Presentation is loading. Please wait.

Presentation is loading. Please wait.

A Modest Proposal for an Assertion Validation Service Bob Cowles (SLAC/OSG) 28-Mar-2007 thanks to discussions with Frank Siebenlist, Rachana Ananthakrishnan.

Similar presentations


Presentation on theme: "A Modest Proposal for an Assertion Validation Service Bob Cowles (SLAC/OSG) 28-Mar-2007 thanks to discussions with Frank Siebenlist, Rachana Ananthakrishnan."— Presentation transcript:

1 A Modest Proposal for an Assertion Validation Service Bob Cowles (SLAC/OSG) 28-Mar-2007 thanks to discussions with Frank Siebenlist, Rachana Ananthakrishnan – ANL Mike Helm – ESnet

2 28Mar07ISGC 20072/7 The Problem PKI credential validation is very complex Application developers tempted to take shortcuts Testing for success, not for failure Locked into PKI credentials based on application code

3 28Mar07ISGC 20073/7 Credential < Assertion Similar problems exist in the authorization space –How to distribute trust roots to all points (every relying party needs to know the certificate associated with the VOMS server to validate VOMS attribute certificate) Validation code and trust-root configuration needs to be correct on each resource –Maintenance issues, especially light-weight clients –Out-of-date could imply security exposure –Administration of new trust-roots –Managing revocation

4 28Mar07ISGC 20074/7 Validation Service Step 1 Create library of routines to perform validation Uses well written library code to perform tests based on grid PKI architecture Treat credential as opaque object in application Allows separation of application and security code.

5 28Mar07ISGC 20075/7 Validation Service Step 2 Library calls modified to invoke external service Library API is unchanged Service of credential checking external to application Secure service Can be shared between applications or sites Might be easier to implement OCSP to reduce CRL scaling problems

6 28Mar07ISGC 20076/7 Validation Service Step 3 Transition to enhanced PKI or non-PKI credentials Service handles multiple forms of credentials/assertions May allow for better integration with future technologies: –Federated identity management –Shib –Bridged infrastructures –SAML, etc.

7 28Mar07ISGC 20077/7 Need is Immediate More application code written each day –Contains coding errors –Contains conceptual errors –Tied to problematic PKI software –Increasing cost to evolve to new technology –Severe scaling problems in current PKI infrastructure Needed – Requests from applications and VOs that this is required – have to get the resources with commitment from middleware and application developers for implementation and deployment.


Download ppt "A Modest Proposal for an Assertion Validation Service Bob Cowles (SLAC/OSG) 28-Mar-2007 thanks to discussions with Frank Siebenlist, Rachana Ananthakrishnan."

Similar presentations


Ads by Google