| Issue |
EPJ Web Conf.
Volume 337, 2025
27th International Conference on Computing in High Energy and Nuclear Physics (CHEP 2024)
|
|
|---|---|---|
| Article Number | 01170 | |
| Number of page(s) | 7 | |
| DOI | https://doi.org/10.1051/epjconf/202533701170 | |
| Published online | 07 October 2025 | |
https://doi.org/10.1051/epjconf/202533701170
CMS Token Transition
1 Morgridge Institute for Research, 330 N Orchard Street, Madison WI, USA
2 CERN, European Organization for Nuclear Research, Espl. des Particules 1, 1217 Geneve, Switzerland
3 INFN, Perugia, Umbria, Italy
4 Fermilab National Accelerator Laboratory, Wilson Road, Batavia, IL 60510, USA
5 University of California at San Diego, San Diego, CA, USA
6 University of Notre Dame, Notre Dame, IN, USA
7 University of Wisconsin, Madison, WI, USA
1 Corresponding author: bbockelman@morgridge.org
2 Corresponding author: lammel@cern.ch
Published online: 7 October 2025
Within the LHC community, a momentous transition has been occurring in authorization. For nearly 20 years, services within the Worldwide LHC Computing Grid (WLCG) have been authorized based on mapping an identity, derived from an X.509 credential, or a group/role, derived from a VOMS extension issued by the experiment. A fundamental shift is occurring to capabilities: the credential, a bearer token, asserts the authorizations of the bearer, not the identity. By the HL-LHC era, the CMS experiment plans for the transition to tokens, based on the WLCG Common JSON Web Token profile, to be complete. Services in the technology architecture include the INDIGO Identity and Access Management server to issue tokens; a HashiCorp Vault server to store and refresh access tokens for users and jobs; a managed token bastion server to push credentials to the HTCondor CredMon service; and HTCondor to maintain valid tokens in long-running batch jobs. We will describe the transition plans of the experiment, current status, configuration of the central authorization server, lessons learned in commissioning token-based access with sites, and operational experience using tokens for both job submissions and file transfers.
© The Authors, published by EDP Sciences, 2025
This is an Open Access article distributed under the terms of the Creative Commons Attribution License 4.0, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
Current usage metrics show cumulative count of Article Views (full-text article views including HTML views, PDF and ePub downloads, according to the available data) and Abstracts Views on Vision4Press platform.
Data correspond to usage on the plateform after 2015. The current usage metrics is available 48-96 hours after online publication and is updated daily on week days.
Initial download of the metrics may take a while.

