Adapting globus and kerberos for a secure ASCI grid
Autor: | Wilbur R. Johnson, Richard J. Detry, Patrick C. Moore |
---|---|
Rok vydání: | 2001 |
Předmět: |
X.509
Cloud computing security Computer science computer.internet_protocol Generic Security Service Algorithm for Secret Key Transaction Generic Security Services Application Program Interface Data security Public key infrastructure Kerberos Grid Security Infrastructure Computer security computer.software_genre computer |
Zdroj: | SC |
DOI: | 10.1145/582034.582055 |
Popis: | Porting a complex secure application from one security infrastructure to another is often difficult or impractical. Grid security associated with the Globus toolkit is supported by a Grid Security Infrastructure (GSI) based on a Public Key Infrastructure where users authenticate to the grid using X509 certificates. Kerberos security is based on a trusted third party, secret key infrastructure where users authenticate using encrypted tickets. However, both GSI and Kerberos provide a Generic Security Services Application Program Interface (GSSAPI) for source code portability. We describe the porting of our Globus system from GSI security to Kerberos V5 security, and the Kerberos modifications necessary to achieve that portability. Our case study provides details and insights that will be of value to developers and designers interested in GSSAPI portability. We conclude, based on our results, that designers of network security software should strive to accommodate the GSSAPI. |
Databáze: | OpenAIRE |
Externí odkaz: |