Permit Server

  • Provides central AuthZ for Cornell
  • Custom solution developed at Cornell
    • Written in C
    • Uses CUSSP to send requests and receive responses
    • Uses GDBM to store AuthZ information
  • Each request is authenticated via Kerberos 4
  • No load balancing
  • Fail over provided by Sun cluster software
  • OS: Solaris 5.9 cluster
  • Machines are in server farm. (Sun Sparc)
    • Two factor AuthN required for SSH login
  • Production: 3 node cluster, shared with some other IdM services
  • Test: 2 node cluster
  • Dev: 2 node cluster
  • Planned to be replaced by Grouper
  • No labels