160 likes | 173 Views
Explore the concept of European middleware and its unique characteristics, including factors such as legislation, privacy, and cultural differences. Discover global trends, such as IP convergence and reduced complexity, and delve into key aspects like directories, public key infrastructure, and inter-domain authorization. Gain insights into the European environment and the need for experimentation, standards, and collaboration.
E N D
Roadmap to European Middleware Is it different? Ton.Verschuren@SURFnet.NL TERENA Networking Conference Antalya, May 2001
Contents • (European) middleware? • Global trends • Directories • Public Key Infrastructure • Inter-domain authorisation • Summary
What is Middleware? the intersection of the stuff that network engineers don’t want to do with the stuff that applications developers don’t want to do -- Ken Klingenstein
What is European Middleware? Stuff that the Europeans don´t want to do? Stuff that only the Europeans want to do? Is there no such thing as European middleware?
The European Environment • Legislation • Privacy • Habits • Cultural differences
Global Trends (1) • IP over everything & everything over IP • Middleware near the intersection applications middleware IP transmission
Global Trends (2) • Reduced complexity in layers • Dumber cores & smarter edges • AAA functions at the edge: • DiffServ • authenticate locally, act globally
Roadmap to the Middleware Track • Directories • Public Key Infrastructures • Inter-domain authorisation
Directories • History: X.500 /Paradise • A single global Directory Information Tree was never realised • Exit X.500; enter LDAP v2 -> v3 • An European NREN White Pages service • Centralised service by DANTE (the glue) • Index & search experimental service: GIDS • Start moving from WP to DEN
Directories (cont’d) • IETF LDAP developments: • Ldapext, co-chaired by Roland Hedberg • Ldup • Ldapbis • Does LDAP fit our needs? • David Chadwick • Schema issues • X.521 vs. Domain Component • EduPerson by Keith Hazelton
Directories (cont’d) • Directories for videoconferencing: • Internet2 vidmid • European collaboration & co-ordination • Terena TF-LSD • GRID developments • Web2ldap • Michael Ströder
PKI • European directives: • Digital Signatures Directive (to be implemented on 1 July 2001) • European Signature Standardization Initiative • Qualified Certificates (not for NREN´s?) • National differences wrt crypto legislation • EuroPKI • Antonio Lioy
PKI (cont’d) • Deployment just started; not all issues well understood • Start bottom up • Client cert for SSL (http, imap, ipsec, …) • Integration with directories • Bottom line is trust
Inter-domain Authorisation • Disclosing credentials beyond your administrative domain: • Publishers • Tele-education • Grids • Increased flexibility: • Better than IP address-based authentication • Increased security: • Weak u/p replaced by e.g. certificate
Inter-domain Authorisation (cont’d) • Various attempts to create a system: • Athens • PAPI • STPA • Gestalt • Shibboleth • Longer-term architecture: • IRTF AAAARCH RG
Summary • There is no such thing as European middleware • But there is an European environment! • Start experimenting to understand the issues • Strong drive from the R&E community • Interoperability should be reached through • Standards • Collaboration