1 / 3

Enhancing Authorization and Authentication in Spitfire: Current Activities and Future Plans

This report by Mika Silander details current activities aimed at improving authorization and authentication within the Spitfire framework. Key areas of focus include validating certificates, addressing issues with the Java Certification Path API (JCPAPI), and implementing CRL checks. Additionally, the report outlines future collaboration with Liberty Alliance for federated solutions in authorization and highlights ongoing efforts to replace IAIK certificate manipulation with improved methods. Scalability questions regarding OCSP in the EDG environment are also discussed.

adlai
Télécharger la présentation

Enhancing Authorization and Authentication in Spitfire: Current Activities and Future Plans

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. Security Group WP2 Report by Mika Silander (E-mail: Akos.Frohner@cern.ch)

  2. Current Activity Improving the authorization in Spitfire • validating certs (authentication) • JDK 1.4 Java Certification Path API (JCPAPI) – needs workarounds • CRL checks (...) • other Spitfire specific issues • mapping to roles (authorization) • mapping table in a local DB

  3. Future Plans • collaboration with Liberty Alliance www.projectliberty.org ?federated solutions for AA by industry • replacing IAIK cert manipulation in Java CoG-> cooperation w Jarek Novotny • Online Credential Status Protocol (OCSP) • will it scale in EDG? • other solution, e.g. mailing list/news? • CAS – Java client lib/servlet, if there is interest

More Related