Present: Petr V, Tom D (notes), Thomas H, Enrico V, Martin B, Brian B, Roberta M, Jim B, Christophe H, Maarten L, Federica A, Marcelo S, David C, Julie M, Jeffrey G, Xin Z, Tommaso D, Dave D, Andrei T
Apologies: Francesco G
Previous Actions:
- Maarten & Mine: Maarten to start an email thread with EOS about Fermilab switchin off VOMs admin.
- Jim: Update PR paragraph based on discussion and circulate once done.
- Paul: Produce a PR following the "Tokens with groups and explicit AuthZ statements" email thread
Proposed agenda:
- Review actions
- CHEP Submission
- WLCG Workshop final call
Notes:
- Draft:
Since 2017, the Worldwide LHC Computing Grid (WLCG) has been working towards enabling token-based authentication and authorisation throughout its middleware stack. Since the initial publication of the WLCG v1.0 Token Schema in 2019, work has been done to integrate OAuth2.0 token flows across the grid middleware. There are many complex challenges to be addressed before the WLCG can be end-to-end token-based, including not just technical hurdles but interoperability with the wider authentication and authorization landscape.
This paper presents the status of the WLCG deployment work, and how it both affects and is affected by partner communities and parties. The authors also detail how the WLCG’s timeline has progressed, and how it has changed, since its publication. - Tom to upload draft to a google doc for comments
Workshop:
- Have just over a week, the intention is to provide an hour overview and discussion, whilst allowing the extra time we were assigned to be used constructively by others
- Maarten has circulated a draft for comment - email thread or directly
- https://cernbox.cern.ch/s/BNAhNvfRhDopRQC
- Note improvements over the comming months on the IAM side and the deployment side
- Increased FTE support in this area
- Set the scene
- Brian: show some visual representation of how new components map to the old ones
- Discussion on VO specifics of Token flows and how much of this needs to be covered within the talk
Fermi Lab and VOMs Admin:
- This was followed up on with Mine, Julie, Maarten & Steven Timm (VOMs Service manager)
- not had time to run tests yet
- VOMs admin instance no longer needed for instances supporting VOs like DUNE
- Hopefully tests should be simple with eos supporting VOMs natively
- Other admins to be informed of "this is what needs to be done now for dune"
AOB:
- Secondary CERN account with IAM:
- Petr has discovered that this was not possible
- Wrong on both sides
- Issue opened with INDIGO IAM: https://github.com/indigo-iam/iam/issues/524
- No cern_person_id for CERN secondary accounts
- Issue goes beyond registration, it is needed during normal login
- Other issue:
- Only way to load DNs for into accounts is to add it via browser
- This makes it awkward for Robot Accounts
- Petr: should be possible with Rest API and curl scripts
- No current issue for this
- SCIM API being used to manage service accounts for ATLAS
- CMS plan to auto-enroll all but AUP
- Christophe: current issues with robot certificate. In VOMs were two different, but now appear all on one account. Mixture of all.
- Issues around if human account or service account is imported first. If Service is first, it will associate the CERN ID to the service account
- Likely that these issues will be addressed after the workshop
- https://github.com/indigo-iam/iam/issues/527
- WLCG profile
- Currently just storage and compute scopes
- Fine Grain scopes for other services, such as Panda
- Is there any plans to standardize these scopes like EGI did
- GraceDB scopes - http based access service
There are minutes attached to this event.
Show them.