Apologies: Tom D
Present: Maarten, Hannah, Liz, Thomas H, Martin B, Dimitrios C, Mine A, Petr V, Julie, Roberta, Federica, David K, Francesco, Enrico, Douglas, Dave D, Max F
Notes: (please send corrections)
- Token Transition Timeline document has been published https://zenodo.org/record/7014668
- A 2 year Graduate has been approved to work on WLCG IAM
- A second Graduate has been approved for FTS and may work on integration
- For Rucio, Dimitrios will take over as the contact (started in August)
- We can create a new version when there are sufficient changes
- JDL (Job Description)/Scopes/Groups discussion & Subject for Token Issuer & list of issuers
- Not the right people in the room
- Petr - not sure why we would need more granular functionality (this is about defining policies in IAM)
- Compute scopes are too simplistic (comment from Brian a while ago), but unclear what they should become
- Thomas - how would access rights be kept in sync with local user accounts (posix)
- Petr - it's not a problem. This will be defined by dcache devs. Normally use groups/roles rather than user mapping.
- Discussion about how to allow legacy methods to continue to work
- When will IAM 1.8 be available for ATLAS? CNAF is testing this week, if all ok can plan for coming weeks. Even if transparent we will publish a service intervention OTG.
- Instances for ALICE and LHCb are in progress
- Several development enhancements are deemed important for IAM (see https://indico.cern.ch/event/1191146/?note=207352), these weren't prioritised. Some we may be able to live with for some time, others are more urgent. Several have already been addressed.
- Official issues should be added to IAM on Github
- Move to agile rollout mechanism, do releases often when a few issues are fixed
- Q from Petr, can we skip registration and just create people when they appear in the HR DB?
- In some cases this is a necessary checkpoint for VO admins to perform other actions
- Did we ever try to change the IAM private key?
- We should do this annually (?)
- No experience so far from CNAF
- Hannah will add to the Jira for service operations for WLCG IAM
- CHEP submission?
- Maarten to start a thread
- Possibly better not to be submitted from CERN
- Upcoming meetings
Actions:
There are minutes attached to this event.
Show them.