2020
DOI: 10.1051/epjconf/202024503001
|View full text |Cite
|
Sign up to set email alerts
|

WLCG Authorisation from X.509 to Tokens

Abstract: The WLCG Authorisation Working Group was formed in July 2017 with the objective to understand and meet the needs of a future-looking Authentication and Authorisation Infrastructure (AAI) for WLCG experiments. Much has changed since the early 2000s when X.509 certificates presented the most suitable choice for authorisation within the grid; progress in token based authorisation and identity federation has provided an interesting alternative with notable advantages in usability and compatibility with external (c… Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
9
0

Year Published

2021
2021
2023
2023

Publication Types

Select...
5
1

Relationship

1
5

Authors

Journals

citations
Cited by 9 publications
(9 citation statements)
references
References 3 publications
0
9
0
Order By: Relevance
“…This transition will be achieved by using the OpenID Connect (OIDC) [37] identity layer on top of the OAuth2 protocol [38]. Rucio supports OIDC authentication [39] and this is already being tested in the DOMA Rucio instance [40]. In the context of ESCAPE an initial testing phase is also ongoing where those functionalities are examined with the aim of demonstrating completely X.509 free access to the resources.…”
Section: Data Lake Architecturementioning
confidence: 99%
“…This transition will be achieved by using the OpenID Connect (OIDC) [37] identity layer on top of the OAuth2 protocol [38]. Rucio supports OIDC authentication [39] and this is already being tested in the DOMA Rucio instance [40]. In the context of ESCAPE an initial testing phase is also ongoing where those functionalities are examined with the aim of demonstrating completely X.509 free access to the resources.…”
Section: Data Lake Architecturementioning
confidence: 99%
“…The WLCG Authorisation Working Group was formed in 2017, at a time when multiple activities were independently beginning to seriously consider token based authorisation. Experts from multiple domains and projects -including SciTokens [4], the INDIGO DataCloud project [5] and EGI [6] -came together to chart a path towards token based authorisation for WLCG [7]. Work to enhance software was supported by several European Commission Projects: EOSC-Hub [8], EOSC Pilot [9] and AARC2 [10].…”
Section: Contributing Groupsmentioning
confidence: 99%
“…Moving away from X.509 is not something experiments can do in isolation, and requires a concerted effort. Work to adopt a token AAI based on the industry standard protocols like Oauth2.0 and OpenID Connect is ongoing at the WLCG level [23].…”
Section: Authentication and Authorisation Implementationsmentioning
confidence: 99%