1 of 14

FIM at WLCG

FIM4R

Authored by Hannah Short & Berk Balci

Feb 15th 2023

1

2 of 14

WLCG

  • Worldwide LHC (Large Hadron Collider) Computing Grid
  • Used by physicists to perform analysis on data from the LHC
  • Highly distributed, >170 organisations
  • CERN provides 20% of storage & compute

2

3 of 14

Evolution

  • From early 2000s authentication has been X.509 with authorisation added as certificate proxy extensions
  • Since 2017 we have been moving from X.509 to JWT Tokens over OAuth2
  • Why?
    • Easier integration with external services (commercial and research)
    • Remove need for end user certificates. Step towards using identity federation for authentication.

3

4 of 14

Towards Tokens 

4

2017

2018

2019

Sep. WLCG Token Schema v1.0 Published​

April. Schema presented to OpenID Foundation

July. WLCG AuthZ WG Formed

November. Identified Pilot Software Options

March. Identified technical solution (Indigo IAM)

July. Identified Certificate Authority (RCAuth.eu)

February. Privacy Statement agreed and approved by CERN HR

X.509

Tokens

2020

WLCG IAM deployed for CMS and ATLAS

Hackathons demonstrated full token workflow

2021

2022

WLCG IAM deployed for ALICE, LHCb and AMBER

First production workflows (ATLAS and CMS)

5 of 14

WLCG Token Claims

5

Common Claims

    • sub
    • exp
    • iss
    • acr
    • aud
    • iat
    • nbf
    • jti
    • eduperson_assurance (REFEDS)
    • wlcg.ver (WLCG)
    • wlcg.groups (WLCG)

ID Tokens

    • auth_time
    • general OIDC Claims

Access Tokens

    • scope (RFC8693)

Note: Where unspecified, the origin is RFC7519 or OpenID Connect core

Access tokens should include at least scope or group

wlcg prefix added to avoid collisions

6 of 14

AAI Design

6

WLCG AuthZ WG

CERN SSO configured as sole Identity Provider, enables identity verification via HR DB (match CERN PersonID)

Follows the AARC Blueprint�https://aarc-community.org/architecture/ but not all AEGIS recommendations

7 of 14

Diagram

7

WLCG AAI Components

HR DB

Membership management & Credential store

VOMS

WLCG Legacy Service (X.509)

WLCG Service (OIDC)

Integration with identity vetting & affiliation dates

Import of existing memberships & credentials from VOMS

VOMS backwards compatibility endpoint

CERN groups

CERN SSO

X.509

8 of 14

AAI Design

8

WLCG AuthZ WG

CERN SSO releases:�

  • Name,
  • Email,
  • CERN Person ID (indicates HR has performed ID check),
  • CERN Kerberos Principal

Currently all researchers have CERN accounts but aim is to work towards removing this need in future.

9 of 14

AAI Design

9

WLCG AuthZ WG

CERN Person ID is checked against CERN HR DB. Affiliation with Virtual Organisation (experiment) is verified, as well as end dates.

If the check is OK, the membership is approved.

10 of 14

X.509 Compatibility

  • X.509 certificate can be linked
  • Long lived proxy cert can be stored in IAM
  • Available via authenticated REST API (SCIM)
  • Possible to integrate RCAuth
  • Separate project ongoing to allow CERN users access to TCS (GEANT’s certificate authority)

10

11 of 14

Deployments

11

IAM Dashboard: https://<experiment>--auth.web.cern.ch�VOMS endpoint: https://voms-<experiment>-auth.app.cern.ch

12 of 14

Deployment technical details

  • Deployed on CERN’s Openshift infrastructure
  • IAM run in Docker container
  • Configuration managed using CERN’s gitlab
  • Logs sent to elastic search
  • Deployment managed by Kubectl
  • Sectigo certificate for IAM dashboard
  • CERN Grid Host Certificate for VOMS endpoint
    • CERN’s CP/CPS was updated to allow this with EUGridPMA approval

12

13 of 14

Policy

  • Aiming to comply with AEGIS approved “AARC-G071 Guidelines for Secure Operation of Attribute Authorities and issuers of statements for entities” https://doi.org/10.5281/zenodo.5927799
  • Known issues with current deployment e.g. segregation of openshift containers, secret storage
  • Many policies r.e. lifecycle management do not change from previous X.509 based system

13

14 of 14

Challenges

  • Token use
    • Best level of authorisation granularity unclear (few fat tokens vs many thin tokens)
    • Token lifetime of 20m is not practical in reality (experiments have set timelines to 4 days)
  • Several technical hurdles before we can be happy with production readiness of WLCG IAM instances

14