Re: Forge Project proposal: PSE-ABC
Vanessa Williams <[email protected]> Mon, 12 Jun 2006 11:36:28 -0400
| Newsgroups | gmane.comp.java.jxta.user |
|---|---|
| Message-ID | <[email protected]> |
We certainly need a good example of how to use the PSE stuff. I get requests for help all the time (sadly, I have almost none to give.) Whether it should be a separate project or not, I leave to others more familiar with what should and should not go into the programmer's guide. Perhaps it could be an expanded tutorial? With the code eventually contributed to commons? Just thoughts... Vanessa On 12-Jun-06, at 10:49 AM, Bruno Margerin wrote: > Hi, > > I would like to propose a modest “forge level” project about PSE > security. This project (PSE-ABC) aims at providing the ABC of the > PSE Membership, hence to lower the learning curve of using the > basics of PSE Membership. The project's goal is to provide easily > re-usable and/or copy/pastable code and documentation for a typical > PSE Membership use. > > The code will provide examples for both basic certificates / > private key usage as well as of use more JXTA specific technologies > such as PSE membership, TLS and Access Control. > > Specifically for Certificates manipulation: > • Issuing a self signed certificate authority > • Issuing a “SuperPeer” / Administrator Certificate/PKey, having > the CA sign the associate signing request, and import the resulting > signed certificates back. > • Issuing 2 edges peers (Peer A and Peer B) Certificates/PKeys and > have the SuperPeer / Administrator sign the signing request and the > edge peers import the resulting signed certificates. > • Manage associated Keystores and associated chains of trust on > each 4 entities (CA, Super/Administrator Peers, and the 2 edge peers). > > For simplicity, while using the JXTA utils, this initial security > infrastructure will be build “off line”, not using the JXTA > platform. I don’t aims at implementing any distributed trust model > such as JXTA Poblano for instance. Again the goal of this project > is to introduce PSE Membership. > > As for the PSE Membership and associated technologies, the scenario > would be to: > • Have the Super Peer create/publish and join a PSE Peer Group. > • Have the 2 Edge Peers (Peer A and Peer B) join this group. > • Have an Edge Peer (Peer A), create an access controlled JXTA > Socket where Peer B would connect via TLS. The access control > mechanism would be an “all or nothing” access based and whether > Peer A and Peer B has “common roots” in their chain of trust. > > I first though that such an example could be contributed within the > JXTA programmer’s guide, but given the expected volume of code, I > am now thinking that it may make the guide overly heavy and need to > be taken outside the guide, as a separate project/tutorial. > > I am neither a JXTA nor a security expert and would rely on the > community for ensuring that I am understanding and using the > security and JXTA tools correctly and to best practices. > > Last, I would also appreciate feed back in whether or when this > forge project should be integrated in the JXTA commons. > > Please let me know what you think, > Thanks, > > Bruno Margerin > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > -- Vanessa Williams Oponia Networks [email protected]