Conveners
LIGO's use of SciTokens
- Derek Weitzel (University of Nebraska, Open Science Grid, SciTokens)
- Jim Basney (National Center for Supercomputing Applications, SciTokens)
- Zach Miller (University of Wisconsin-Madison, HTCondor, SciTokens)
- Duncan Brown (Syracuse University, pyCBC, SciTokens)
- Duncan Meacher (University of Wisconsin-Milwaukee, LIGO)
Description
This panel will discuss ongoing work in LIGO to adopt SciTokens for capability-based access to resources. Panelists will discuss deployment progress on LIGO compute clusters (HTCondor), storage systems (XRootD), and collaboration services (LIGO SegDB), including applicable authorization policies. LIGO is pursuing a hybrid approach with multiple token issuers, including local token issuers on compute cluster login nodes that issue capabilities based on local logins along with a centralized OAuth token issuer (operated by CILogon) that issues capabilities based on LIGO LDAP group memberships. LIGO users do their work mostly on the command-line, so alternatives to OAuth browser-based workflows for token issuance are a priority.