Cargando…

LHCb: DIRAC Secure Distributed Platform

DIRAC, the LHCb community grid solution, provides access to a vast amount of computing and storage resources to a large number of users. In DIRAC users are organized in groups with different needs and permissions. In order to ensure that only allowed users can access the resources and to enforce tha...

Descripción completa

Detalles Bibliográficos
Autores principales: Casajus, A, Graciani, R
Lenguaje:eng
Publicado: 2009
Acceso en línea:http://cds.cern.ch/record/1170451
_version_ 1780916137418031104
author Casajus, A
Graciani, R
author_facet Casajus, A
Graciani, R
author_sort Casajus, A
collection CERN
description DIRAC, the LHCb community grid solution, provides access to a vast amount of computing and storage resources to a large number of users. In DIRAC users are organized in groups with different needs and permissions. In order to ensure that only allowed users can access the resources and to enforce that there are no abuses, security is mandatory. All DIRAC services and clients use secure connections that are authenticated using certificates and grid proxies. Once a client has been authenticated, authorization rules are applied to the requested action based on the presented credentials. These authorization rules and the list of users and groups are centrally managed in the DIRAC Configuration Service. Users submit jobs to DIRAC using their local credentials. From then on, DIRAC has to interact with different Grid services on behalf of this user. DIRAC has a proxy management service where users upload short-lived proxies to be used when DIRAC needs to act on behalf of them. Long duration proxies are uploaded by users to MyProxy service, and DIRAC retrieves new short delegated proxies when necessary. This contribution discusses the details of the implementation of this security infrastructure in DIRAC.
id cern-1170451
institution Organización Europea para la Investigación Nuclear
language eng
publishDate 2009
record_format invenio
spelling cern-11704512019-09-30T06:29:59Zhttp://cds.cern.ch/record/1170451engCasajus, AGraciani, RLHCb: DIRAC Secure Distributed PlatformDIRAC, the LHCb community grid solution, provides access to a vast amount of computing and storage resources to a large number of users. In DIRAC users are organized in groups with different needs and permissions. In order to ensure that only allowed users can access the resources and to enforce that there are no abuses, security is mandatory. All DIRAC services and clients use secure connections that are authenticated using certificates and grid proxies. Once a client has been authenticated, authorization rules are applied to the requested action based on the presented credentials. These authorization rules and the list of users and groups are centrally managed in the DIRAC Configuration Service. Users submit jobs to DIRAC using their local credentials. From then on, DIRAC has to interact with different Grid services on behalf of this user. DIRAC has a proxy management service where users upload short-lived proxies to be used when DIRAC needs to act on behalf of them. Long duration proxies are uploaded by users to MyProxy service, and DIRAC retrieves new short delegated proxies when necessary. This contribution discusses the details of the implementation of this security infrastructure in DIRAC.Poster-2009-101oai:cds.cern.ch:11704512009-03-24
spellingShingle Casajus, A
Graciani, R
LHCb: DIRAC Secure Distributed Platform
title LHCb: DIRAC Secure Distributed Platform
title_full LHCb: DIRAC Secure Distributed Platform
title_fullStr LHCb: DIRAC Secure Distributed Platform
title_full_unstemmed LHCb: DIRAC Secure Distributed Platform
title_short LHCb: DIRAC Secure Distributed Platform
title_sort lhcb: dirac secure distributed platform
url http://cds.cern.ch/record/1170451
work_keys_str_mv AT casajusa lhcbdiracsecuredistributedplatform
AT gracianir lhcbdiracsecuredistributedplatform