I am thinking of macaroon and scitoken as something similar to signed URL in the sense that it allows someone a temporary access. and macaroon is issued by the storage admin and scitoken is issued by a VO.

The current mechanism for a storage admin to obtain a macaroon is only available in http protocol (which is OK) and require either an x509 or scitoken authentication. I wonder if there are other "local" authentication methods (such as krb5, password, sss, etc.) on the http side that allow an admin obtain a macaroon . Andy says that "password" may work in http but never tested.


Reply to this email directly, view it on GitHub, or unsubscribe.
You are receiving this because you are subscribed to this thread.Message ID: <xrootd/xrootd/pull/1802/c1280206961@github.com>

[ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/xrootd/xrootd/pull/1802#issuecomment-1280206961", "url": "https://github.com/xrootd/xrootd/pull/1802#issuecomment-1280206961", "name": "View Pull Request" }, "description": "View this Pull Request on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]

Use REPLY-ALL to reply to list

To unsubscribe from the XROOTD-DEV list, click the following link:
https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1