Presentation is loading. Please wait.

Presentation is loading. Please wait.

Project CLASP: Common Login and Access rights across Services Plan Goal  Propose a detailed plan to reduce the number of login/passwords entered by users.

Similar presentations


Presentation on theme: "Project CLASP: Common Login and Access rights across Services Plan Goal  Propose a detailed plan to reduce the number of login/passwords entered by users."— Presentation transcript:

1 Project CLASP: Common Login and Access rights across Services Plan Goal  Propose a detailed plan to reduce the number of login/passwords entered by users to access services they are authorised to use http://cern.ch/proj-CLASP

2 What’s in a name? The meaning of “clasp”:  An object used to join together two materials  To take in your hand  An acronym for “Common Login and Access rights across Services Plan”

3 Outline  Project Goal  Project Purpose  Background  Scope  Project Phases  Phase 1 Goals  Phase 1 Deliverables  Summary

4 Project CLASP Purpose For users both on and off the CERN site:  Investigate and propose a plan for implementing a common authentication mechanism for use by CERN services.  Investigate and propose a platform independent mechanism to provide controlled access to objects (e.g. systems, files, web pages) for authenticated users.

5 Background  The number of login/passwords has become a frustration for the user community  The number of services continues to grow  Initiatives towards a common login id and password synchronisation have been made  Windows 2000 and Linux 2000 provide an opportunity for further improvement  Technologies such as Kerberos v5, Certificates/PKI, LDAP are becoming mature  A Divisional Project is launched (CLASP)

6 Project Scope  Address computing services offered by IT and AS Divisions  Normal user access from in or outside CERN  Target W2000 and Linux for interactive (telnet, X), web, and file (NICE, AFS) access  Not a “security project”- but elimination of clear-text passwords is desirable  Not an “implementation project” - the result will be a proposal and detailed plan

7 The final proposal will include:  A proposed common authentication and authorisation mechanism  A plan for introducing the mechanism  A list of services covered  Recommendations for services not covered  An opt-out mechanism for special cases  A password (check & change) policy  An assessment of the impact on users and service providers both at CERN and other sites

8 Project Phases Phase 1:  Service Survey and Feasibility Study what do we have now and what is possible for the future Phase 2:  Final Proposal and Detailed Plan Phase 1 will define the steps required for Phase 2

9 Phase 1 Goals  Document the current login/password mechanisms used on IT and AS services  Assess the feasibility of Kerberos v5 and/or other technology as a common authentication mechanism for the planned Windows 2000 & Linux 2000 environments  Investigate possibilities for platform independent access control  Propose next steps, including personnel and budget estimates

10 Phase 1 Deliverables Two Documents:  Survey of login/password mechanisms used by services in IT and AS Division  Feasibility of Kerberos v5 and/or other technology as a base technology for meeting the project goal Success Criteria:  Acceptance by an open C5 meeting Timescale:  From Jan 2000 for 3 - 6 months

11 Service Survey: Document Blueprint Purpose:  Document current login/password mechanisms for IT and AS services  Provide a basis to assess the impact of introducing a common authentication mechanism Planned Contents:  A table of services with a brief description of the login/password mechanism used People Involved:  Contributors: service managers  Audience: service providers and IT management  Reviewers: service managers  Editor: Denise Heagerty

12 Feasibility Study: Document Blueprint Purpose:  To allow a decision on the technology to be used as the basis for a common authentication mechanism  To document initial investigations and test results People Involved:  Contributors: members of teams working on CLASP, Linux, WIN2000, AFS, Web, LDAP, other specialists  Audience: service providers and IT management  Reviewers: service managers  Editor: Denise Heagerty

13 Feasibility Study: Document Blueprint (cont) Planned Contents:  A proposed base technology for common authentication and authorisation at CERN  Background information and justification  A list of services covered  A list of tests made and the results  A discussion of possibilities for platform independent access control  Proposed next steps, including personnel and budget estimates

14 Summary  Project purpose, scope and phases outlined  Phase 1: service survey and feasibility study parallel activities your collaboration is needed results will be documented and presented to C5 Timescale: From Jan 2000 for 3-6 months  Phase 2: final proposal and detailed plan expected contents outlined actions and resources required will be defined by Phase 1http://cern.ch/proj-clasp

15 Password?


Download ppt "Project CLASP: Common Login and Access rights across Services Plan Goal  Propose a detailed plan to reduce the number of login/passwords entered by users."

Similar presentations


Ads by Google