Best practices of user account management with virtual organization based access to grid

  • Authors:
  • Jiří Denemark;Michał Jankowski;Aleš Křenek;Luděk Matyska;Norbert Meyer;Miroslav Ruda;Paweł Wolniewicz

  • Affiliations:
  • Faculty of Informatics, Masaryk University, Brno, Czech Republic;Poznań Supercomputing and Networking Center, Poznań, Poland;Institute of Computer Science, Masaryk University, Brno, Czech Republic;Institute of Computer Science, Masaryk University, Brno, Czech Republic;Poznań Supercomputing and Networking Center, Poznań, Poland;Institute of Computer Science, Masaryk University, Brno, Czech Republic;Poznań Supercomputing and Networking Center, Poznań, Poland

  • Venue:
  • PPAM'05 Proceedings of the 6th international conference on Parallel Processing and Applied Mathematics
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Scalable and fine-grained Grid authorization requires the move away from gridmap-file based access control and 1-to-1 mappings to individual operating system user accounts. This is recognized and addressed by virtual organization authorization services and user management systems e. g. Virtual Organization Membership Service (VOMS), Local Centre Authorization System (LCAS), Local Credential MAPping Service (LCMAPS) and Community Authorization Service (CAS). They do, however, not address user operating system account management and isolation/sandboxing requirements, such as flexible pooling of accounts while maintaining auditing records. In this paper we compare existing systems which solve the above shortcomings and are currently used in real production grids.