60 likes | 200 Views
Reflections. Many different ways of converting “global” credentials to a “local” UID So what? Understand what information is used, how Example: implicit importance primary group “No X support in software Y” If it is important, clear the agenda for the people that can fix the problem
E N D
Many different ways of converting “global” credentials to a “local” UID • So what? • Understand what information is used, how • Example: implicit importance primary group • “No X support in software Y” • If it is important, clear the agenda for the people that can fix the problem • GIN and OGSA-AuthZ efforts • Both audiences need input!
Too complex or not? • "/VO=alice/GROUP=/alice/ROLE=lcgadmin":::sgm:"/VO=alice/GROUP=/alice/ROLE=production":::prd:"/VO=alice/GROUP=/alice"::::"/VO=atlas/GROUP=/atlas/ROLE=lcgadmin":::sgm:"/VO=atlas/GROUP=/atlas/ROLE=production":::prd:"/VO=atlas/GROUP=/atlas"::::"/VO=cms/GROUP=/cms/ROLE=lcgadmin":::sgm:"/VO=cms/GROUP=/cms/ROLE=production":::prd:"/VO=cms/GROUP=/cms/GROUP=HeavyIons":cms01:1340::"/VO=cms/GROUP=/cms/GROUP=Higgs":cms02:1341::"/VO=cms/GROUP=/cms/GROUP=StandardModel":cms03:1342::"/VO=cms/GROUP=/cms/GROUP=Susy":cms04:1343::"/VO=cms/GROUP=/cms"::::"/VO=lhcb/GROUP=/lhcb/ROLE=lcgadmin":::sgm:"/VO=lhcb/GROUP=/lhcb/ROLE=production":::prd:"/VO=lhcb/GROUP=/lhcb"::::"/VO=dteam/GROUP=/dteam/ROLE=lcgadmin":::sgm:"/VO=dteam/GROUP=/dteam/ROLE=production":::prd:"/VO=dteam/GROUP=/dteam"::::"/VO=biomed/GROUP=/biomed/ROLE=lcgadmin":::sgm:"/VO=biomed/GROUP=/biomed/ROLE=production":::prd:"/VO=biomed/GROUP=/biomed"::::
Opening up the floor • Do we have an end-to-end solution? • Roles, Groups, Capabilities, Mappings, ACLs, Configuration • Do we need to agree on semantics or not? • Software X,Y,Z pluggability • OGSA-AuthZ and GIN both in need of input • This is a resource management problem! • Mohammed/Mountain rather thanAlexander/Gordian knot • Identify the problems we really have to solve