CERN Authentication and Authorization Services
The goal of the new CERN Authentication and Authorization Services are to provide a centralized authentication and authorization infrastructure.
The main components of the services are:
- A Single Sign-On service, based on Keycloak, providing federated and social authentication and supporting SAML and OIDC protocols.
- A Users Portal, where users can manage their own accounts.
- A Group Management System (GMS), where users can define and manage access control groups and mailing lists.
- An Applications Portal, where application owners can register their applications for Single Sign-On and configure the applications' authorization schemes.
- A Resources Portal, where users can visualize and manage their subscriptions to IT services and list their resources.
- The Authorization Service API that can be used to automate the users, groups, resources and applications management.
Several additional services are operated by the same team:
- WLCG IAM instances, that act as OAuth Token Issuers for CERN Experiment participants to access grid computing.
- Certificate Authorities, that provides digital certificates for CERN users, hosts and services.
Roadmap (updated for Q3 2025)
The roadmaps show our team's current plans, by area of activity.
We plan our activities quarterly. Any request for features not currently in our plans will be considered at the next quarterly planning.
Some of the activities headers provide links to the corresponding epic task in our Jira project, if you want to follow the team's progress more closely.
Please note that the times provided are rough estimates, and that priorities can change over time.
Single Sign On | ||||||||||||||
Current What we work on now (Q3 2025) |
Near-term What we plan working on next (Q4 2025 - Q1 2026) |
Future What we investigate |
||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
|
||||||||||||
Groups Management System (GMS) | ||||||||||||||
Current What we work on now (Q3 2025) |
Near-term What we plan working on next (Q4 2025 - Q1 2026) |
Future What we investigate |
||||||||||||
|
|
|
||||||||||||
Resources Management | ||||||||||||||
Current What we work on now (Q3 2025) |
Near-term What we plan working on next (Q4 2025 - Q1 2026) |
Future What we investigate |
||||||||||||
|
|
|
||||||||||||
Certificate Authority | ||||||||||||||
Current What we work on now (Q3 2025) |
Near-term What we plan working on next (Q4 2025 - Q1 2026) |
Future What we investigate |
||||||||||||
|
|
|||||||||||||
WLCG IAM | ||||||||||||||
Current What we work on now (Q3 2025) |
Near-term What we plan working on next (Q4 2025 - Q1 2026) |
Future What we investigate |
||||||||||||
|
|
Recent Highlights
Q2 2025
- Successfully integrated OpenStack and Google Workspace into the newly redesigned Resources Portal. Significant progress made towards the goals of the Eligibility Project.
- Approaching feature completion for GMS, with a significant number of clients actively migrating.
- Implemented the synchronisation of ORCID IDs from the HR system into the Authorization Service, with ORCID management possible via the Users Portal.
- Completed cleanup of several legacy Single Sign-On (SSO) components, including the 2FA realm and the Keycloak bridge.
- Implemented password policy enhancements in alignment with Cyber Security Audit requirements.
- Decommissioned legacy EDH password management features.
- DBOD upgrades completed on time with minimal impact to services.
Q1 2025
- Released new synchronisation functionality for the GMS platform.
- Upgraded Single Sign-On (SSO) infrastructure to Keycloak version 24.
- Enabled authentication support for the European Open Science Cloud via SSO.
- Integrated an enhanced eduGAIN discovery service to improve user experience.
- Optimised database logic, resulting in significant performance improvements for SSO and the Authorization Service, benefiting systems such as Eligibility, GMS, and Accounts.
Contact
See the dedicated contact page with ways to reach us and to stay in touch.