franci Tajnik.
Grid Security 1. Grid security is a crucial component Need for secure communication between grid elements  Authenticated ( verify entities are who they.
CAMP PKI UPDATE August 2002 Jim Jokl
Bridge Certification Architecture A Brief Demo by Tim Sigmon and Yuji Shinozaki June, 2000.
Digital Signatures A Brief Overview by Tim Sigmon April, 2001.
HEPKI-PAG Policy Activities Group David L. Wasley University of California.
GridShib: Grid/Shibboleth Interoperability September 14, 2006 Washington, DC Tom Barton, Tim Freeman, Kate Keahey, Raj Kettimuthu, Tom Scavo, Frank Siebenlist,
NSF Middleware Initiative Renee Woodten Frost Assistant Director, Middleware Initiatives Internet2 NSF Middleware Initiative.
Introduction to Public Key Infrastructure January 2004 CSG Meeting Jim Jokl.
Evolution of the Open Science Grid Authentication Model Kevin Hill Fermilab OSG Security Team.
Module 9: Designing Public Key Infrastructure in Windows Server 2008.
PKI Activities at Virginia September 2000 Jim Jokl
Public Key Infrastructure (X509 PKI) Presented by : Ali Fanian
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
3-Nov-00D.P.Kelsey, HEPiX, JLAB1 Certificates for DataGRID David Kelsey CLRC/RAL, UK
The Federal PKI Or, How to Herd Worms Peter Alterman Senior Advisor, Federal PKI Steering Committee.
“Trust me …” Policy and Practices in PKI David L. Wasley Fall 2006 PKI Workshop.
Leveraging the InCommon Federation to access the NSF TeraGrid Jim Basney Senior Research Scientist National Center for Supercomputing Applications University.
Security fundamentals Topic 5 Using a Public Key Infrastructure.
Higher Ed Bridge CA Extending Trust Across Higher Education - And Beyond David L. Wasley University of California.
Pkiuniversity.com. Alice Bob Honest Abe’s CA Simple PKI hierarchy.
Bridge Certification Architecture A Brief Overview by Tim Sigmon May, 2000.
1 Grid School Module 4: Grid Security. 2 Typical Grid Scenario Users Resources.
Federal PKI Update Peter Alterman, Ph.D. Chair, Federal PKI Policy Authority.
1 Public Key Infrastructure Dr. Rocky K. C. Chang 25 February, 2002.
1 Public Key Infrastructure Rocky K. C. Chang 6 March 2007.
1 SURAGrid User/Host Certificate Authority SURAgrid Meeting MARCH 26, 2010 Jim Jokl University of Virginia.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
1 US Higher Education Root CA (USHER) Update Fed/Ed Meeting December 14, 2005 Jim Jokl University of Virginia.
TAG Presentation 18th May 2004 Paul Butler
TAG Presentation 18th May 2004 Paul Butler
Technical Approach Chris Louden Enspier
Fed/ED December 2007 Jim Jokl University of Virginia
September 2002 CSG Meeting Jim Jokl
Presentation transcript:

Leveraging Campus Authentication for Grid Scalability Jim Jokl Marty Humphrey University of Virginia Internet2 Meeting April 2004

University of Virginia 2 NMI Testbed Activity  Early project focus Testing various NMI components Integrating them with campus infrastructure  Next phase: more inter-campus activities Focus on Globus  However, results can be generally applicable How do we facilitate sharing of data and compute resources between campuses?  Scalability and complexity issues for the Grid  Security, researcher support, sharing equity issues  Our focus: authentication and inter-campus trust  Hence inter-campus aspects of Globus PKI

University of Virginia 3 Background: Public Key Infrastructure (PKI)  A PKI uses asymmetric cryptography A pair of mathematically related keys  The Public Key is published widely; Private Key is secret  An X.509 Certificate is: An object signed by a Certification Authority (CA) A binding of a user’s identity to their public key An object containing attributes about the individual and the Issuing Certification Authority  Critical Issues How do you trust the credential binding? How can other institutions trust it? How would trust scale in a large Grid or Grids?

University of Virginia 4 Background: Trust in a Hierarchical PKI  Trust based on trusting “root” certificate  User cert trust via validating cert chain to a trusted root  Some issues: “root” compromise A CA per Grid v.s. a CA per school v.s. ?  Researcher support Integrating existing campus credentials Root Certificate Intermediate Certificate User A Cert User C Cert User B Cert User D Cert User E Cert

University of Virginia 5 Background: Trust in a Bridge PKI  Enables trust between multiple hierarchical CAs  No need to reconstitute whole PKI if CA is compromised  Generally uses more infrastructure than just the cross-certificate pairs  Can enable trust between existing PKIs  Preserves technical and political separation  Logical choice for multi- campus / multi-grid systems Enable researchers to use home campus credentials Root A Mid-A User A1 User A2 Root BRoot n Mid-B User B1 Bridge CA Cross-certificate pairs

University of Virginia 6 PKI Bridge Path Validation

University of Virginia 7 Globus & Bridge Test Environment  Simple bridge test environment revealed Globus can validate a bridge trust path  All needed cross-certificates must be pre-loaded into /etc/grid-security/certificates  Appears that all needed intermediate CA certificates must also be pre-loaded  No known support for a directory mechanism to locate cross-certificates  Does no appear to follow AIA URLs to obtain any needed cross or intermediate certificates A more complex real-world test is needed

University of Virginia 8 Globus PKI Integration Notes  Campus CA Integration Use of Campus CAs with Globus for inter- institutional sharing of resources should be manageable Typical campus certificate profiles (e.g. PKI- lite) work well with Globus Challenges will exist for locating the needed cross-certificates and intermediate CA certificates

University of Virginia 9 Globus PKI Integration Notes  Campus CA integration is complicated by the Globus interface Campus CAs and OS-exported certificates are generally in PKCS-12 format Globus expects raw PEM files for the certificate and the private key  A file to map certificate DNs to UNIX login names must be maintained A maintenance challenge for large inter- institutional grids

University of Virginia 10 Goals for Larger Test on the NMI Testbed Grid  Test the use of Globus in a real and larger bridged PKI environment  Enable the use of campus CAs in inter- institutional Grids Show that one set of campus-issued credentials can work  Use on a single or multiple grids  Eases researcher pain (and support issues) Explore complexity issues, demonstrate scalability  Create appropriate tools and documentation  Prepare for Globus to leverage other activities Higher Education Bridge Certification Authority Higher Education Root Certification Authority

University of Virginia 11 Higher Education Bridge Certification Authority (HEBCA)  A project of EDUCAUSE Implement a bridge for higher education based on the Federal PKI bridge model Support both campus PKIs and sector hierarchical PKIs Cross-certify with the Federal bridge (and others as appropriate)  Use of HEBCA with Globus may be a natural result of this work

University of Virginia 12 US Higher Education Root CA  A project of Internet2 The replacement for the CREN CA  Designed to support campuses that wish to be part of a hierarchical CA CA sign’s campus CA signing certificates  Expectation is to cross-certify with HEBCA at some level  Campus CAs that are part of this hierarchy would also work well in a bridged Globus environment

University of Virginia 13 Current Project Status  Built Testbed Bridge CA Off-line system  Cross-certifications UVA: complete UAB: nearly done TACC: 50% USC: getting started  /etc/grid-security Certificates, policy files, and hash links generated via scripts Gridmap file by hand

University of Virginia 14 Tool Development  In addition to supporting the testbed grid via cross-certification, we plan to explore a few tools Credential converter web site that takes a PKCS-12 (as is available in most enterprise CAs) and returns the PEM files needed by Globus A tool to chase down cross-certificates from AIA fields and build the needed Globus links and signing policy files Potentially: a CA using a Shibboleth-based RA  Provide certificates for campuses that have Shibboleth but are not yet operating an enterprise CA  Each campus would have its own root that would be cross- certified via the testbed bridge  We should know a lot more in a few months