EPJ Web of Conferences • Vol 337
January 2025 • Brian Bockelman, Rahul Chauhan, D. Ciangottini, Dave Dykstra, Edita Kizinevič, Stephan Lammel, Marco Mascheroni, Sarun Nuntaviriyakul, Panos Paparrig…
Within the LHC community, a momentous transition has been occurring in authorization. For nearly 20 years, services within the Worldwide LHC Computing Grid (WLCG) have been authorized based on mapping an identity, derived from an X.509 credential, or a group/role, derived from a VOMS extension issued by the experiment. A fundamental shift is occurring to capabilities: the credential, a bearer token, asserts the authorizations of the bearer, not the identity. By the HL-LHC era, the CMS experiment plans for the tran…