Experiences with Integrating Custos SecurityServices
Isuru Ranawaka, Samitha Liyanage, Dannon Baker, Alexandru Mahmoud,, Juleen Graham, Terry Fleury, Dimuthu Wannipurage, Yu Ma, Enis Afgan, Jim, Basney, Suresh Marru, Marlon Pierce

TL;DR
This paper discusses the integration of Custos, an open-source cybersecurity service for science gateways, highlighting its deployment scenarios, hierarchical tenant management, and support for non-browser applications.
Contribution
It introduces extended deployment scenarios for Custos, demonstrating hierarchical tenant management and support for service accounts beyond previous work.
Findings
Hierarchical tenant management enables federation of multiple gateways.
Custos supports non-browser applications with service accounts.
Extended deployment scenarios enhance security and scalability.
Abstract
Science gateways are user-facing cyberinfrastruc-ture that provide researchers and educators with Web-basedaccess to scientific software, computing, and data resources.Managing user identities, accounts, and permissions are essentialtasks for science gateways, and gateways likewise must man-age secure connections between their middleware and remoteresources. The Custos project is an effort to build open sourcesoftware that can be operated as a multi-tenanted service thatprovides reliable implementations of common science gatewaycybersecurity needs, including federated authentication, iden-tity management, group and authorization management, andresource credential management. Custos aims further to provideintegrated solutions through these capabilities, delivering end-to-end support for several science gateway usage scenarios. Thispaper examines four deployment scenarios using Custos…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsScientific Computing and Data Management · Distributed and Parallel Computing Systems · Research Data Management Practices
