27–31 Mar 2023
Research Center for Environmental Changes (RCEC), Academia Sinica
Asia/Taipei timezone

Status of CERN Authentication and Authorisation

27 Mar 2023, 16:15
25m
1F Conference Room (Research Center for Environmental Changes (RCEC), Academia Sinica )

1F Conference Room

Research Center for Environmental Changes (RCEC), Academia Sinica

128 Academia Road, Section 2 Nankang, Taipei 11529 Taiwan 25°2′45″N 121°36′37″E
Basic IT Services & End User Services Basic IT Services & End User Services

Speaker

Asier Aguado Corman (CERN)

Description

Authentication and Authorisation is the core service to secure access for computing resources at any large-scale organisation. At CERN we handle around 25,000 logins per day of 35,000 individual users, granting them access to more than 9,000 applications and websites that use the organisation's Single Sign-On (SSO). To achieve this, we have built an Identity and Access Management platform based on open source and commercial software. CERN has also many different needs and use cases, which needed to be adapted or implemented by leveraging existing solutions and protocols. These needs included a general need for machine-to-machine automated authentication, CLI access and two-factor authentication (2FA). We will describe our authentication landscape and focus on key challenges that we hope will be relevant for other communities.

Primary authors

Asier Aguado Corman (CERN) Hannah Short (CERN) Adeel Ahmad (CERN) Maria Fava (CERN) Sebastian Lopienski (CERN) Antonio Nappi (CERN) Paolo Tedesco (CERN)

Presentation materials