User account

You may ask for a user account at CC-IN2P3 if:

  • you are administratively affiliated to an IN2P3 research structure,

  • you work in collaboration with IN2P3 or research entities using CC-IN2P3 services and resources,

  • your applications/infrastructures are hosted by CC-IN2P3.

Important

Once created, a user account may become member of one or more collaborations, and his activity will be managed under the responsibility of the relevant collaboration contacts.

If the collaboration is allowed to use computing resources following its resource request, the account will have access to the interactive servers. To highlight this authorization, the account will be referred to as computing account.

Request an account

To create your CC-IN2P3 user account, please follow the procedure below:

  1. read the Charters for the use of resources (the account creation or submission of a creation request implies acceptance of the charters),

  2. go to the Identity Management Portal and select the “Sign up” button,

  3. fill in the required information (using eduGAIN will make this task easier) and follow the instructions you’ll receive by e-mail.

Important

Once your account is created, request, if necessary, the membership to the scientific collaborations in which you wish to work.

Attention

The creation of a user account for research structures personnel involving an administrative collaboration, will be subject to validation by the relevant collaboration contact. The account will therefore be active only after validation.

Account management

Profile editing

You will be able to perform the following actions yourself on your account information from the Identity Management Portal:

  • modify your First and Last name,

  • change or reset your password,

  • request membership to scientific collaborations.

  • Pending validation by the concerned collaboration contact, no further modification of the profile will be possible,

  • the main group does not change after a membership request. To change it, please use the CLI commands.

Attention

Your reference e-mail address is used for all exchanges with CC-IN2P3. A notification will be sent periodically inviting you to revalidate your profile. If you do not reply, the account will be suspended pending deletion. To change your reference e-mail address, please contact user support.

Important

For the following actions please ask the relevant collaboration contact to contact user support:

  • extend the account expiration date,

  • detach an account from a collaboration,

  • delete an account.

CLI commands

You may find below few suggestions for checking and managing account information through a command-line interface (CLI) from a interactive server.

To know the information associated to your account

use the command laboinfo with the following syntax (the expected output fields are shown):

% laboinfo -u <userid>
"userid"  "Last name"  "First name"  "last manual connection date"  "expiration date"  "group list"  "e-mail"

To explore all the command functionalities:

% laboinfo -h
To know the principal group

use the following command:

% id -gn

Without the option –gn the command will list all the groups your account is associated with.

To change your principal group

with a group your account is already associated with, use the following command:

% newgroup --help

Usage: newgroup   --help  | -h
       newgroup   --query | -q
       newgroup [ --temp  | -t ] [ --login | -l ] <groupname>

The --temp option allows to change the group temporarily and only in the active session where the command is executed. At logout the group change is cancelled.

The --login option allows to load the chosen group login environment. This modification is permanent up to the next change.

Personal certificates

Access to certain CNRS services requires a personal certificate. Please refer to the paragraphs below to obtain and manage your certificates.

Access by identity federation

The connection to the some of the services provided by the CC-IN2P3 and accessible through web interface is most often achieved by authentication via the identity federation eduGAIN or RENATER (which is part of eduGAIN). This type of connection allows automatic validation of the account on first access and implements a Single Sign On system, based on the user’s reference e-mail.

Some services require manual registration for users not recognized by identity federation. Many institutional domains are listed in the federation: please check the presence of your institutional guardianship on the respective WAIF pages below. Please contact, if necessary, user support.