GTS 1.3 Administrators Guide
[ GTS: Administrators Guide | Developers Guide | caGrid: Documentation Guides ]
Overview
|
The Globus Toolkit |
The figure illustrates how the GTS can be used to enable the Globus Toolkit to authenticate users against the latest trusted certificate authorities. To accomplish this, the GTS provides a framework called SyncGTS, which is embedded in the Globus runtime to automatically synchronize the local trust certificate store with the latest trust fabric maintained in the GTS. When a Grid service is invoked, Globus authenticates the client by validating that the provided PKI credential is signed by a trusted certificate authority. The certificate is validated against a local store as illustrated by the figure. In the figure below, the Dorian certificate authority has been registered with the GTS as a trusted certificate authority and Globus has been configured to synchronize its local trusted certificate store with the GTS. For example, when an Ohio State University user invokes a Grid service using her Dorian-obtained PKI credential, Globus authenticates her.
Installation
There are two distinct installation scenarios for GTS.
- Installing a Master GTS
When you are installing GTS for a new grid and the GTS instance will be the ultimate authority for which certificate authorities grid services should trust, you are installing GTS in the role of master GTS. The instructions for installing a master GTS are part of the caGrid Installation Guide.
- Installing a Slave GTS
If you are installing a GTS instance that will get its information about which certificate authorities to trust from one or more other GTS instances then you are GTS in the role of slave GTS. Instructions for this type of installation are in the Slave GTS Installation Guide.





