This document proposes a security policy and architecture for computational grids. The key points are:
1. The security policy is designed to integrate heterogeneous trust domains while allowing each domain to enforce its own local security policies.
2. The policy focuses on authentication to allow single sign-on for users and processes across domains, while delegating access control to local policies.
3. It defines global and local subjects, with partial mappings between them, to support single sign-on while respecting local naming schemes.
4. The policy requires mutual authentication for cross-domain operations and allows locally authenticated subjects to access resources according to local access control policies.
5. It enables processes to act on behalf of users with deleg