Technical Primer- Directories.ppt
《Technical Primer- Directories.ppt》由会员分享,可在线阅读,更多相关《Technical Primer- Directories.ppt(63页珍藏版)》请在麦多课文档分享上搜索。
1、Technical Primer: Directories,Michael R. Gettes Principal Technologist Georgetown University gettesGeorgetown.EDU http:/www.georgetown.edu/giia/internet2,2,MACE-DIR,Keith Hazelton, Chair, Wisconsin eduPerson objectclass LDAP-Recipe Dir of Dirs for Higher Education (DoDHE) Shibboleth project dir depe
2、ndencies Meta Directories MetaMerge Groups (Dynamic vs. Static; Management) Afilliated Directories (Stitched, Data Link) http:/middleware.internet2.edu/directories,3,MACE-DIR: eduPerson 1.0 (1/22/01 release),MACE initiated (Internet2 + EDUCAUSE)Globally interesting useful attributesGet community buy
3、-in, must use it also eduPersonAffiliation (DoDHE), eduPersonPrincipalName (Shibboleth)“Less is more”, how to use standard objectclasseshttp:/www.educause.edu/eduperson,4,eduPerson 1.5 object class,Included as part of the NSF Middleware Initiative (NMI) Release 1.0 announced today, May 7th eduPerson
4、 1.0 is the production version, 1.5 status is “released for public review” (RPR) Next NMI release will include final 1.5 based on review period discussions,5,eduPerson 1.5 object class,Changes from 1.0:Introductory section addedRFC2252 style definitions included for the eduPerson object class itself
5、 and for each of the eduPerson attributes.Notes on additional attributes from existing object classes, existing notes clarified, syntax and indexing recommendations updated.,6,eduPerson 1.5 object class,Two new attributes: eduPersonPrimaryOrgUnitDN eduPersonEntitlement Simple case: value is the name
6、 of a contract for licensed resource http:/ Values of eduPersonEntitlement can be URLs or URNs,7,eduPerson 1.5 object class,eduPersonEntitlement Values of eduPersonEntitlement can be URLs or URNs http:/www.w3.org/Addressing/ RFC2396 Uniform Resource Identifiers RFC2141 Uniform Resource Names URNs to
7、 allow federation of name creation without name clashes. urn:mace:brown.edu:foo mace-submitinternet2.edu for information on URN registration,8,eduOrg 1.0,eduOrg 1.0 released as “Experimental” object class Basic organizational info attributes from X.520 Telecomm, postal, locale eduOrgHomePageURI eduO
8、rgIdentityAuthNPolicyURI eduOrgLegalName eduOrgSuperiorURI eduOrgWhitePagesURI,9,LDAP-Recipe positioning and the NMI R1,A special case document Pre-existed NMI and MACE document standards for format and naming. Will conform to NMI/MACE naming and future process for acceptance. Content? Well, we shal
9、l see,10,LDAP-Recipe Version 1.5 (pre May 7, 2002),Directory Tree Schema (Design, upgrading, maint) AuthN (binding and pw mgmt) eduPerson attr discussion (select) Access Control Replication Name population,11,LDAP-Recipe Version 2.0 (NMI R1 May 7, 2002),Groups, Groups, Groups Static, Dynamic, app is
10、sues, builds on “NMI Groups Doc” E-Mail Routing considerations Attribute firewalling, Sendmail, app issues eduPersonOrgDN and eduPersonPrimaryOrgUnitDN Original Intent for eduPerson 1.0 and Primary RDN Issues (a must read) Software reference (small, needs to grow),12,MACE-DIR: Directory of Directori
11、es for Higher Education,Web of Data vs. Web of People Prototype: April, 2000 (by M. Gettes) Highly scalable parallel searching Interesting development/research problems Configs, LDAP libraries, Human Interface Realized the need to: Promote eduPerson & common schema Promote good directory design (rec
12、ipe) Work proceeding Sun Microsystems Grant http:/middleware.internet2.edu/dodhe,13,MACE-DIR: DoDHE and LDAP Analyzer,Todd Piket, Michigan Tech (aka Mr. Pinkert) Web based tool to empirically analyze a directoryeduPerson compliance Indexing and naming LDAP-Recipe guidance (good practice)Beta: http:/
13、morpheus.dcs.it.mtu.edu/tcpiket/dodhe,14,MACE-Dir Futures,Technical Advisory Board eduOrg, eduPerson, edu? Shibboleth and other related work Roles (RBAC) Group Implementations (Eileen Shepard, BC; Tom Barton, Memphis) Blue Pages LDAP-Recipe (next?) Affiliated Directories (Rob Banz, UMBC) pkiUser/pki
14、Ca, Bridge CA, etc Video Middleware (commObjectUri OCs) GRID interoperability Directory Policy,15,MACE-Dir Futures (continued),EduOrg “blue page” entriesEduOrgUnit 1.0 object class and attributesAffiliated directories scenarios Identity management in Health Sciences Assembling info on the fly Data/M
15、etadata bundles as units of exchange Exploring with our Technical Advisory Board,16,MACE-SHIBBOLETH,Steven Carmody, Brown, Chair A Biblical pass phrase “password” Get it right or “off with your head” Inter-institutional Authentication/Authorization Web Authorization of Remote Sites with Local Creden
16、tials Authentication via WebISO October, 2001 Demo target http:/middleware.internet2.edu/shibboleth,May, 2002,17,VID-MID Video Middleware,Recently FormedAuthentication and Authorization of H.323 sessions.Client to ClientClient to MCUDirectory enabledHow to find video enabled people?What is necessary
17、 to describe video capabilities?Will likely extend to IP Telephony and so on,18,Technical,Policy,PKI is 1/3 Technical and 2/3 Policy?,19,HEPKI,TAG Technical Activities Group Jim Jokl, Chair, Virginia Mobility, Cert Profiles, PKI-Lite, etc, etc, lots of techno PAG Policy Activities Group Default Chai
18、r, Ken Klingenstein, Colorado Knee-deep in policy, HEBCA, Campus, Subs+RP PKI Labs (AT&T) Neal McBurnett, Avaya Wisconsin-Madison & Dartmouth Industry, Gov., Edu expert guidance http:/www.educause.edu/hepki,20,Bridge CA and Trust Paths,Verisign,Bridge CA,Bridge CA,HE,Policy & Namespace,21,22,Bridge
19、CAs,Higher Education Bridge CA FBCA peeringWe have a draft HEBCA CP (NetEDU PKI WG) FBCA CompatibleHow many HEBCAs? (EDUCAUSE!)Do we really understand PKI implementations with respect to policy needs? (proxy certificates, relying party agreements, name constraints, FERPA, HIPAA, who eats who?)BCA se
20、ems to be the most promising perspective. Will each person be a BCA?Does ALL software (Client/Server) need to be changed?Mitretek announces new BCA deployment model 2/15/2001 Scalable & deployable Server plug-ins make client changes less likely,23,domainComponent (DC=) Naming,Traditional X.500 namin
21、g: cn=Michael R Gettes, ou=Server Group, ou=UIS, o=Georgetown University, c=USdomainComponent (DC) naming: uid=gettes,ou=People,dc=georgetown,dc=eduHEPKI is issuing guidance and advice on DC= naming,24,Attributes for PKI,Store them in a Certificate? Attributes persist for life of Certificate No need
22、 for Directory or other lookup The Certificate itself becomes the AuthZ control point Store them in a Directory? Very light-weight Certificates Requires Directory Access Long-term Certificate, Directory is AuthZ control point. How many Certificates will we have? Pseudonymous Certificates,25,David Wa
23、sleys PKI Puzzle,Were Building A “Bridge Over The River PKI”,A word about “Portals”,28,Portals: Authentication,Security is not easyif it was, then everyone would be doing it. Applications MUST NOT handle authentication Dont assume you will have access to passwords at the portalThe portal is YAA (yet
24、 another application)but portals have web servers to do the dirty workportals can trust the web server to authenticateand pass “identity” on to the portal,29,Portals: Authorization,Security is not easyif it was, then everyone would be doing it. Applications should handle authorizationThe portal is Y
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
2000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- TECHNICALPRIMERDIRECTORIESPPT
