National Computational Science National Center for Supercomputing Applications National Computational Science Integration of the MyProxy Online Credential.

Slides:



Advertisements
Similar presentations
National Center for Supercomputing Applications MyProxy and NVO or Web SSO for Grid Portals GlobusWorld 2006 Washington, DC, USA September 12, 2006 Mike.
Advertisements

MyProxy Jim Basney Senior Research Scientist NCSA
OGF 19, Raleigh NC HPC Profile WG Marty Humphrey, co-chair Department of Computer Science University of Virginia Charlottesville, VA.
Using the Collaborative Tools in NEESgrid Charles Severance University of Michigan.
MyProxy: A Multi-Purpose Grid Authentication Service
Jim Basney GSI Credential Management with MyProxy GGF8 Production Grid Management RG Workshop June.
Military Technical Academy Bucharest, 2006 GRID SECURITY INFRASTRUCTURE (GSI) - Globus Toolkit - ADINA RIPOSAN Department of Applied Informatics.
Grid Security. Typical Grid Scenario Users Resources.
National Center for Supercomputing Applications Integrating MyProxy with Site Authentication Jim Basney Senior Research Scientist National Center for Supercomputing.
National Center for Supercomputing Applications MyProxy and GSISSH Update Von Welch National Center for Supercomputing Applications University of Illinois.
National Center for Supercomputing Applications PKI and CKM ® Scaling Study NCASSR Kick-off Meeting June 11-12, 2003 Jim Basney
GGF15 Workshop MyProxy Integration with PubCookie Marty Humphrey*, Jim Jokl*, and Jim Basney** *Department of Computer Science, University of Virginia,
National Center for Supercomputing Applications University of Illinois at Urbana-Champaign This material is based upon work supported by the National Science.
1-2.1 Grid computing infrastructure software Brief introduction to Globus © 2010 B. Wilkinson/Clayton Ferner. Spring 2010 Grid computing course. Modification.
Federated Access to US CyberInfrastructure Jim Basney CILogon This material is based upon work supported by the National Science Foundation.
Single Sign-On for Java Web Start Applications Using MyProxy Terry Fleury, Jim Basney, and Von Welch November 3, 2006.
TeraGrid Science Gateway AAAA Model: Implementation and Lessons Learned Jim Basney NCSA University of Illinois Von Welch Independent.
Globus Computing Infrustructure Software Globus Toolkit 11-2.
MyProxy NMI Integration Jim Basney, NCSA Marty Humphrey, University of Virginia
Web-based Portal for Discovery, Retrieval and Visualization of Earth Science Datasets in Grid Environment Zhenping (Jane) Liu.
TeraGrid ’06 National Center for Supercomputing Applications Managing Credentials on the TeraGrid with MyProxy Jim Basney.
National Computational Science National Center for Supercomputing Applications National Computational Science MyProxy: An Online Credential Repository.
Riccardo Bruno INFN.CT Sevilla, Sep 2007 The GENIUS Grid portal.
Distributed Web Security for Science Gateways Jim Basney In collaboration with: Rion Dooley Jeff Gaynor
Distributed Web Security for Science Gateways Jim Basney In collaboration with: Rion Dooley Jeff Gaynor
University of Virginia Experiences with NMI at the University of Virginia NMI Integration Testbed: Experiences in Middleware Deployment Spring 2003 Internet2.
National Center for Supercomputing Applications The Computational Chemistry Grid: Production Cyberinfrastructure for Computational Chemistry PI: John Connolly.
TeraGrid Science Gateways: Scaling TeraGrid Access Aaron Shelmire¹, Jim Basney², Jim Marsteller¹, Von Welch²,
Long Term Ecological Research Network Information System LTER Grid Pilot Study LTER Information Manager’s Meeting Montreal, Canada 4-7 August 2005 Mark.
Grid Computing, B. Wilkinson, b.1 National Science Foundation Middleware Initiative (NMI) Started in 2001 initially over 3 years “to create and deploy.
Grid Security Issues Shelestov Andrii Space Research Institute NASU-NSAU, Ukraine.
Managing Credentials with MyProxy Jim Basney National Center for Supercomputing Applications University of Illinois
Javascript Cog Kit By Zhenhua Guo. Grid Applications Currently, most grid related applications are written as separate software. –server side: Globus,
National Computational Science National Center for Supercomputing Applications National Computational Science NCSA-IPG Collaboration Projects Overview.
GridShib and MyProxy Grid Credential Management and Identity Federation Von Welch NCSA
Using the MyProxy Online Credential Repository Jim Basney National Center for Supercomputing Applications University of Illinois
Tutorial: Building Science Gateways TeraGrid 08 Tom Scavo, Jim Basney, Terry Fleury, Von Welch National Center for Supercomputing.
Todd Tannenbaum Computer Sciences Department University of Wisconsin-Madison Condor RoadMap.
An OGSI CredentialManager Service Jim Basney, Shiva Shankar Chetan, Feng Qin, Sumin Song, Xiao Tu National Center for Supercomputing Applications, University.
NGS Portal.
Holding slide prior to starting show. A Portlet Interface for Computational Electromagnetics on the Grid Maria Lin and David Walker Cardiff University.
National Computational Science National Center for Supercomputing Applications National Computational Science Credential Management in the Grid Security.
Identity Federation and Attribute-based Authorization through the Globus Toolkit, Shibboleth, GridShib, and MyProxy Tom Barton 1, Jim Basney 2, Tim Freeman.
NA-MIC National Alliance for Medical Image Computing UCSD: Engineering Core 2 Portal and Grid Infrastructure.
Grid Security: Authentication Most Grids rely on a Public Key Infrastructure system for issuing credentials. Users are issued long term public and private.
Part 9: MyProxy Pragmatics This presentation and lab ends the GRIDS Center agenda Q: When do we convene again tomorrow?
GRIDS Center Middleware Overview Sandra Redman Information Technology and Systems Center and Information Technology Research Center National Space Science.
Biometric Authentication in Distributed Computing Environments Vijai Gandikota Karthikeyan Mahadevan Bojan Cukic.
The MyProxy Online Credential Repository Jim Basney NCSA
SOS August 21, 2006 GGF Security for Open Science Center for Enabling Technology Lead PI - Deb Agarwal, Lawrence Berkeley National Laboratory - Lawrence.
National Computational Science National Center for Supercomputing Applications National Computational Science GSI Online Credential Retrieval Requirements.
Grid, Web services and Taverna Machiel Jansen Richard Holland.
Leveraging the InCommon Federation to access the NSF TeraGrid Jim Basney Senior Research Scientist National Center for Supercomputing Applications University.
Security CET September 27, 2006 GGF Security for Open Science Project Lead PI - Deb Agarwal, Lawrence Berkeley National Laboratory - Lawrence Berkeley.
Feb 2-4, 2004LNCC Workshop on Computational Grids & Apps Middleware for Production Grids Jim Basney Senior Research Scientist Grid and Security Technologies.
1 Grid School Module 4: Grid Security. 2 Typical Grid Scenario Users Resources.
Using the MyProxy Online Credential Repository Jim Basney National Center for Supercomputing Applications University of Illinois
National Energy Research Scientific Computing Center (NERSC) Visportal : interface to grid enabled NERC resources Cristina Siegerist NERSC Center Division,
Introduction to Portals.
The GRIDS Center, part of the NSF Middleware Initiative Grid Security Overview presented by Von Welch National Center for Supercomputing.
Holding slide prior to starting show. Lessons Learned from the GECEM Portal David Walker Cardiff University
The NGS Portal Guy Warner NeSC Training.
Antonio Fuentes RedIRIS Barcelona, 15 Abril 2008 The GENIUS Grid portal.
Grid Security.
Example: Rapid Atmospheric Modeling System, ColoState U
NAREGI-CA Development of NAREGI-CA NAREGI-CA Software CP/CPS Audit
Security for Open Science
MyProxy Integration with PubCookie
A Grid Authorization Model for Science Gateways
Presentation transcript:

National Computational Science National Center for Supercomputing Applications National Computational Science Integration of the MyProxy Online Credential Repository into the NSF Middleware Initiative Software Infrastructure Jim Basney NCSA Marty Humphrey University of Virginia

National Computational Science National Center for Supercomputing ApplicationsNational Computational Science MyProxy Provides a repository for Grid (GSI) proxy credentials –Per-credential policy controls how the credential can be retrieved Uses –Retrieve a proxy credential on demand from any machine without distributing long-term credentials –Delegate a proxy credential without modifying existing protocols (example: https to Grid portals) –Allow monitored, controlled renewal of delegated proxy credentials rather than delegating long-lived proxy credentials directly

National Computational Science National Center for Supercomputing ApplicationsNational Computational Science MyProxy Upload Proxy MyProxy Server Web Portal Login Fetch Proxy Grid Resources Scheduler Submit Jobs Renew Proxy Fetch Proxy Renew Proxy

National Computational Science National Center for Supercomputing ApplicationsNational Computational Science MyProxy Status Initially developed at NCSA in 2000 by Jason Novotny and Von Welch for delegating credentials to Grid portals Updated to support per-credential authorization, direct retrieval, renewal, and Globus 2.0 in the last year Latest version available from NMI supporting continued NCSA/UVA development July June 2004

National Computational Science National Center for Supercomputing ApplicationsNational Computational Science NMI Deliverables: Year 1 Prepare for NMI distribution Support multiple credentials per user Provide a thread-safe C API library Integrate with Condor-G Support Kerberos authentication and storing Kerberos credentials Support audit functions

National Computational Science National Center for Supercomputing ApplicationsNational Computational Science NMI Deliverables: Year 2 Submit OGSA-compliant protocol draft for credential retrieval services (a.k.a. token services) to GGF Provide an OGSA-compliant protocol implementation Develop and implement an authorization framework for credential repositories Develop mechanisms to reduce complexity for users managing multiple credentials