You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Next »

CUWebLogin

  • Provides Kerberos AuthN and Single Sign-On for CUWebAuth
    • Custom solution also developed at Cornell
    • Written in C
  • Is a Kerberos proxy
    • NetID/password is supplied to CUWebLogin over SSL
    • CUWebLogin authenticates via Kerberos AuthN on user's behalf
  • Uses Apache to display login web page
  • Uses CUSSP to transfer information between CUWebAuth and CUWebLogin
  • Uses DBM to store session information
  • Uses Kerberos 4 for NetIDs
  • Uses Kerberos 5 for GuestIDs
  • Will be replaced by CUWebLogin 2.0
    • All new design
  • Production: 2 machines
  • No dynamic load balancing
    • CUWebAuth can be configured to use either of the 2 CUWebLogin servers
  • Fail over happens via CUWebAuth
    • CUWebAuth tries primary CUWebLogin server
    • If that fails, it tries the secondary
  • OS: Solaris 5.9
  • Machines are in server farm (Sun Sparc)
    • Two factor AuthN required for SSH login
    • Machines are split between Rhodes and CCC
  • Test: 2 machines
  • Dev: 2 machines
  • No labels