A Scalable Grid User Management System for Large Virtual Organization
Dairong Yu, Jordan B. L. Smith, T Carter, Zhongao Liu, T. Wlodek, Gabriele Carcassi, J Spiletic, Smith, G, Xinchao Zhao · CERN Document Server (European Organization for Nuclear Research) · 2005
We describe our work on GUMS, a site tool for Resource Authorization (AuthZ) and Grid User Identity Mapping.We will first define the scope of the work, and describe the general direction we are taking.We will describe the current functionalities provided to BNL, such as the ability to have a flexible site policy controlled by a single XML file and the ability to integrate with site databases.We will then describe the current work being done for OSG, which includes the use of account pool, a GT3/4 based service and role based authorization using VOMS extended proxy credentials. OVERVIEWGUMS (Grid User Management System) is a site tool for resource Authorization that addresses one function: mapping grid certificates to local identities (i.e.UNIX account). Grid Identity Mapping ServiceA job comes to a site with a GRID credential (the proxy certificate).The site resources might not use GRID credentials natively, and will use some different mechanism to identify users, such as UNIX accounts, Kerberos principals, and the like.The gatekeeper will need to map the GRID credential to the site credential.GUMS is a service that provide this type of mapping: tells you which site user the GRID user should be using.Notice that it doesn't authenticate for you: it doesn't 'su', it doesn't retrieve Kerberos credentials.It just tells the gatekeeper which site credentials should get.The gatekeeper is still in charge of enforcing the site mapping established by GUMS. Past, Present and FutureGUMS was first designed by Rich Baker and Dantong Yu at BNL in the first half of 2003.A first implementation was provided by Tomasz Wlodek and Dantong Yu.Gabriele Carcassi took over the project in March 2004 and brought the system into full production at BNL in May 2004.Between June and July the code was consolidated to allow the business logic to be called either from command line or a web application, which allows a GT3/4 service implementation.Current work is going toward a web application that would provide both a web interface for the administrator and a web service that implement the OGSA AuthZ interface.This is done within the Privilege Project, a joint project between USCMS and USATLAS.