Thursday March 18, 2021 Liaison Meeting Minutes
https://indico.bnl.gov/event/11069/
In addition to the uploaded presentation materials, the following QA and discussion was noted:
Facility News
- HEPIX Spring ’21 wrapping up now, upcoming sPHENIX review and Atlas T1
Experimental Support
- what auth for the upcoming XROOTD testbed (see Fabric below)
- 1. Internal 2. Read privilege for all 3. R/W privilege limited for only a small set of users
- StashCache data federation will re-visit later (no ETA yet)
- currently only 1 collaboration writes by using x509; moving to SciTokens
- we will integrate federation with JLAB storage
General Services
- data transfers, new server pair: sftp.sdcc.bnl.gov for sftp replaces rftpexp servers (not for gridftp)
- ETA for replacements is flexible maybe 1 or 2 month
Fabric
- initial XROOTD testbed (initially without federation) in few weeks
Tools and Services
- 6 BNL presentations at HEPIX
- https://indico.cern.ch/event/995485/timetable/#all.detailed
- Liaisons reach out to Chris Lepore and Louis Pelosi for access to add/edit the SDCC website
Status of Indico Activities
- currently operated by ITD with local accounts, allowing creation with any email address
- we will continue to work with ITD on the next iteration of Indico and external LDAP integration
- why add federated ID? Requests are coming for Single Sign On. Local accounts will remain
- regarding members-only categories/events, A) add users by hand or B) LDAP integration is scaleable and long term
- SSO reduces friction (on the order of 700 Indico accounts are a gmail email address) if we allowed certain IDPs
- CILogon, eduroam, AD, key cloak, gmail, Facebook, GitHub, etc…
- local accounts may be a security problem: 2 defacements ocurred where anyone could edit a public event
- concerning past public meetings accessibility in the future, we are asking to solidify guidelines for what can and cannot be public
- we can then evaluate past events on a case by case basis to determine how to make public again
- possibly with a contact managers logging in and meeting the guidelines for public event or by simply enforcing a Passcode#
- issue will be if an event is public and the parent group is private then users must have the URL can’t browse to event
- Indico has calendar which can link the events
- other groups in NPP not represented in this meeting
- we are contacting groups and content managers to review our proposals before proceeding to ITD
- we plan to gather list of all Category Managers (many) and share this proposal and invite Q/A
There are minutes attached to this event.
Show them.