DocumentCode :
451223
Title :
Adapting Globus and Kerberos for a Secure ASCI Grid
Author :
Moore, Patrick C. ; Johnson, Wilbur R. ; Detry, Richard J.
Author_Institution :
Sandia National Laboratories
fYear :
2001
fDate :
10-16 Nov. 2001
Firstpage :
54
Lastpage :
54
Abstract :
Porting a complex secure application from one security infrastructure to another is often difficult or impractical. Grid security associated with the Globus toolkit is supported by a Grid Security Infrastructure (GSI) based on a Public Key Infrastructure where users authenticate to the grid using X509 certificates. Kerberos security is based on a trusted third party, secret key infrastructure where users authenticate using encrypted tickets. However, both GSI and Kerberos provide a Generic Security Services Application Program Interface (GSSAPI) for source code portability. We describe the porting of our Globus system from GSI security to Kerberos V5 security, and the Kerberos modifications necessary to achieve that portability. Our case study provides details and insights that will be of value to developers and designers interested in GSSAPI portability. We conclude, based on our results, that designers of network security software should strive to accommodate the GSSAPI.
Keywords :
ASCI; GSSAPI; Globus; Kerberos; grid; security; Authentication; Computer networks; Cryptography; Data security; Distributed computing; Government; National security; Power system security; Public key; US Department of Energy; ASCI; GSSAPI; Globus; Kerberos; grid; security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Supercomputing, ACM/IEEE 2001 Conference
Print_ISBN :
1-58113-293-X
Type :
conf
DOI :
10.1109/SC.2001.10009
Filename :
1592830
Link To Document :
بازگشت