FIM at WLCG
FIM4R
Authored by Hannah Short & Berk Balci
Feb 15th 2023
1
WLCG
2
Evolution
3
Towards Tokens
4
2017
2018
2019
Sep. WLCG Token Schema v1.0 Published
April. Schema presented to OpenID Foundation
July. WLCG AuthZ WG Formed
November. Identified Pilot Software Options
March. Identified technical solution (Indigo IAM)
July. Identified Certificate Authority (RCAuth.eu)
February. Privacy Statement agreed and approved by CERN HR
X.509
Tokens
2020
WLCG IAM deployed for CMS and ATLAS
Hackathons demonstrated full token workflow
2021
2022
WLCG IAM deployed for ALICE, LHCb and AMBER
First production workflows (ATLAS and CMS)
WLCG Token Claims
5
Common Claims
ID Tokens
Access Tokens
Note: Where unspecified, the origin is RFC7519 or OpenID Connect core
Access tokens should include at least scope or group
wlcg prefix added to avoid collisions
AAI Design
6
WLCG AuthZ WG
CERN SSO configured as sole Identity Provider, enables identity verification via HR DB (match CERN PersonID)
Follows the AARC Blueprint�https://aarc-community.org/architecture/ but not all AEGIS recommendations
Diagram
7
WLCG AAI Components
HR DB
Membership management & Credential store
VOMS
WLCG Legacy Service (X.509)
WLCG Service (OIDC)
Integration with identity vetting & affiliation dates
Import of existing memberships & credentials from VOMS
VOMS backwards compatibility endpoint
CERN groups
CERN SSO
X.509
AAI Design
8
WLCG AuthZ WG
CERN SSO releases:�
Currently all researchers have CERN accounts but aim is to work towards removing this need in future.
AAI Design
9
WLCG AuthZ WG
CERN Person ID is checked against CERN HR DB. Affiliation with Virtual Organisation (experiment) is verified, as well as end dates.
If the check is OK, the membership is approved.
X.509 Compatibility
10
Deployments
11
IAM Dashboard: https://<experiment>--auth.web.cern.ch�VOMS endpoint: https://voms-<experiment>-auth.app.cern.ch
Deployment technical details
12
Policy
13
Challenges
14