WLCG Authorisation from X.509 to Tokens

Paper by the WLCG Authorization Working Group (arXiv:2007.03602, CHEP proceedings).

What it anchors

  • The pain points of the X.509/VOMS model: user-hostile certificates, poor browser and cloud-native integration, coarse-grained authorization.
  • The selection of INDIGO IAM as the token issuer for WLCG and the plan to migrate the infrastructure to OAuth2/OIDC-based flows.