Download presentation
Presentation is loading. Please wait.
Published byJonathan Ramshaw Modified over 10 years ago
1
Author - Title- Date - n° 1 Partner Logo Authentication John Gordon GridPP 2 nd May 2002
2
John Gordon - DataGrid Workshop, Frascati, Oct 2001 2 Certificate Authorities u RAL has run a CA for UKHEP since October 2000 u CLRC GSC runs a prototype CA for the UK eScience Core Programme n You can use it now CLRC is developing ‘ The UK e-Science CA’ u The UK e-Science CA will issue personal, server, and service certificates
3
John Gordon - DataGrid Workshop, Frascati, Oct 2001 3 Personal : /C=UK/O=eScience/OU= /L= /CN= u The CN should be a personal name, not a role, i.e. "Joe Bloggs“ rather than "postmaster" or "RA". u The OU is the UK e-Science project of the Registration Authority, not (necessarily) the project that the user belongs to. u Similarly, L is the locality of the RA. u For personal certificates, we keep the email address provided by the user, and this is the only personal information we keep, and it is not made public.
4
John Gordon - DataGrid Workshop, Frascati, Oct 2001 4 Server certificates : /C=UK/O=eScience/OU= /L= /CN= /Email= u Here fqdn is a Fully Qualified Domain Name, Email is an email address of a contact person, a person who is responsible for that host u (this email address is publically available, but that's the same with DNS for example, the host's DNS entry will also have an email address).
5
John Gordon - DataGrid Workshop, Frascati, Oct 2001 5 Service certificates : u Are the same as server certificates. Except the CN is u.../CN= / /Email= u and service is the IANA assigned name for the service (not sure yet if we allow for non-standard port-numbers, probably we should but it's not in there yet).
6
John Gordon - DataGrid Workshop, Frascati, Oct 2001 6 u For further details, consult u http://www.grid-support.ac.uk/ca/interim_procedure.html u Service numbers: u http://www.iana.org/assignments/port-numbers u (yes, gsiftp is in there)
7
John Gordon - DataGrid Workshop, Frascati, Oct 2001 7 Authorisation u Important to separate this from Authentication u Certificates above say nothing about membership of projects or VOs u Working with Globus on Community Authorisation Service (CAS) u Current authorisation by gridmapfile (Andrew McNab)
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.