Decision: from X.509 proxies to tokens

X.509 proxies were user-hostile, invisible to browsers, alien to cloud-native tooling — and authorization was all-or-nothing: holding a proxy granted broad rights across entire clusters. The WLCG AuthZ working group chose OAuth2/OIDC with INDIGO IAM as issuer, trading a global PKI for signed, short-lived, capability-scoped tokens.


Topology