Cargando…

x509-free access to WLCG resources

Access to WLCG resources is authenticated using an x509 and PKI infrastructure. Even though HEP users have always been exposed to certificates directly, the development of modern Web Applications by the LHC experiments calls for simplified authentication processes keeping the underlying software unm...

Descripción completa

Detalles Bibliográficos
Autores principales: Short, H, Manzi, A, De Notaris, V, Keeble, O, Kiryanov, A, Mikkonen, H, Tedesco, P, Wartel, R
Lenguaje:eng
Publicado: 2017
Materias:
Acceso en línea:https://dx.doi.org/10.1088/1742-6596/898/10/102001
http://cds.cern.ch/record/2298176
_version_ 1780956990069014528
author Short, H
Manzi, A
De Notaris, V
Keeble, O
Kiryanov, A
Mikkonen, H
Tedesco, P
Wartel, R
author_facet Short, H
Manzi, A
De Notaris, V
Keeble, O
Kiryanov, A
Mikkonen, H
Tedesco, P
Wartel, R
author_sort Short, H
collection CERN
description Access to WLCG resources is authenticated using an x509 and PKI infrastructure. Even though HEP users have always been exposed to certificates directly, the development of modern Web Applications by the LHC experiments calls for simplified authentication processes keeping the underlying software unmodified. In this work we will show a solution with the goal of providing access to WLCG resources using the user’s home organisations credentials, without the need for user-acquired x509 certificates. In particular, we focus on identity providers within eduGAIN, which interconnects research and education organisations worldwide, and enables the trustworthy exchange of identity-related information. eduGAIN has been integrated at CERN in the SSO infrastructure so that users can authenticate without the need of a CERN account. This solution achieves x509-free access to Grid resources with the help of two services: STS and an online CA. The STS (Security Token Service) allows credential translation from the SAML2 format used by Identity Federations to the VOMS-enabled x509 used by most of the Grid. The IOTA CA (Identifier-Only Trust Assurance Certification Authority) is responsible for the automatic issuing of short-lived x509 certificates. The IOTA CA deployed at CERN has been accepted by EUGridPMA as the CERN LCG IOTA CA, included in the IGTF trust anchor distribution and installed by the sites in WLCG. We will also describe the first pilot projects which are integrating the solution.
id oai-inspirehep.net-1638222
institution Organización Europea para la Investigación Nuclear
language eng
publishDate 2017
record_format invenio
spelling oai-inspirehep.net-16382222021-02-09T10:07:42Zdoi:10.1088/1742-6596/898/10/102001http://cds.cern.ch/record/2298176engShort, HManzi, ADe Notaris, VKeeble, OKiryanov, AMikkonen, HTedesco, PWartel, Rx509-free access to WLCG resourcesComputing and ComputersAccess to WLCG resources is authenticated using an x509 and PKI infrastructure. Even though HEP users have always been exposed to certificates directly, the development of modern Web Applications by the LHC experiments calls for simplified authentication processes keeping the underlying software unmodified. In this work we will show a solution with the goal of providing access to WLCG resources using the user’s home organisations credentials, without the need for user-acquired x509 certificates. In particular, we focus on identity providers within eduGAIN, which interconnects research and education organisations worldwide, and enables the trustworthy exchange of identity-related information. eduGAIN has been integrated at CERN in the SSO infrastructure so that users can authenticate without the need of a CERN account. This solution achieves x509-free access to Grid resources with the help of two services: STS and an online CA. The STS (Security Token Service) allows credential translation from the SAML2 format used by Identity Federations to the VOMS-enabled x509 used by most of the Grid. The IOTA CA (Identifier-Only Trust Assurance Certification Authority) is responsible for the automatic issuing of short-lived x509 certificates. The IOTA CA deployed at CERN has been accepted by EUGridPMA as the CERN LCG IOTA CA, included in the IGTF trust anchor distribution and installed by the sites in WLCG. We will also describe the first pilot projects which are integrating the solution.oai:inspirehep.net:16382222017
spellingShingle Computing and Computers
Short, H
Manzi, A
De Notaris, V
Keeble, O
Kiryanov, A
Mikkonen, H
Tedesco, P
Wartel, R
x509-free access to WLCG resources
title x509-free access to WLCG resources
title_full x509-free access to WLCG resources
title_fullStr x509-free access to WLCG resources
title_full_unstemmed x509-free access to WLCG resources
title_short x509-free access to WLCG resources
title_sort x509-free access to wlcg resources
topic Computing and Computers
url https://dx.doi.org/10.1088/1742-6596/898/10/102001
http://cds.cern.ch/record/2298176
work_keys_str_mv AT shorth x509freeaccesstowlcgresources
AT manzia x509freeaccesstowlcgresources
AT denotarisv x509freeaccesstowlcgresources
AT keebleo x509freeaccesstowlcgresources
AT kiryanova x509freeaccesstowlcgresources
AT mikkonenh x509freeaccesstowlcgresources
AT tedescop x509freeaccesstowlcgresources
AT wartelr x509freeaccesstowlcgresources