50 likes | 149 Views
Auth/Authz at PSU. Steve Kellogg Director, Advanced Information Technologies Academic Services and Emerging Technologies Information Technologies Services The Pennsylvania State University. Penn State. 24 Campuses 140,000+ users (being managed) Single Identity; Penn State Access Account
E N D
Auth/Authz at PSU Steve Kellogg Director, Advanced Information Technologies Academic Services and Emerging Technologies Information Technologies Services The Pennsylvania State University
Penn State • 24 Campuses • 140,000+ users (being managed) • Single Identity; Penn State Access Account • AFS/K4 (circa 1991) • DCE/DFS (circa 1995)
General Philosophy • Few scalable components • Security is very important • A single enterprise-wide digital identity • A single account and services/resources are allocated and de-allocated to the account. • Standards-based approach • A preference for build v. buy.
Components • Registry/directory • Authentication system • Authorization; user and group • A secure distributed interprocess communication mechanism • A scalable, secure single filesystem integrated via the same auth/authz mechanisms
Modern Components • Kerberos V • LDAP • Authorization • Attributes • Groups • Distributed IPC • HTTPS POST • XMLRPC • Filesystem?????