NCSA Home
Contact Us | Intranet | Search

Cyberinfrastructure Seminar Series

Tuesday, September 6, 2005

Using the MyProxy Online Credential Repository
Jim Basney , NCSA
11:00 AM - 12:30 PM (PDT)
1:00   PM - 2:30 PM (CDT)
3000 NCSA Building via AG

The MyProxy (http://myproxy.ncsa.uiuc.edu/) online credential repository provides secure and convenient storage for grid security credentials.

MyProxy is mature, open source software for the Globus Toolkit that has been used by the grid community for over four years, in projects such as NEESgrid, TeraGrid, EU DataGrid, and the NASA Information Power Grid. MyProxy is included in the NSF Middleware Initiative GRIDS Center software distribution and is included in the Globus Toolkit 4.0 release.

MyProxy allows users to easily obtain a proxy credential from the repository, without requiring users to manage private key and certificate files. Grid portals use MyProxy to obtain proxy credentials, so users can access secure grid resources via the portal interface. Job management software, such as Condor-G, uses MyProxy to renew credentials for long-running jobs. MyProxy can also be integrated with CA software, such as the Globus Simple CA, to ease credential distribution.

A well-managed MyProxy repository can provide better security for user private keys when compared to the typical solution of storing keys on end-user desktop systems. MyProxy can enforce policies on the passphrases used to protect user keys and can provide the ability to monitor key usage to detect or track misuse. MyProxy can also be integrated with local site authentication systems, such as Kerberos and one-time passwords, to bridge between local site security and grid security.

In this talk, I'll describe how MyProxy is used in practice today, covering basic setup, integration with portals, job managers, and CAs, and new features added in recent MyProxy releases.

The Cyberinfrastructure Seminar Series is a set of presentations on cyberinfrastructure and related research organized by NCSA and SDSC. These seminars are available on site at the presenting institution and remotely via the Access Grid. For more details regarding the AG venue for this seminar, please refer to: http://agschedule.ncsa.uiuc.edu/meetingdetails.asp?MID=9804. All Access Grid sites are welcome to participate in this seminar. If you have any questions, contact Jennie File, NCSA Training & Outreach Group.