ABSTRACT
In this paper, we present a TeraGrid OAuth service, integrated with the TeraGrid User Portal and TeraGrid MyProxy service, that provides certificates to science gateways. The OAuth service eliminates the need for TeraGrid users to disclose their TeraGrid passwords to science gateways when accessing their individual TeraGrid accounts via gateway interfaces. Instead, TeraGrid users authenticate at the TeraGrid User Portal to approve issuance of a certificate by MyProxy to the science gateway they are using. We present the design and implementation of the TeraGrid OAuth service, describe the underlying network protocol, and discuss design decisions and security considerations we made while developing the service in consultation with TeraGrid working groups and staff.
References
- E. Hammer-Lahav (ed.). The OAuth 1.0 Protocol. IETF RFC 5849 (Informational), April 2010. http://tools.ietf.org/html/rfc5849Google Scholar
- E. Rescorla (ed.). HTTP Over TLS. IETF RFC 2818 (Informational), May 2000. http://tools.ietf.org/html/rfc2818 Google Scholar
Digital Library
- Jim Basney, Marty Humphrey, and Von Welch. The MyProxy Online Credential Repository. Software: Practice and Experience, Volume 35, Issue 9, July 2005, pages 801-816. http://dx.doi.org/10.1002/spe.688 Google Scholar
Digital Library
- Jim Basney, Terry Fleury, and Von Welch. Federated Login to TeraGrid. 9th Symposium on Identity and Trust on the Internet (IDtrust), Gaithersburg, MD, April 2010. http://dx.doi.org/10.1145/1750389.1750391 Google Scholar
Digital Library
- Jim Basney, Von Welch, and Nancy Wilkins-Diehr. TeraGrid Science Gateway AAAA Model: Implementation and Lessons Learned. TeraGrid Conference, August 2010. http://dx.doi.org/10.1145/1838574.1838576 Google Scholar
Digital Library
- Joseph A. Insley, Ti Leggett, and Michael E. Papka. Using Dynamic Accounts to Enable Access to Advanced Resources through Science Gateways. Grid Computing Environments Workshop, 2009. http://dx.doi.org/10.1145/1658260.1658279 Google Scholar
Digital Library
- Marlon Pierce, Suresh Marru, Wenjun Wu, Gopi Kandaswami, Gregor von Laszewski, Rion Dooley, Maytal Dahan, Nancy Wilkins-Diehr, and Mary Thomas. Open Grid Computing Environments. TeraGrid Conference, June 2009.Google Scholar
- Marlon Pierce, Xiaoming Gao, Sangmi Pallickara, Zhenhua Guo, Geoffrey Fox. The QuakeSim Portal and Services: New Approaches to Science Gateway Development Techniques. Concurrency and Computation: Practice and Experience, 22: 1732--1749. http://dx.doi.org/10.1002/cpe.1528 Google Scholar
Digital Library
- Nancy Wilkins-Diehr, Dennis Gannon, Gerhard Klimeck, Scott Oster, and Sudhakar Pamidighantam. TeraGrid Science Gateways and Their Impact on Science. IEEE Computer 41(11): 32--41 (2008). http://dx.doi.org/10.1109/MC.2008.470 Google Scholar
Digital Library
- Nancy Wilkins-Diehr (ed.). Science Gateways: Common Community Interfaces to Grid Resources. Concurrency and Computation: Practice and Experience, 19(6): 743--749 (2007). http://dx.doi.org/10.1002/cpe.1098 Google Scholar
Digital Library
- Nancy Wilkins-Diehr and Thomas Soddemann. Science Gateway, Portal and Other Community Interfaces to High End Resources. ACM/IEEE Conference on Supercomputing (SC '06), 2006. http://dx.doi.org/10.1145/1188455.1188472 Google Scholar
Digital Library
- T. Dierks and E. Rescorla (eds.). The Transport Layer Security (TLS) Protocol. IETF RFC 5246 (Standards Track), August 2008. http://tools.ietf.org/html/rfc5246Google Scholar
- Von Welch, Jim Barlow, James Basney, Doru Marcusiu and Nancy Wilkins-Diehr. A AAAA Model to Support Science Gateways with Community Accounts. Concurrency and Computation: Practice and Experience, 2006. http://dx.doi.org/10.1002/cpe.1081 Google Scholar
Digital Library
- Wenjun Wu, M. E. Papka, R. Stevens. Toward an OpenSocial Life Science Gateway. Grid Computing Environments Workshop, November 2008. http://dx.doi.org/10.1109/GCE.2008.4738450Google Scholar
Cross Ref
- Wenjun Wu, Thomas Uram, Michael Wilde, Mark Hereld, and Michael E. Papka. Accelerating Science Gateway Development with Web 2.0 and Swift. TeraGrid Conference, August 2010. http://dx.doi.org/10.1145/1838574.1838597 Google Scholar
Digital Library
- Zhenhua Guo, Raminderjeet Singh, and Marlon Pierce. Building the PolarGrid Portal Using Web 2.0 and OpenSocial. Grid Computing Environments Workshop, 2009. http://dx.doi.org/10.1145/1658260.1658267 Google Scholar
Digital Library
Index Terms
An OAuth service for issuing certificates to science gateways for TeraGrid users




Comments