Requirements: Security
authentication based on Keberos/SecurID
- this is a particular implementation of ORB and GSSAPI
- NPAC suggests PKI approach for the web access
no need for new “WebFlow” user accounts
- users needs Gateway certificates or “Gateway ID”, though
- mapping between Gateway ID and the user account is needed
- model for authority delegation is needed
access control
- reuse existing database
- AKENTI uses LDAP, ORB uses Access Control Lists