Directories and Certificates.ppt
《Directories and Certificates.ppt》由会员分享,可在线阅读,更多相关《Directories and Certificates.ppt(103页珍藏版)》请在麦多课文档分享上搜索。
1、Directories and Certificates,Renee Woodten Frost Project Manager, Internet2 Middleware Initiative I2 Middleware Liaison, University of Michigan. And an ensemble of hundreds,ACUTA August 1, 2001,Topics,Acknowledgements What is Middleware? Core middleware: the basic technologies Directories Issues, ar
2、chitecture, good practices Current activities - LDAP Recipe, eduPerson, MACE-Dir, Directory of Directories, Metadirectories Certificates PKI fundamentals Current events in PKI Shibboleth Where to watch,ACUTA August 1, 2001,Internet2,Mission: Develop and deploy advanced network applications and techn
3、ologies, accelerating the creation of tomorrows Internet.Goals: Enable new generation of applications Re-create leading edge Research and Education network capability Transfer technology and experience to the global production Internet,ACUTA August 1, 2001,Middleware Initiatives Acknowledgements,MAC
4、E and the working groups Early Harvest - NSF catalytic grant and meeting Early Adopters testbed campuses Higher Education partners - campuses, EDUCAUSE, CREN, AACRAO, NACUA, etc. Corporate partners - IBM, ATT, Sun, et al. Government partners - including NSF and the fPKI TWG,ACUTA August 1, 2001,MACE
5、 (Middleware Architecture Committee for Education),Purpose - to provide advice, create experiments, foster standards, etc. on key technical issues for core middleware within higher education Membership - Bob Morgan (UW) Chair, Steven Carmody (Brown), Michael Gettes (Georgetown), Keith Hazelton (Wisc
6、onsin), Paul Hill (MIT), Jim Jokl (Virginia), Mark Poepping (CMU), David Wasley (California), Von Welch (Grid) Creates working groups in major areas, including directories, inter-realm authentication, PKI, medical issues, video, etc. Works via conference calls, emails, occasional serendipitous in-pe
7、rson meetings.,ACUTA August 1, 2001,Early Harvest,NSF funded workshop in Fall 99 and subsequent activitiesDefined the territory and established a work planBest practices in identifiers, authentication, and directories (http:/middleware.internet2.edu/best-practices.html)http:/middleware.internet2.edu
8、/earlyharvest/,ACUTA August 1, 2001,Early Adopters: The Campus Testbed Phase,A variety of roles and missionsCommitment to move implementation forwardProvided some training and facilitated supportDevelop national models of deployment alternativesAddress policy standardsProfiles and plans are on Inter
9、net2 middleware site,ACUTA August 1, 2001,Early Adopter Participants,Dartmouth U. of Hawaii Johns Hopkins U. of Maryland, BC U. of Memphis U. of Michigan,Michigan Tech U. U. of Pittsburgh U. of Southern Cal U. of Tennessee, Memphis Tufts U.,ACUTA August 1, 2001,Partnerships,EDUCAUSE CREN Grids, JA-S
10、IG, OKI Campuses Higher education professional associations - AACRAO, NACUA, CUMREC, etc. Increasing international interactions Corporate - IBM, Sun, ATT, etc.,ACUTA August 1, 2001,Remedial IT architecture,The proliferation of customizable applications requires a centralization of “customizations”Th
11、e increase in power and complexity of the network requires access to user profilesElectronic personal security services is now an impediment to the next-generation computing gridsInter-institutional applications require interoperational deployments of institutional directories and authentication,ACU
12、TA August 1, 2001,What is Middleware?,Specialized networked services that are shared by applications and users A set of core software components that permit scaling of applications and networks Tools that take the complexity out of application integration A second layer of the IT infrastructure, sit
13、ting above the network A land where technology meets policy The intersection of what networks designers and applications developers each do not want to do,ACUTA August 1, 2001,Specifically,Digital libraries need scalable, interoperable authentication and authorization. The Grid is a new paradigm for
14、 a computational resource; Globus provides middleware, including security, location and allocation of resources, and scheduling. This relies on campus-based services and inter-institutional standards. Instructional Management Systems need authentication and directories. Next-generation portals want
15、common authentication and storage. Academic collaboration requires restricted sharing of materials between institutions. What Internet1 did with communication, Internet2 may do with collaboration.,ACUTA August 1, 2001,A Map of Middleware,ACUTA August 1, 2001,The Grid,A model for a distributed comput
16、ing environment, addressing diverse computational resources, distributed databases, network bandwidth, object brokering, security, etc. Globus (www.globus.org) is the software that implements most of these components; Legion is another such software environment Needs to integrate with campus infrast
17、ructure Gridforum (www.gridforum.org) umbrella activity of agencies and academics Look for grids to occur locally and nationally, in physics, earthquake engineering, etc.,ACUTA August 1, 2001,Core Middleware,Identity - unique markers of who you (person, machine, service, group) areAuthentication - h
18、ow you prove or establish that you are that identityDirectories - where an identitys basic characteristics are keptAuthorization - what an identity is permitted to doPKI, etc - emerging tools for security services,ACUTA August 1, 2001,What is the nature of the work?,Technological Establish campus-wi
19、de services: name space, authentication Build an enterprise directory service Populate the directory from source systems Enable applications to use the directory Policies and Politics Clarify relationships between individuals and institution Determine who manages, who can update and who can see comm
20、on data Structure information access and use rules between departments and central administrative units Reconcile business rules and practices,ACUTA August 1, 2001,What are the benefits to the institution?,Economies for central IT - reduced account management, better web site access controls, tighte
21、r network security. Economies for distributed IT - reduced administration, access to better information feeds, easier integration of departmental applications into campus-wide use. Improved services for students and faculty - access to scholarly information, control of personal data, reduced legal e
22、xposures. Participation in future research environments - Grids, videoconferencing, etc. Participation in new collaborative initiatives Directory of Directories, Shibboleth, etc.,ACUTA August 1, 2001,What are the costs to the institution?,Modest increases in capital equipment and staffing requiremen
23、ts for central IT Considerable time and effort to conduct campus wide planning and vetting processes One-time costs to retrofit some applications to new central infrastructure One-time costs to build feeds from legacy source systems to central directory services The political wounds from the reducti
24、on of duchies in data and policies,ACUTA August 1, 2001,OIDs to reference identifiers,Numeric coding to uniquely define many middleware elements, such as directory attributes and certificate policiesNumbering is only for identification (are two OIDs equal? If so, the associated objects are the same)
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
2000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- DIRECTORIESANDCERTIFICATESPPT
