Migrating Security Components from GT3

1. WS Authentication Framework

While the GT4 version of this component has similar features to the GT3 version, some of the configuration methodology has changed and some features have been enhanced. Refer to Section 3.1.4.5, “Configuring authorization mechanisms” for changes in configuration.

2. Host credentials

GT2 and GT3 services were set up to run with root owned host credentials. In GT4 most, but not all, services will run as the globus user. To allow the globus user to start services using host credentials the globus user needs to be able to access them. This requirement can be satisfied by making a copy of the root owned host credentials, i.e. the host certificate and private key, owned by the globus user. In GT4 this copy is assumed to be /etc/grid-security/container{cert,key}.pem.

3. Community Authorization Service (CAS)

This version is not compatible with the GT3 version of CAS because of protocol changes. To migrate to this version, this component needs to be installed completely independent of any current GT3 CAS installs.

4. MyProxy

No special procedures are required for MyProxy installations migrating from GT3 to GT4. MyProxy is backward compatible.

5. GSI-OpenSSH

No special procedures are required for GSI-OpenSSH installations migrating from GT3 to GT4. GSI-OpenSSH is backward compatible.