Cyberinfrastructure Seminar Series
Tuesday, September 6, 2005
Using the MyProxy Online Credential Repository
Jim Basney , NCSA
11:00 AM - 12:30 PM (PDT)
1:00 PM - 2:30 PM (CDT)
3000 NCSA Building via AG
The MyProxy (http://myproxy.ncsa.uiuc.edu/) online credential repository provides
secure and convenient storage for grid security credentials.
MyProxy is mature, open source software for the Globus Toolkit that has been
used by the grid community for over four years, in projects such as NEESgrid,
TeraGrid, EU DataGrid, and the NASA Information Power Grid. MyProxy is included
in the NSF Middleware Initiative GRIDS Center software distribution and is
included in the Globus Toolkit 4.0 release.
MyProxy allows users to easily obtain a proxy credential from the repository,
without requiring users to manage private key and certificate files. Grid portals
use MyProxy to obtain proxy credentials, so users can access secure grid resources
via the portal interface. Job management software, such as Condor-G, uses MyProxy
to renew credentials for long-running jobs. MyProxy can also be integrated
with CA software, such as the Globus Simple CA, to ease credential distribution.
A well-managed MyProxy repository can provide better security for user private
keys when compared to the typical solution of storing keys on end-user desktop
systems. MyProxy can enforce policies on the passphrases used to protect user
keys and can provide the ability to monitor key usage to detect or track misuse.
MyProxy can also be integrated with local site authentication systems, such
as Kerberos and one-time passwords, to bridge between local site security and
grid security.
In this talk, I'll describe how MyProxy is used in practice today, covering
basic setup, integration with portals, job managers, and CAs, and new features
added in recent MyProxy releases.
The Cyberinfrastructure Seminar Series is a set of presentations
on cyberinfrastructure and related research organized by NCSA and SDSC. These
seminars are available on site at the presenting institution and remotely via
the Access Grid. For more details regarding the AG venue for this seminar,
please refer to:
http://agschedule.ncsa.uiuc.edu/meetingdetails.asp?MID=9804.
All Access Grid sites are welcome to participate in this seminar. If you have
any questions, contact Jennie
File, NCSA Training & Outreach Group.