Download presentation
Presentation is loading. Please wait.
Published byStewart Hampton Modified over 8 years ago
1
Project CLASP: Common Login and Access rights across Services Plan Goal Propose a detailed plan to reduce the number of login/passwords entered by users to access services they are authorised to use http://cern.ch/proj-CLASP
2
What’s in a name? The meaning of “clasp”: An object used to join together two materials To take in your hand An acronym for “Common Login and Access rights across Services Plan”
3
Outline Project Goal Project Purpose Background Scope Project Phases Phase 1 Goals Phase 1 Deliverables Summary
4
Project CLASP Purpose For users both on and off the CERN site: Investigate and propose a plan for implementing a common authentication mechanism for use by CERN services. Investigate and propose a platform independent mechanism to provide controlled access to objects (e.g. systems, files, web pages) for authenticated users.
5
Background The number of login/passwords has become a frustration for the user community The number of services continues to grow Initiatives towards a common login id and password synchronisation have been made Windows 2000 and Linux 2000 provide an opportunity for further improvement Technologies such as Kerberos v5, Certificates/PKI, LDAP are becoming mature A Divisional Project is launched (CLASP)
6
Project Scope Address computing services offered by IT and AS Divisions Normal user access from in or outside CERN Target W2000 and Linux for interactive (telnet, X), web, and file (NICE, AFS) access Not a “security project”- but elimination of clear-text passwords is desirable Not an “implementation project” - the result will be a proposal and detailed plan
7
The final proposal will include: A proposed common authentication and authorisation mechanism A plan for introducing the mechanism A list of services covered Recommendations for services not covered An opt-out mechanism for special cases A password (check & change) policy An assessment of the impact on users and service providers both at CERN and other sites
8
Project Phases Phase 1: Service Survey and Feasibility Study what do we have now and what is possible for the future Phase 2: Final Proposal and Detailed Plan Phase 1 will define the steps required for Phase 2
9
Phase 1 Goals Document the current login/password mechanisms used on IT and AS services Assess the feasibility of Kerberos v5 and/or other technology as a common authentication mechanism for the planned Windows 2000 & Linux 2000 environments Investigate possibilities for platform independent access control Propose next steps, including personnel and budget estimates
10
Phase 1 Deliverables Two Documents: Survey of login/password mechanisms used by services in IT and AS Division Feasibility of Kerberos v5 and/or other technology as a base technology for meeting the project goal Success Criteria: Acceptance by an open C5 meeting Timescale: From Jan 2000 for 3 - 6 months
11
Service Survey: Document Blueprint Purpose: Document current login/password mechanisms for IT and AS services Provide a basis to assess the impact of introducing a common authentication mechanism Planned Contents: A table of services with a brief description of the login/password mechanism used People Involved: Contributors: service managers Audience: service providers and IT management Reviewers: service managers Editor: Denise Heagerty
12
Feasibility Study: Document Blueprint Purpose: To allow a decision on the technology to be used as the basis for a common authentication mechanism To document initial investigations and test results People Involved: Contributors: members of teams working on CLASP, Linux, WIN2000, AFS, Web, LDAP, other specialists Audience: service providers and IT management Reviewers: service managers Editor: Denise Heagerty
13
Feasibility Study: Document Blueprint (cont) Planned Contents: A proposed base technology for common authentication and authorisation at CERN Background information and justification A list of services covered A list of tests made and the results A discussion of possibilities for platform independent access control Proposed next steps, including personnel and budget estimates
14
Summary Project purpose, scope and phases outlined Phase 1: service survey and feasibility study parallel activities your collaboration is needed results will be documented and presented to C5 Timescale: From Jan 2000 for 3-6 months Phase 2: final proposal and detailed plan expected contents outlined actions and resources required will be defined by Phase 1http://cern.ch/proj-clasp
15
Password?
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.