Scitokens/Xrootd-Scitokens: Flexible Authorization Handling

Scitokens/Xrootd-Scitokens: Flexible Authorization Handling
复制标题

Scitokens/Xrootd-Scitokens:灵活的授权处理

DOI:
10.5281/zenodo.1206217
复制
发表时间:
2018
期刊:
High Performance Distributed Computing, 2003. Proceedings. 12th IEEE International Symposium on
影响因子:
--
通讯作者:
D. Weitzel
D. Weitzel
中科院分区:
--
文献类型:
--
作者:
B. Bockelman;D. Weitzel

文献摘要

被引文献

相似文献

在此版本中,我们通过以下三个功能显著改进了授权处理: base_path现在可以采用逗号分隔的路径列表,允许单个颁发者覆盖文件系统命名空间的多个部分。 restricted_path被引入。此选项限制允许颁发者在其基本区域内为其颁发授权的路径。它旨在简化迁移到现有存储的基于SciToken的设置,其中多个组共享相同的基本区域。 default_user被引入。这提供了在凭证中为通过scitokens授权的请求设置用户名的能力。它允许系统管理员将颁发者的文件系统访问映射到特定的Unix用户名。
In this release, we significantly improve the authorization handling with the following three features: base_path can now take a comma-separated list of paths, allowing a single issuer to cover multiple parts of the filesystem namespace. restricted_path was introduced. This option restricts the paths the issuer is allowed to issue authorizations for within its base area(s). It is intended to ease the migrations to a SciTokens-based setup for existing storages where multiple groups share a same base area. default_user was introduced. This provides the ability to set the username in the credential for requests that pass the scitokens authorization. It allows the sysadmin to map the filesystem access of an issuer to a specific Unix username.