首页> 外文会议>42nd annual midwest instruction and computing symposium 2009 >Using KERBEROS to Harden the Active Directory System (LDAP) in a Domain Used to Support Grid/Clustering Activity
【24h】

Using KERBEROS to Harden the Active Directory System (LDAP) in a Domain Used to Support Grid/Clustering Activity

机译:使用KERBEROS强化用于支持网格/集群活动的域中的Active Directory系统(LDAP)

获取原文
获取原文并翻译 | 示例

摘要

The advent of distributed processing and global information systems has driven the need for fast, efficient and secure global authentication systems. Typically distributed processing implies that any given application will require computing resources from multiple computing nodes, and hence for the sake of convenience will require single sign-on capability for the end-user. The user database to support this global authentication process, because it encompasses all hosts in a domain is a prime attack target and requires substantial resources if it is to be adequately protected. To illustrate these concepts a case study was used in which the characteristics of a computing domain were described in detail and the conversion process of this domain from a simple NIS global authentication system to an extremely robust LDAP/Kerberos system was discussed. It was determined that the added complexity and extra work required to implement the LDAP/Kerberos system was well worthwhile due to the vast increase in robustness and scalability observed. Further, this task was carried out at the same time the production hosts were converted from individual physical hosts to virtual machines to provide a "greener" computing environment. Even though this conversion added to the workload the fact that both processes were starting from scratch made it easy to coordinate the needed linkages between the two.
机译:分布式处理和全球信息系统的出现推动了对快速,高效和安全的全球认证系统的需求。通常,分布式处理意味着任何给定的应用程序都将需要来自多个计算节点的计算资源,因此,为了方便起见,最终用户将需要单点登录功能。用户数据库支持此全局身份验证过程,因为它包含域中的所有主机是主要的攻击目标,并且如果要得到充分保护,则需要大量资源。为了说明这些概念,使用了一个案例研究,其中详细描述了计算域的特征,并讨论了该域从简单的NIS全局身份验证系统到极其健壮的LDAP / Kerberos系统的转换过程。已确定,由于观察到的健壮性和可伸缩性大大提高,因此实现LDAP / Kerberos系统所需的额外复杂性和额外工作非常值得。此外,该任务是在将生产主机从单个物理主机转换为虚拟机的同时执行的,以提供“绿色”计算环境。尽管这种转换增加了工作量,但是两个过程都是从头开始的,这使得协调两者之间所需的链接变得容易。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号