Token Trust & Traceability WG

Europe/Zurich
Description

 

 

Zoom Meeting ID
64974356171
Host
Matthew Steven Doidge
Useful links
Join via phone
Zoom URL

https://codimd.web.cern.ch/Ktl5BrNSR2iX2kgvFTz67A

 

# TTT 4/8/26

Attending: Matt, Maarten, Donald, DaveK, Linda, DaveD

## CHEP Paper, other news
CHEP deadline extension until the end of November. Overleaf doc shared with template in place, onus on Matt and Tom to add some more to it.

--some discussion, got a structure down.
--dont' need to fear repeating
--can copy off ourselves from the last CHEP submission
--ML suggests repetition to allow the paper to stand on its own.

--some discussion of the RA, such as not allowing listing directoriesin any read tokens. Huge protection for abuse of stolen tokens.
--WOuld force scope of listing directories to be made, so it can be explcitly discouraged
--Need to be sure that the spec is respected by the implimentation 

EGI Conference in September - Matt will do the leg work, mostly plan to use the DOMA presentation as a base (make non-DOMA focussed, slightly more in depth introduction to WLCG, and a bit more polish): [DOMA TTT](https://indico.cern.ch/event/1699677/contributions/7148518/attachments/3302362/5907772/TTTforDOMAJune26.pdf)


## Assurance policy document
See google link to draft document.

Discuss Goals, scope. Aim for the draft to be finished by WLCG Workshop in November?

Links:
Existing policy "Approval of Certification Authorities": https://documents.egi.eu/public/ShowDocument?docid=83

IGTF levels of assurance: https://www.igtf.net/ap/authn-assurance/igtf-authn-assurance-1.5.pdf


--ML this would have once been under the remit of the resource evolution taskforce.
ML- have two seperate CA ecosystems at the moment, and user certificates will be gone in a few years.
Do we want to keep IGTF in the long run?
DK - robot certificates? (long term will disappear). Discussion to 
ML - will need to chase the edge cases.
At some point ssl guys might kick out proxies again.
Naive hope that certificate that was good enough for bank should be good enough for a grid service. But might not be happy with the public systems.
DK - some commercial provides are IGTF accredited. 

ML - one of the plans is to make these polcies updatable.

DK - note ELM (used by google) not on the list in the draft. Also notes that in past you needed a valid user cert to request a host certificate.

ML underlying assumptions need to be reasonable

Writing words should be the easy bit.

Need to digest the draft and come up with some questions for next time.

DK - start with thinking what it is the best way of indentifying issuers.

Issuers have OS trusted certificates by default. Convenient for users in their browsers. Happened naturally. scitokens library assumes this.

Discussion of DUNE and ARC.

DaveD says you list only the issuers you trust.

ML need to worry about the slippery slope. But sticking to IGTF is a slippery slope.

Note issue with ARC only has single trust store. Question if changing this behaviour would be worth it - likely not.

Lets Encrypt due to be added to IGTF once client usage has petered out (end of 2027?), only usable of host certificates
DK - afaik lets encrypt haven't asked, unlike google who did.
DD - qould be requested by user (fermilab asked a while back).
DK - discussion with cilogon, I'd be ahppy to trust their service.
DD - rememeber that need to explicitly trust an issuer.
Reason crooks

lets Encrypt might be easier?
How easy would it be to spoof?

ML - similar points came up recently, about how issuers listed on twiki pages that could be messed with  
DD - igtf could give list of issuers

ML - also don't have a list of voms issuers, so this could be something new. IGTF people might be reluctant.

gocdb is VO neutral.

Some of these issues migth need to go into a companion document for the other questions that arise from this - difficulty of spoofing, guard rails etc.

Will create our own document to write down these questions and answer them to the best of our ability- see how this applies to the polcy in question, or elsewhere.

Set up a parallel google doc.

## AOB, Next meeting(s)
Either 18th of 19th of August.

Will try to squeeze a meeting into the first half of September, w/c 7th or 14th.
--Will set up a doodle for this


## To do list
- finished CHEP paper (focus on Matt, Tom)
- rewrite material into EGI presentation and share with group (Matt)
- Trust Assurance policy, set up "side document"

There are minutes attached to this event. Show them.
    • 16:00 16:05
      Actions, Since Last Meeting 5m
    • 16:05 16:20
      Outcomes from CHEP, DOMA, other feedback for the Risk Assessment 15m

      Note slot at EGI2026, extension of CHEP deadline to September.

    • 16:20 16:40
      Discussion - Starting the Token Policy review 20m

      See the document link shared on the list.

    • 16:40 16:45
      AOB, next meeting 5m

      Sneak a meeting in on Wednesday 19th?
      (or maybe Tuesday the 18th?)