GT 4.0 Security Features

This section provides details about some of the features of the C and Java GSI implementations.

Table 1. GT 4.0 Security Features

AreaSupported FeatureGT4 C CodeGT4 Java Code
Proxy CertificateAuthentication with RFC 3820 compliant proxy certificatesYesYes
 Authentication with Globus (old OID) proxy certificatesYesYes
 Authentication with legacy (GT2) proxy certificatesAvailable, but unsupportedAvailable, but unsupported
 Delegation of proxy certificatesYesYes
X.509 ExtensionsExtended Key Usage ExtensionYesNo
CA SupportCA Signing PolicyYesNo
 Configurable trust roots (CA certificates)YesYes
RevocationCRLsYesYes
 OCSPNoNo
GSSAPIGSSAPIYes, refer to RFC 2744Yes
  GSSAPI extensions YesYes
 Integrity protection of user dataYesYes
AuthorizationUser Authorization using grid map fileYesYes
 Client-side authorization of service using hostnameYesYes
 Client-side authorization of service with wildcard matching of hostnames (e.g foo matches foo-*, foo-1, foo-bar etc)YesYes
 CAS SupportOnly in GridFTPNo
KerberosRelinking with Kerberos instead of PKIYes (kludgey)Theoretically as part of Java 1.4, but untested
SOAPSOAP independent message signingYesYes
 SOAP independent message encryptionYesYes
 Context establishment in SOAPYesYes
 Secure SOAP dispatch headersNoYes