Participants: Adeel, Alison, Andrei, Andrii, Balazs, Dave, Doug, Enrico, Francesco, Ian, Irwin, Jeny, Jim, Joao, John, Julie, Maarten (notes), Manuel, Marcelo, Matthias, Max, Mischa, Petr, Roberta, Stefano

Notes:  (please send corrections)

Maarten summarized the support that can be expected for the IAM services at CERN:

For the next few months it would be somewhat risky to rely on the IAM instances at CERN for short-lived tokens. Incidents outside working hours might not be resolved until the next business day. Token lifetimes could in principle be increased to a few days. However, there are expectations in some libraries that lifetimes are a few hours at most. We would need to make those expectations more configurable (could still be a good idea).

Dave then pointed out that we only need pilot submission tokens at this time and that those tokens do not have to come from IAM. ATLAS and CMS can set up their own pilot token providers, imitating what is already in place for LIGO. Jim agreed scitokens.org would be a good place to host the required details, already being HA and well-supported:

This approach now looks the way forward and possibly even part of the long-term solution. HTCondor CEs will just need to have more trusted issuers included in their configurations. Stefano asked for guidance beyond the ad-hoc recipes being used today. Maarten acknowledged we need to capture examples and best practices e.g. in our Twiki area.

Actions:

 

Next meeting:  Feb 17.