A credential renewal service for long-running jobs

Daniel Kouřil, Jim Basney

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Jobs on the Grid require security credentials throughout their run for accessing secure Grid resources, such as GridFTP data repositories. However, delegating long-lived credentials to long-running jobs brings an increased risk that a credential will be compromised and misused. Additionally, it is often difficult to predict the run-time of jobs on the Grid, due to changes in application performance and resource load, making it difficult to set the lifetime of the delegated credential in advance. We have developed a solution to this problem for the EU DataGrid project using the MyProxy online credential repository and have further evolved it during the EGEE project. Users store their long-lived credentials in a dedicated MyProxy server and delegate short-lived credentials to their jobs. When a job's credential nears expiration, the Workload Management System retrieves a new short-lived credential from the MyProxy server on the user's behalf and uses it to refresh the job's credential. The MyProxy server's policy specifies which services may obtain credentials on the user's behalf, and all operations are logged at the MyProxy server, where access to credentials may be restricted if a compromise is detected or suspected. This system has been used for credential renewal in Grids in Europe for over three years. In this paper, we present the system design, describe our experiences, and discuss the security implications of this approach.

Original languageEnglish (US)
Title of host publicationProceedings of the 6th IEEE/ACM International Workshop on Grid Computing
Pages63-68
Number of pages6
DOIs
StatePublished - 2005
Event6th IEEE/ACM International Workshop on Grid Computing - Seattle, WA, United States
Duration: Nov 13 2005Nov 14 2005

Publication series

NameProceedings - IEEE/ACM International Workshop on Grid Computing
Volume2005
ISSN (Print)1550-5510

Other

Other6th IEEE/ACM International Workshop on Grid Computing
CountryUnited States
CitySeattle, WA
Period11/13/0511/14/05

ASJC Scopus subject areas

  • Engineering(all)

Fingerprint Dive into the research topics of 'A credential renewal service for long-running jobs'. Together they form a unique fingerprint.

Cite this