4–5 Feb 2019
CERN
Europe/Zurich timezone
There is a live webcast for this event.

Progress in token-based auth for the WLCG

5 Feb 2019, 15:10
25m
513/1-024 (CERN)

513/1-024

CERN

50
Show room on map

Speaker

Brian Paul Bockelman (University of Nebraska Lincoln (US))

Description

In 2018, as part of the effort to replace the use of the Globus Toolkit's security infrastructure, a flurry of new approaches toward token-based authentication and authorization were attempted in the WLCG. This includes work in token formats (such as SciTokens, Macaroons, or WLCG JWT) and token acquisition workflows. After a year of experimentation, some common patterns are starting to emerge.

The token-based approach - relying on describing the bearer's capabilities - is a more flexible scheme than the traditional GSI setup, which relies on identity mapping. In this presentation, I'll outline the difference between the two and take a tour through the different token schemes. I'll discuss the new feature support in XRootD for these different authorization techniques.

Primary author

Brian Paul Bockelman (University of Nebraska Lincoln (US))

Presentation materials