A Credential Renewal Service for Long-Running Jobs

Authors

KOUŘIL Daniel BASNEY Jim

Year of publication 2005
Type Article in Proceedings
Conference Proceedings of the 6th IEEE/ACM International Workshop on Grid Computing (GRID'05)
MU Faculty or unit

Institute of Computer Science

Citation
Keywords long-running jobs; credential renewal; grid authentication and authorization
Description Jobs on the Grid require security credentials throughout their run for accessing secure Grid resources. However, delegating long-lived credentials to long-running jobs brings an increased risk that a credential will be compromised and misused. Additionally, it is often difficult to predict the run-time of jobs on the Grid, due to changes in application performance and resource load, making it difficult to set the lifetime of the delegated credential in advance. We have developed a solution to this problem for the EU DataGrid project using the MyProxy online credential repository and have further evolved it during the EGEE project. This system has been used for credential renewal in Grids in Europe for over three years. In this paper, we present the system design, describe our experiences, and discuss the security implications of this approach.

You are running an old browser version. We recommend updating your browser to its latest version.

More info