GridCertLib: a Single Sign-on Solution for Grid Web Portals
Riccardo Murri, Peter Kunszt, Sergio Maffioletti, Valery Tschopp · arXiv (Cornell University) · 2011
Abstract This paper describes the design and implementation of GridCertLib, a Java libraryleveraging a Shibboleth-based authentication infrastructure and the SLCS online cer-tificate signing service, to provide short-lived X.509 certificates and Grid proxies.The main use case envisioned for GridCertLib, is to provide seamless and secureaccess to Grid X.509 certificates and proxies in web applicat ions and portals: when auser logs in to the portal using SAML-based Shibboleth authentication, GridCertLibuses the SAML assertion to obtain a Grid X.509 certificate fro m the SLCS service andgenerate a VOMS proxy from it.We give an overviewof the architecture of GridCertLib and briefly describe its pro-gramming model. Its application to some deployment scenarios is outlined, as well asa report on practical experience integrating GridCertLib into portals for Bioinformat-ics and Computational Chemistry applications, based on the popular P-GRADE andDjango softwares. 1 Introduction Most Grid computing middleware in production use today relies on X.509 certificateproxies [44] for user authentication. This has been an issue when implementing web-based interfaces to Grid computingfacilities: in orderto generate a proxy, a copy of theX.509 private key is needed together with the passphrase used to encrypt it. However,uploadingthe public/privatekeypair to a web portal is undesirableon security grounds.Several solutions and workarounds have been implemented (see Section 2 below), butnone of them can be considered entirely satisfactory: either because they do not fullyaddress the security concerns, or because they require end users to take multiple steps,possibly through different and unrelated user interfaces (e.g. a web portal and UNIXshell commands).1