GridCertLib: Use Shibboleth to Access the Grid from Web Portals

Peter Kunszt, Sergio Maffioletti, Riccardo Murri, Valery Tschopp · 2011

Abstract This paper describes the design and implementation of GridCertLib, a Java libraryleveraging a Shibboleth-based authentication infrastructure and the SLCS online cer-tificate signing service, to provide short-lived X.509 certificates and Grid proxies.The main use case envisioned for GridCertLib, is to provide seamless and secureaccess to Grid/X.509 certificates and proxies in web portals : when a user logs in tothe portal using SWITCHaai Shibboleth authentication,GridCertLib can automaticallyobtain a Grid/X.509 certificate from the SLCS service and gen erate a VOMS proxyfrom it.We give an overviewof the architecture of GridCertLib and briefly describe its pro-gramming model. Application to common deployment scenarios are outlined, and wereport on our practical experience integrating GridCertLib into the a portal for Bioin-formatics applications, based on the popular P-GRADE software. 1 Introduction Most Grid computing middleware in production use today relies on X.509 certificateproxies [16] for user authentication. This has been an issue when implementing web-based interfaces to Grid computing facilities: in order to generate a proxy, a copyof the X.509 private key is needed together with the passphrase used to encrypt it.However, uploading the public/private key pair to a web portal is undesirable on secu-rity grounds. Several solutions and workarounds have been implemented (see SectionAn overview of existing solutions below), but none of them can be considered entirelysatisfactory: either on security grounds, or because they require end users to take mul-tiple steps, possibly through different and unrelated user interfaces (e.g. a web portaland UNIX shell commands).The solution we developed leverages two features offered by SWITCH, the SwissNational Academic Network: SWITCHaai and SLCS. SWITCH has deployed the1

Read the paper · More papers on PaperTik