Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

WLCG Authorisation from X.509 to Tokens

Conference · · EPJ Web Conf.
The WLCG Authorisation Working Group was formed in July 2017 with the objective to understand and meet the needs of a future-looking Authentication and Authorisation Infrastructure (AAI) for WLCG experiments. Much has changed since the early 2000s when X.509 certificates presented the most suitable choice for authorisation within the grid; progress in token based authorisation and identity federation has provided an interesting alternative with notable advantages in usability and compatibility with external (commercial) partners. The need for interoperability in this new model is paramount as infrastructures and research communities become increasingly interdependent. Over the past two years, the working group has made significant steps towards identifying a system to meet the technical needs highlighted by the community during staged requirements gathering activities. Enhancement work has been possible thanks to externally funded projects, allowing existing AAI solutions to be adapted to our needs. A cornerstone of the infrastructure is the reliance on a common token schema in line with evolving standards and best practices, allowing for maximum compatibility and easy cooperation with peer infrastructures and services. We present the work of the group and an analysis of the anticipated changes in authorisation model by moving from X.509 to token based authorisation. A concrete example of token integration in Rucio is presented.
Research Organization:
Fermi National Accelerator Laboratory (FNAL), Batavia, IL (United States)
Sponsoring Organization:
USDOE Office of Science (SC), High Energy Physics (HEP) (SC-25)
DOE Contract Number:
AC02-07CH11359
OSTI ID:
1842723
Report Number(s):
FERMILAB-CONF-20-758-OCIO; arXiv:2007.03602; oai:inspirehep.net:1832074
Conference Information:
Journal Name: EPJ Web Conf. Journal Volume: 245
Country of Publication:
United States
Language:
English

References (3)

SciTokens: Capability-Based Secure Access to Remote Scientific Data
  • Withers, Alex; Bockelman, Brian; Weitzel, Derek
  • PEARC '18: Practice and Experience in Advanced Research Computing, Proceedings of the Practice and Experience on Advanced Research Computing https://doi.org/10.1145/3219104.3219135
conference July 2018
Beyond X.509: token-based authentication and authorization for HEP journal January 2019
Rucio: Scientific Data Management journal August 2019

Similar Records

WLCG Transition from X.509 to Tokens. Status, Plans, and Timeline
Journal Article · Sun May 05 20:00:00 EDT 2024 · EPJ Web of Conferences (Online) · OSTI ID:2446957

WLCG Token Usage and Discovery
Conference · Thu Dec 31 23:00:00 EST 2020 · EPJ Web Conf. · OSTI ID:1781073

WLCG transition from X.509 to Tokens: Progress and Outlook
Conference · Tue Dec 31 23:00:00 EST 2024 · EPJ Web Conf. · OSTI ID:3009878

Related Subjects