This site uses cookies. By continuing to use this site you agree to our use of cookies. To find out more, see our Privacy and Cookies policy.
The following article is Open access

Role Based Access Control system in the ATLAS experiment

, , , , , , , , , , , , , , , and

Published under licence by IOP Publishing Ltd
, , Citation M L Valsan et al 2011 J. Phys.: Conf. Ser. 331 022042 DOI 10.1088/1742-6596/331/2/022042

1742-6596/331/2/022042

Abstract

The complexity of the ATLAS experiment motivated the deployment of an integrated Access Control System in order to guarantee safe and optimal access for a large number of users to the various software and hardware resources. Such an integrated system was foreseen since the design of the infrastructure and is now central to the operations model. In order to cope with the ever growing needs of restricting access to all resources used within the experiment, the Roles Based Access Control (RBAC) previously developed has been extended and improved. The paper starts with a short presentation of the RBAC design, implementation and the changes made to the system to allow the management and usage of roles to control access to the vast and diverse set of resources. The RBAC implementation uses a directory service based on Lightweight Directory Access Protocol to store the users (∼3000), roles (∼320), groups (∼80) and access policies. The information is kept in sync with various other databases and directory services: human resources, central CERN IT, CERN Active Directory and the Access Control Database used by DCS. The paper concludes with a detailed description of the integration across all areas of the system.

Export citation and abstract BibTeX RIS

Please wait… references are loading.
10.1088/1742-6596/331/2/022042