User Management for Virtual Organizations

Scalable and fine-grained Grid authorization requires moving away from a gridmapfile based access control and 1-to-l mappings to individual OS user accounts. This is recognized and addressed to by virtual organization (VO) authorization services, e. g. VOMS/LCAS and CAS. They, however, do not address user OS account management and isolation/sandboxing requirements, such as flexible pooling of accounts while maintaining auditing records. This paper describes some existing systems for user management for VOs and provides a list of requirements for a new user management system on which our current research is focused on.