<!-- keep this as a security measure: #uncomment if the subject should only be modifiable by the listed groups * Set ALLOWTOPICCHANGE = Main.TWikiAdminGroup,Main.CMSAdminGroup * Set ALLOWTOPICRENAME = Main.TWikiAdminGroup,Main.CMSAdminGroup #uncomment this if you want the page only be viewable by the listed groups # * Set ALLOWTOPICVIEW = Main.TWikiAdminGroup,Main.CMSAdminGroup --> %TOC% %ICON{arrowleft}% Go to [[CMSTier3LogXX][previous page]] / [[CMSTier3LogXX][next page]] of Tier3 site log %M% ---+ 04. 12. 2012 Problem with myproxy renewal from PSI vobox I am afraid that in 2011 maybe the old error causing problems with the parenthesis containing SWITCH certs may have surfaced again. At least a newer bug report on the globus website may indicate that * http://bugzilla.globus.org/bugzilla/show_bug.cgi?id=7211 * http://bugzilla.globus.org/bugzilla/show_bug.cgi?id=6903 But we ran fine until this week, and the bug reports seem to imply that the version has been in operation at CERN for some time. ---++ Functioning example with CSCS vobox <verbatim> I place the myproxy using t3ui02: [feichtinger@t3ui02 ~]$ myproxy-init -l psi_phedex_derek -x \ -R /DC=com/DC=quovadisglobal/DC=grid/DC=switch/DC=hosts/C=CH/ST=Zuerich/L=Zuerich/O=ETH Zuerich/CN=cmsvobox.lcg.cscs.ch -c 720 [phedex@cmsvobox:~]$ voms-proxy-info ... identity : /DC=com/DC=quovadisglobal/DC=grid/DC=switch/DC=hosts/C=CH/ST=Zuerich/L=Zuerich/O=ETH Zuerich/CN=cmsvobox.lcg.cscs.ch ... [phedex@cmsvobox:~]$ myproxy-get-delegation -v -s myproxy.cern.ch -v -l psi_phedex_derek -a /home/phedex/derek_x509 -o /tmp/gaga MyProxy v4.2 10 Jan 2008 PAM Socket bound to port 20000. Attempting to connect to 128.142.139.217:7512 using trusted certificates directory /etc/grid-security/certificates server name: /DC=ch/DC=cern/OU=computers/CN=px307.cern.ch checking that server name is acceptable... server name does not match "myproxy@px307.cern.ch" server name matches "host@px307.cern.ch" authenticated server name is acceptable A credential has been received for user psi_phedex_derek in /tmp/gaga. </verbatim> ---++ failing example for PSI vobox <verbatim> I place the myproxy using t3ui02: [feichtinger@t3ui02 ~]$ myproxy-init -l psi_phedex_derek -x -c 720 \ -R /DC=com/DC=quovadisglobal/DC=grid/DC=switch/DC=hosts/C=CH/ST=Aargau/L=Villigen/O=Paul-Scherrer-Institut (PSI)/CN=t3cmsvobox.psi.ch [phedex@t3cmsvobox02 ~]$ voms-proxy-info ... identity : /DC=com/DC=quovadisglobal/DC=grid/DC=switch/DC=hosts/C=CH/ST=Aargau/L=Villigen/O=Paul-Scherrer-Institut (PSI)/CN=t3cmsvobox.psi.ch ... [phedex@t3cmsvobox02 ~]$ myproxy-get-delegation -s myproxy.cern.ch -v -l psi_phedex_derek -a /home/phedex/gridcert/proxy.cert.derek -o /tmp/gaga MyProxy v4.2 10 Jan 2008 PAM Socket bound to port 20000. Attempting to connect to 128.142.139.217:7512 using trusted certificates directory /etc/grid-security/certificates/ server name: /DC=ch/DC=cern/OU=computers/CN=px307.cern.ch checking that server name is acceptable... server name does not match "myproxy@px307.cern.ch" server name matches "host@px307.cern.ch" authenticated server name is acceptable Failed to receive credentials. ERROR from myproxy-server (myproxy.cern.ch): no passphrase authentication failed </verbatim> ---++ Opened GGUS Ticket about this error REFERENCE LINK: https://ggus.eu/ws/ticket_info.php?ticket=89187 SUBJECT: Can't renew Phedex proxy vs myproxy.cern.ch -- Main.DerekFeichtinger - 2012-12-04 ---------------- %ICON{arrowleft}% Go to [[CMSTier3LogXX][previous page]] / [[CMSTier3LogXX][next page]] of Tier3 site log %M%
This topic: CmsTier3
>
WebHome
>
CMSTier3Log
>
CMSTier3Log32
Topic revision: r2 - 2012-12-04 - FabioMartinelli
Copyright © 2008-2024 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki?
Send feedback