Grid Authentication and Authorization with Reliably Distributed Services (GAARDS) is the security infrastructure of caGrid. It provides services and tools for the administration and enforcement of security policy in an enterprise Grid: 1) Grid user management, 2) identity federation, 3) trust management, 4) group/VO management 5) Access Control Policy management and enforcement, and 5) Integration between existing security domains and the Grid security domain. It consists of (a) Dorian: A Grid service for the provisioning and management of Grid users accounts; (b) Grid Trust Service (GTS): A Grid-wide mechanism for maintaining and provisioning a federated trust fabric consisting of trusted certificate authorities, allowing Grid services to make authentication decisions against the most recent information; (c) Grid Grouper: A group-based authorization solution for the Grid; and (d) Authentication Service: A framework for issuing SAML assertions for existing credential providers so they may easily integrate with Dorian and other Grid credential providers.





