Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Demonstrator workflow

1.Group "PRACE" is empty on B2ACCESS and there is no user like "Michal Jankowski" in B2ACCESS

Image Modified

Image Modified

2.

User "/C=PL/O=GRID/O=PSNC/CN=Michal Jankowski" cannot access EUDAT resource at gsiftp://eptest.eudat.psnc.pl

Image Modified
3.There is no local user account mapped to "/C=PL/O=GRID/O=PSNC/CN=Michal Jankowski" on eptest.eudat.psnc.pl.
Image Modified
4.

Users with attribute deisaUserProfile set to “EUDAT” are selected from PRACE LDAP.

The same selection is done by prace_eudat_users_sync.py script, that synchronizes PRACE LDAP and B2ACCESS. Normally the script is called periodically (e.g. hourly), but for the demo it may be run manually by the admin.

Image Modified
5.After the script run, the user  "/C=PL/O=GRID/O=PSNC/CN=Michal Jankowski" appear in B2ACCESS and group "PRACE" contains PRACE users.
Image Modified
6.

User "/C=PL/O=GRID/O=PSNC/CN=Michal Jankowski" can access EUDAT resource at gsiftp://eptest.eudat.psnc.pl

Image Modified
7.Local user account provisioning and grid mapping are done automatically on user login.
Image Modified
8.

Attribute deisaUserProfile with value “EUDAT” is removed from user "Michal Jankowski" in PRACE LDAP.

Image Modified
9.As the result of prace_eudat_users_sync.py script run the user is removed from PRACE group in B2ACCESS (but not completely from the service).

Image Modified

Image Modified

10.

User "/C=PL/O=GRID/O=PSNC/CN=Michal Jankowski" cannot access EUDAT resource at gsiftp://eptest.eudat.psnc.pl

Image Modified
11.The local account still exists, but the user is removed from the grid mapping.
Image Modified

 

Resources

  1. Unity IDM GitHub

...

  • Being evaluated by EUDAT
  • Group synchronisation will be added

B2ACCESS -> B2STAGE ”old” mechanism:

  • Ready for evaluation

B2ACCESS -> B2STAGE ”new” mechanism:

  • Proof of concept