Re: Forge Project proposal: PSE-ABC
Bruno Margerin <[email protected]> Mon, 12 Jun 2006 12:54:07 -0400
| Newsgroups | gmane.comp.java.jxta.user |
|---|---|
| Message-ID | <[email protected]> |
Vanessa, Thanks for your feedbacks, I indeed would like to see it turned into a tutorial, and see PSE-ABC project just as a shell, a mean of inviting the community to contribute. Mike has already written a good tutorial with some snipplet of code. I certainly use that for the code I am putting together, not to mention his insights from JXTA Townhall. Maybe the PSE-ABC project should expend his existing tutorial. I am just trying to contribute my limited knowledge on that matter, and hope that with the community's contribution, it could mature into something useful. I believe that along with SRDI, the PSE membership, and especially what it actually is and isn't are among the most "mysterious" part of the JXTA platform implementation. Yet I believe both are critically important. I've banged my head quite a bit digging into PSE, and am still confuse on many of its aspects, but I hope to be able to contribute to make it easier to understand. Bruno Margerin Vanessa Williams wrote: > We certainly need a good example of how to use the PSE stuff. I get > requests for help all the time (sadly, I have almost none to give.) > Whether it should be a separate project or not, I leave to others more > familiar with what should and should not go into the programmer's > guide. Perhaps it could be an expanded tutorial? With the code > eventually contributed to commons? Just thoughts... > > Vanessa > > On 12-Jun-06, at 10:49 AM, Bruno Margerin wrote: > >> Hi, >> >> I would like to propose a modest “forge level†project about PSE >> security. This project (PSE-ABC) aims at providing the ABC of the PSE >> Membership, hence to lower the learning curve of using the basics of >> PSE Membership. The project's goal is to provide easily re-usable >> and/or copy/pastable code and documentation for a typical PSE >> Membership use. >> >> The code will provide examples for both basic certificates / private >> key usage as well as of use more JXTA specific technologies such as >> PSE membership, TLS and Access Control. >> >> Specifically for Certificates manipulation: >> • Issuing a self signed certificate authority >> • Issuing a “SuperPeer†/ Administrator Certificate/PKey, having the >> CA sign the associate signing request, and import the resulting >> signed certificates back. >> • Issuing 2 edges peers (Peer A and Peer B) Certificates/PKeys and >> have the SuperPeer / Administrator sign the signing request and the >> edge peers import the resulting signed certificates. >> • Manage associated Keystores and associated chains of trust on each >> 4 entities (CA, Super/Administrator Peers, and the 2 edge peers). >> >> For simplicity, while using the JXTA utils, this initial security >> infrastructure will be build “off lineâ€, not using the JXTA platform. >> I don’t aims at implementing any distributed trust model such as JXTA >> Poblano for instance. Again the goal of this project is to introduce >> PSE Membership. >> >> As for the PSE Membership and associated technologies, the scenario >> would be to: >> • Have the Super Peer create/publish and join a PSE Peer Group. >> • Have the 2 Edge Peers (Peer A and Peer B) join this group. >> • Have an Edge Peer (Peer A), create an access controlled JXTA Socket >> where Peer B would connect via TLS. The access control mechanism >> would be an “all or nothing†access based and whether Peer A and Peer >> B has “common roots†in their chain of trust. >> >> I first though that such an example could be contributed within the >> JXTA programmer’s guide, but given the expected volume of code, I am >> now thinking that it may make the guide overly heavy and need to be >> taken outside the guide, as a separate project/tutorial. >> >> I am neither a JXTA nor a security expert and would rely on the >> community for ensuring that I am understanding and using the security >> and JXTA tools correctly and to best practices. >> >> Last, I would also appreciate feed back in whether or when this forge >> project should be integrated in the JXTA commons. >> >> Please let me know what you think, >> Thanks, >> >> Bruno Margerin >> >> --------------------------------------------------------------------- >> To unsubscribe, e-mail: [email protected] >> For additional commands, e-mail: [email protected] >> > > -- > Vanessa Williams > Oponia Networks > [email protected] > > > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] >