CERN IT Governance

Home

❯

topics

❯

Identity architecture

Identity architecture

Properties2
descriptionHub: authentication and authorization for the CERN campus.
tagsidentity

Aug 12, 20261 min read

Identity architecture

One SSO for ~150,000 identities and thousands of applications. The pieces: cern-sso authenticates, the authorization-service-api and gms decide what you are allowed to do, and oidc-integration carries the result to every application as cern-token-claims. The shape of the system is explained by three decisions: decision-leave-adfs, decision-onprem-sso and sso-performance-hardening, held together by authn-authz-decoupling.


Backlinks

  • ADFS (2008–2023)
  • Authentication and authorization are separate engines
  • Authorization Service API
  • CERN SSO
  • The CERN token claims
  • Decision: leave ADFS
  • Decision: on-premise over cloud SSO
  • E-groups (–2026)
  • Group Management System (GMS)
  • OIDC integration at CERN
  • Decision: strip the customisations, externalise the cache
  • IT Governance and Identity Architecture (CERN)

Created with Quartz v5.0.0 © 2026

  • CERN
  • GitHub OKF