The old Indico instance is available at
30 November 2020 to 1 December 2020
Zoom Coordinates
America/New_York timezone


Token Based Authorisation for WLCG

30 Nov 2020, 09:05
Zoom Coordinates

Zoom Coordinates

Join Zoom Meeting For passcode, contact: Meeting ID: 956 8279 7458 Dial by your location +1 267 831 0333 US (Philadelphia) +1 786 635 1003 US (Miami) +1 929 205 6099 US (New York) +1 301 715 8592 US (Washington D.C) +1 312 626 6799 US (Chicago) +1 470 250 9358 US (Atlanta) +1 470 381 2552 US (Atlanta) +1 646 518 9805 US (New York) +1 651 372 8299 US (St. Paul) +1 253 215 8782 US (Tacoma) +1 346 248 7799 US (Houston) +1 602 753 0140 US (Phoenix) +1 669 219 2599 US (San Jose) +1 669 900 6833 US (San Jose) +1 720 928 9299 US (Denver) +1 971 247 1195 US (Portland) +1 206 337 9723 US (Seattle) +1 213 338 8477 US (Los Angeles) Meeting ID: 956 8279 7458 Find your local number: Join by SIP Join by H.323 (US West) (US East) (China) (India Mumbai) (India Hyderabad) (Amsterdam Netherlands) (Germany) (Australia) (Hong Kong SAR) (Brazil) (Canada) (Japan) Meeting ID: 956 8279 7458


Token Based Authorisation for WLCG

  • Andrea Ceccanti (INFN)
  • Hannah Short (CERN)
  • Brian Bockelman (CERN)
  • Jim Basney (National Center for Supercomputing Applications)


The WLCG Authorization Working Group was formed in July 2017 with the objective to understand and meet the needs of a future-looking Authentication and Authorization Infrastructure (AAI) for Worldwide LHC Computing Grid (WLCG) experiments. Much has changed since the early 2000s when X.509 certificates presented the most suitable choice for authorization within the grid; progress in token based authorization and identity federation has provided an interesting alternative with notable advantages in usability and compatibility with external (commercial and academic) partners. The need for interoperability in this new model is paramount, as infrastructures and research communities become increasingly interdependent.

Over the past three years, the working group has made significant steps towards defining a system to meet the technical needs highlighted by the community. A token based AAI has been identified, enhanced and deployed to allow several High Energy Physics experiments to integrate their clients and middleware. Key aspects of the work have been possible thanks to externally funded projects, allowing existing AAI components to be adapted to our needs, and individual contributions at several well attended hackathons. A cornerstone of the infrastructure is the reliance on a common token schema in line with evolving standards and best practices, allowing for maximum compatibility and easy cooperation with peer infrastructures and services. This schema is being updated as the working group gains practical experience. We present the progress so far, challenges faced and a look at next steps.

Presentation Materials

Building timetable...