Re: Forge Project proposal: PSE-ABC

Bruno Margerin <[email protected]> Mon, 12 Jun 2006 12:54:07 -0400
Newsgroups gmane.comp.java.jxta.user
Message-ID <[email protected]>
Vanessa,

Thanks for your feedbacks,
I indeed would like to see it turned into a tutorial, and see PSE-ABC 
project just as a shell, a mean of inviting the community to contribute.
 Mike has already written a good  tutorial with some snipplet of code. I 
certainly use that  for the code I am putting together, not to mention 
his insights from JXTA Townhall. Maybe the PSE-ABC project should expend 
his existing tutorial. I am just trying to contribute my limited 
knowledge on that matter, and hope that with the community's 
contribution, it could mature into something useful.

I believe that along with SRDI, the PSE membership, and especially what 
it actually is and isn't  are among the most "mysterious"  part of the 
JXTA platform implementation. Yet I believe both are critically 
important. I've banged my head quite a bit digging into PSE, and am 
still confuse on many of its aspects, but I hope to be able to 
contribute to make it easier to understand.

Bruno Margerin

Vanessa Williams wrote:
> We certainly need a good example of how to use the PSE stuff. I get 
> requests for help all the time (sadly, I have almost none to give.) 
> Whether it should be a separate project or not, I leave to others more 
> familiar with what should and should not go into the programmer's 
> guide. Perhaps it could be an expanded tutorial? With the code 
> eventually contributed to commons? Just thoughts...
>
> Vanessa
>
> On 12-Jun-06, at 10:49 AM, Bruno Margerin wrote:
>
>> Hi,
>>
>> I would like to propose a modest “forge level†project about PSE 
>> security. This project (PSE-ABC) aims at providing the ABC of the PSE 
>> Membership, hence to lower the learning curve of using the basics of 
>> PSE Membership. The project's goal is to provide easily re-usable 
>> and/or copy/pastable code and documentation for a typical PSE 
>> Membership use.
>>
>> The code will provide examples for both basic certificates / private 
>> key usage as well as of use more JXTA specific technologies such as 
>> PSE membership, TLS and Access Control.
>>
>> Specifically for Certificates manipulation:
>> • Issuing a self signed certificate authority
>> • Issuing a “SuperPeer†/ Administrator Certificate/PKey, having the 
>> CA sign the associate signing request, and import the resulting 
>> signed certificates back.
>> • Issuing 2 edges peers (Peer A and Peer B) Certificates/PKeys and 
>> have the SuperPeer / Administrator sign the signing request and the 
>> edge peers import the resulting signed certificates.
>> • Manage associated Keystores and associated chains of trust on each 
>> 4 entities (CA, Super/Administrator Peers, and the 2 edge peers).
>>
>> For simplicity, while using the JXTA utils, this initial security 
>> infrastructure will be build “off lineâ€, not using the JXTA platform. 
>> I don’t aims at implementing any distributed trust model such as JXTA 
>> Poblano for instance. Again the goal of this project is to introduce 
>> PSE Membership.
>>
>> As for the PSE Membership and associated technologies, the scenario 
>> would be to:
>> • Have the Super Peer create/publish and join a PSE Peer Group.
>> • Have the 2 Edge Peers (Peer A and Peer B) join this group.
>> • Have an Edge Peer (Peer A), create an access controlled JXTA Socket 
>> where Peer B would connect via TLS. The access control mechanism 
>> would be an “all or nothing†access based and whether Peer A and Peer 
>> B has “common roots†in their chain of trust.
>>
>> I first though that such an example could be contributed within the 
>> JXTA programmer’s guide, but given the expected volume of code, I am 
>> now thinking that it may make the guide overly heavy and need to be 
>> taken outside the guide, as a separate project/tutorial.
>>
>> I am neither a JXTA nor a security expert and would rely on the 
>> community for ensuring that I am understanding and using the security 
>> and JXTA tools correctly and to best practices.
>>
>> Last, I would also appreciate feed back in whether or when this forge 
>> project should be integrated in the JXTA commons.
>>
>> Please let me know what you think,
>> Thanks,
>>
>> Bruno Margerin
>>
>> ---------------------------------------------------------------------
>> To unsubscribe, e-mail: [email protected]
>> For additional commands, e-mail: [email protected]
>>
>
> -- 
> Vanessa Williams
> Oponia Networks
> [email protected]
>
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>