Presentation is loading. Please wait.

Presentation is loading. Please wait.

CA-OPS Authentication Profiles Tony Genovese ATF team ESnet Lawrence Berkeley National Laboratory.

Similar presentations


Presentation on theme: "CA-OPS Authentication Profiles Tony Genovese ATF team ESnet Lawrence Berkeley National Laboratory."— Presentation transcript:

1 CA-OPS Authentication Profiles Tony Genovese ATF team ESnet Lawrence Berkeley National Laboratory

2 February 2005 TERENA TF-EMC2 1 Outline Authentication Profiles Authentication Profiles Why authentication profiles?Why authentication profiles? What is in it?What is in it? General Federation documentGeneral Federation document

3 February 2005 TERENA TF-EMC2 2 Why Authentication Profiles? New Authentication services will fragment the current global trust model. New Authentication services will fragment the current global trust model. Yet, we must allow for innovations in Authentication services. Yet, we must allow for innovations in Authentication services. Classic PKI procrustean bed no longer works.Classic PKI procrustean bed no longer works. Currently a draft GGF informational doc. Currently a draft GGF informational doc.

4 February 2005 TERENA TF-EMC2 3 Authentication Profile what is in it? Authentication Services must provide basic information on: Authentication Services must provide basic information on: The governance of authentication service.The governance of authentication service. A set of membership and operational requirements.A set of membership and operational requirements. Publishing model that Relying parties can trust.Publishing model that Relying parties can trust.

5 February 2005 TERENA TF-EMC2 4 General Federation Document 1. Federation definition - description 2. General architecture 3. Identity management 4. Operational requirements 5. Site security. 6. Publication and repository responsibilities 7. Liability 8. Financial responsibilities 9. Audits and compliance 10. Privacy and confidentiality 11. Compromise and disaster recovery 12. Federation administration

6 February 2005 TERENA TF-EMC2 5 New Federations that can be profiled Any Federation with common AuthN services. Any Federation with common AuthN services. SIPS - Site Integrated Proxy services SIPS - Site Integrated Proxy services KCA exampleKCA example Site SSL support - Host certificate service Site SSL support - Host certificate service RAF - RADIUS Authentication Fabric RAF - RADIUS Authentication Fabric Active Credential Stores Active Credential Stores

7 February 2005 TERENA TF-EMC2 6 Status of document Mostly guidance material being added Mostly guidance material being added Change name to reflect focus Change name to reflect focus Authentication Federations for GridsAuthentication Federations for Grids Grid Federation templateGrid Federation template Trust Federation setupTrust Federation setup Being used by the Americas Grid PMA for chartering. Being used by the Americas Grid PMA for chartering.


Download ppt "CA-OPS Authentication Profiles Tony Genovese ATF team ESnet Lawrence Berkeley National Laboratory."

Similar presentations


Ads by Google