User Management

User and groups management and access to services in the CESNET e-infrastructure is provided by the Perun system, which is an integral part of the system.

It provides users with unified access to services with a single user account. The system allows delegating administration to responsible persons, enabling organizations connected to CESNET to manage their users independently without contacting the e-infrastructure administrator.

The service can also control access to e-infrastructure services and services of connected organizations. The Perun service is involved in international identity federations, so users from organizations outside the Czech Republic can also be managed. The essential features of the system include:

  • Self-management of users in the form of virtual organization management,
  • management of access control to e-infrastructure services and own services,
  • management of users, groups, and services,
  • management of user registrations,
  • registration of acknowledgments in user publications,
  • the service provides data via LDAP interface, SAML2 attribute authority, VOOT, SCIM, and push mechanism,
  • synchronization with external IdM systems.

The Perun system was developed by CESNET and CERIT-SC staff and students from Masaryk University and Czech Technical University in Prague.