CERN Accelerating science

Single Sign On Update on 24th July

 
Description: 

Next Tuesday (24th July) the Single Sign On (SSO) service will be upgraded to support new services and features:

- Scripted access to SSO enabled web pages, available centrally on Linux as a RPM package (http://cern.ch/linux/docs/cernssocookie.shtml)

- Introduce Two Factor Authentication systems: CERN Smartcards, SMS validated authentication and Yubikeys.

- Introduce a 'Basic Authorization System' which enables at SSO top level (at authentication time) a basic authorization filtering: CERN Users, CERN Externals, Non CERN

- Introduce the concept of E-Groups filters for authorizations at Application level: each application owner will be able to select which E-groups he will need to manage his authorizations, thus avoiding to receive very large tokens containing hundreds of useless E-groups information.

Extended details are available here:
https://espace.cern.ch/authentication/CERN%20Authentication%20Help/SSO%20Update%20July%202012.aspx

Specific Service Detail: 
CERN SSO (Single Sign On)
Reason for this intervention: 

Upgrading features on SSO to prepare for IAA policies currently being discussed.

Effective from date: 
Tuesday, July 24, 2012 - 08:00
End date: 
Tuesday, July 24, 2012 - 08:30
Service Element Affected: 
Identity and Resource Management Application Support
Impact on service: 
Intervention should be transparent
Posted by: 
IT-OIS
Unit responsible for resolution: 
IT Department