The old Indico instance is available at http://indico-memoria.rnp.br
30 November 2020 to 1 December 2020
Zoom Coordinates
America/New_York timezone

Session

Fermilab's experience transitioning to token-based AAI technologies.

1 Dec 2020, 10:00
Zoom Coordinates

Zoom Coordinates

Join Zoom Meeting https://cmu.zoom.us/j/95682797458 For passcode, contact: dsimmel@psc.edu filus@psc.edu Meeting ID: 956 8279 7458 Dial by your location +1 267 831 0333 US (Philadelphia) +1 786 635 1003 US (Miami) +1 929 205 6099 US (New York) +1 301 715 8592 US (Washington D.C) +1 312 626 6799 US (Chicago) +1 470 250 9358 US (Atlanta) +1 470 381 2552 US (Atlanta) +1 646 518 9805 US (New York) +1 651 372 8299 US (St. Paul) +1 253 215 8782 US (Tacoma) +1 346 248 7799 US (Houston) +1 602 753 0140 US (Phoenix) +1 669 219 2599 US (San Jose) +1 669 900 6833 US (San Jose) +1 720 928 9299 US (Denver) +1 971 247 1195 US (Portland) +1 206 337 9723 US (Seattle) +1 213 338 8477 US (Los Angeles) Meeting ID: 956 8279 7458 Find your local number: https://cmu.zoom.us/u/acnDsIhJso Join by SIP 95682797458@zoomcrc.com Join by H.323 162.255.37.11 (US West) 162.255.36.11 (US East) 221.122.88.195 (China) 115.114.131.7 (India Mumbai) 115.114.115.7 (India Hyderabad) 213.19.144.110 (Amsterdam Netherlands) 213.244.140.110 (Germany) 103.122.166.55 (Australia) 209.9.211.110 (Hong Kong SAR) 64.211.144.160 (Brazil) 69.174.57.160 (Canada) 207.226.132.110 (Japan) Meeting ID: 956 8279 7458

Conveners

Fermilab's experience transitioning to token-based AAI technologies.

  • Jeny Teheran (Fermilab)
  • David Dykstra (Fermilab)
  • Mine Altunay Cheung (Fermilab)

Description

As Fermilab becomes the host laboratory for international collaborations like DUNE, it is our goal to provide transparent access to computing resources for all of our scientific user community across organizational and national boundaries. Fermilab's Federated Identities project aims to integrate our current infrastructure with Federated-based Authentication and Authorization Infrastructure (AAI) technologies. Our goal is enabling scientific user's access without the burden of managing additional user accounts and forcing users to hold an extra set of authentication credentials.

Fermilab started working with internal and external scientific services providers in order to transition away from X.509 certificates for user authentication towards newer technologies such as OAuth, OpenID Connect and JSON Web Tokens. During this session, we will present the updates we have made to our architecture to integrate token-based technologies. We will discuss the progress we made by integrating our authorization attributes repository (FERRY) with a token issuer operated by CILogon. An important addition to our current architecture is the deployment of a new online credential repository (Vault) in replacement of MyProxy. We will also discuss the current challenges we are facing, especially maintaining compliance with DoE security policies and requirements while expanding our current infrastructure with novel authentication and authorization mechanisms.

Presentation Materials

Building timetable...