160 likes | 278 Views
Roadmap to European Middleware Is it different? Ton.Verschuren@SURFnet.NL TERENA Networking Conference Antalya, May 2001. Contents. ( European) middleware? Global trends Directories Public Key Infrastructure Inter-domain authorisation Summary. What is Middleware?.
E N D
Roadmap to European Middleware Is it different? Ton.Verschuren@SURFnet.NL TERENA Networking Conference Antalya, May 2001
Contents • (European) middleware? • Global trends • Directories • Public Key Infrastructure • Inter-domain authorisation • Summary
What is Middleware? the intersection of the stuff that network engineers don’t want to do with the stuff that applications developers don’t want to do -- Ken Klingenstein
What is European Middleware? Stuff that the Europeans don´t want to do? Stuff that only the Europeans want to do? Is there no such thing as European middleware?
The European Environment • Legislation • Privacy • Habits • Cultural differences
Global Trends (1) • IP over everything & everything over IP • Middleware near the intersection applications middleware IP transmission
Global Trends (2) • Reduced complexity in layers • Dumber cores & smarter edges • AAA functions at the edge: • DiffServ • authenticate locally, act globally
Roadmap to the Middleware Track • Directories • Public Key Infrastructures • Inter-domain authorisation
Directories • History: X.500 /Paradise • A single global Directory Information Tree was never realised • Exit X.500; enter LDAP v2 -> v3 • An European NREN White Pages service • Centralised service by DANTE (the glue) • Index & search experimental service: GIDS • Start moving from WP to DEN
Directories (cont’d) • IETF LDAP developments: • Ldapext, co-chaired by Roland Hedberg • Ldup • Ldapbis • Does LDAP fit our needs? • David Chadwick • Schema issues • X.521 vs. Domain Component • EduPerson by Keith Hazelton
Directories (cont’d) • Directories for videoconferencing: • Internet2 vidmid • European collaboration & co-ordination • Terena TF-LSD • GRID developments • Web2ldap • Michael Ströder
PKI • European directives: • Digital Signatures Directive (to be implemented on 1 July 2001) • European Signature Standardization Initiative • Qualified Certificates (not for NREN´s?) • National differences wrt crypto legislation • EuroPKI • Antonio Lioy
PKI (cont’d) • Deployment just started; not all issues well understood • Start bottom up • Client cert for SSL (http, imap, ipsec, …) • Integration with directories • Bottom line is trust
Inter-domain Authorisation • Disclosing credentials beyond your administrative domain: • Publishers • Tele-education • Grids • Increased flexibility: • Better than IP address-based authentication • Increased security: • Weak u/p replaced by e.g. certificate
Inter-domain Authorisation (cont’d) • Various attempts to create a system: • Athens • PAPI • STPA • Gestalt • Shibboleth • Longer-term architecture: • IRTF AAAARCH RG
Summary • There is no such thing as European middleware • But there is an European environment! • Start experimenting to understand the issues • Strong drive from the R&E community • Interoperability should be reached through • Standards • Collaboration