Correct, xrdmapc has to follow to authentication requirements of each
endpoint. So, the auth stuff has to be setup correctly for any of this to
work.
Andy
On Mon, 3 Aug 2015, Brian Bockelman wrote:
> Hi Marian,
>
> xrdmapc appears to be trying to use GSI authentication, but cannot find either proxy or cert/key for the root account.
>
> Where do you believe the GSI credentials should be coming from?
>
> Brian
>
>> On Aug 3, 2015, at 4:35 PM, Marian Zvada <[log in to unmask]> wrote:
>>
>> Forgot to say - behavior is reproducible now in both xrootd rpm flavors, from EPEL and OSG. (In 4.2.1 it was just in EPEL, weird enough, huh?) I have still other unresolved questions with xrdmapc but those are under microscope of Andy progressing...
>>
>> Thanks,
>> Marian
>>
>> On 8/3/15 4:27 PM, Marian Zvada wrote:
>>> Hi,
>>>
>>> did anyone had chance look at this and perhaps explain? I can see same
>>> annoyance running 4.2.2 (****).
>>>
>>> Thanks,
>>> Marian
>>>
>>> (****)
>>> [root@vocms027 ~]# xrdmapc --list all cms-xrd-transit.cern.ch:1094
>>> 150803 23:23:09 7669 secgsi_InitProxy: cannot access private key file:
>>> /root/.globus/userkey.pem
>>> xrdmapc: Unable to connect to osg-se.cac.cornell.edu:1094; [FATAL] Auth
>>> failed
>>> 0**** vocms027.cern.ch:1094
>>> Srv cms25.physics.ucsb.edu:1094
>>> Srv cms-se.hep.uprm.edu:1094
>>> 1 Man osg-se.cac.cornell.edu:1094
>>> [root@vocms027 ~]# ls -al /root/.glo*
>>> ls: cannot access /root/.glo*: No such file or directory
>>> [root@vocms027 ~]# rpm -qa | grep xrootd
>>> xrootd-server-devel-4.2.2-1.el6.x86_64
>>> xrootd-server-libs-4.2.2-1.el6.x86_64
>>> xrootd-devel-4.2.2-1.el6.x86_64
>>> xrootd-client-4.2.2-1.el6.x86_64
>>> xrootd-libs-4.2.2-1.el6.x86_64
>>> xrootd-client-devel-4.2.2-1.el6.x86_64
>>> xrootd-client-libs-4.2.2-1.el6.x86_64
>>> xrootd-server-4.2.2-1.el6.x86_64
>>>
>>>
>>> On 7/16/15 2:24 PM, Marian Zvada wrote:
>>>> Hi Folks,
>>>>
>>>> I find this annoying:
>>>>
>>>> # xrdmapc --list all vocms027.cern.ch:1094
>>>> 150716 21:11:38 5509 secgsi_InitProxy: cannot access private key file:
>>>> /root/.globus/userkey.pem
>>>> ...
>>>> ...
>>>> [root@vocms027 ~]# ls -al /root/.globus/
>>>> ls: cannot access /root/.globus/: No such file or directory
>>>>
>>>> Note the "secgsi_InitProxy: cannot access private key", on the system
>>>> that directory .globus doesn't even exist. How come? Here the rpms
>>>> installed on the system (*).
>>>>
>>>> Strangely, I don't see same behavior on 4.2.1 from osg-repo (**).
>>>> xrdmapc doesn't complain about any and comparing configs between the two
>>>> systems are pretty much same.
>>>>
>>>> Although there might be difference in the packaging between CERN
>>>> provided and OSG, I fear there must be something else why it tries to
>>>> locate /root/.globus/userkey.pem file on my system?
>>>>
>>>> Oh, and here is the config how it looks like (***).
>>>>
>>>> Do you see anything obvious why this happens?
>>>>
>>>> Thanks,
>>>> Marian
>>>>
>>>> (*)
>>>> xrootd-server-devel-4.2.1-1.slc6.x86_64
>>>> xrootd-server-libs-4.2.1-1.slc6.x86_64
>>>> xrootd-libs-4.2.1-1.slc6.x86_64
>>>> xrootd-devel-4.2.1-1.slc6.x86_64
>>>> xrootd-client-libs-4.2.1-1.slc6.x86_64
>>>> xrootd-client-devel-4.2.1-1.slc6.x86_64
>>>> xrootd-server-4.2.1-1.slc6.x86_64
>>>> xrootd-client-4.2.1-1.slc6.x86_64
>>>>
>>>> (**)
>>>> xrootd-server-libs-4.2.1-2.osg32.el6.x86_64
>>>> xrootd-client-libs-4.2.1-2.osg32.el6.x86_64
>>>> xrootd-server-4.2.1-2.osg32.el6.x86_64
>>>> xrootd-4.2.1-2.osg32.el6.x86_64
>>>> xrootd-libs-4.2.1-2.osg32.el6.x86_64
>>>> xrootd-selinux-4.2.1-2.osg32.el6.noarch
>>>>
>>>> (***)
>>>> xrd.port 1213 if exec cmsd
>>>> xrd.port 1094 if exec xrootd
>>>> all.sitename CERN-TRANSIT
>>>> all.role meta manager
>>>> all.export /
>>>> all.manager meta all cms-xrd-transit.cern.ch+ 1213
>>>> cms.delay startup 10 lookup 5 qdl 30 servers 1
>>>> cms.trace forward redirect
>>>> xrd.report xrootd.t2.ucsd.edu:9931 every 30s all sync
>>>> xrootd.monitor all fstat 60s lfn ops ssq xfr 5 ident 5m dest fstat info
>>>> user redir CMS-AAA-EU-COLLECTOR.cern.ch:9330
>>>> xrootd.trace emsg redirect
>>>> xrd.network keepalive kaparms 5m,5s,5
>>>> xrd.timeout idle 30m
>>>> frm.xfr.copycmd /bin/cp /dev/null $PFN
>>>> all.adminpath /var/spool/xrootd
>>>> all.pidpath /var/run/xrootd
>>>>
>>>> ########################################################################
>>>> Use REPLY-ALL to reply to list
>>>>
>>>> To unsubscribe from the XROOTD-DEV list, click the following link:
>>>> https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1
>>>
>>> ########################################################################
>>> Use REPLY-ALL to reply to list
>>>
>>> To unsubscribe from the XROOTD-DEV list, click the following link:
>>> https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1
>>
>> ########################################################################
>> Use REPLY-ALL to reply to list
>>
>> To unsubscribe from the XROOTD-DEV list, click the following link:
>> https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1
>
> ########################################################################
> Use REPLY-ALL to reply to list
>
> To unsubscribe from the XROOTD-DEV list, click the following link:
> https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1
>
########################################################################
Use REPLY-ALL to reply to list
To unsubscribe from the XROOTD-DEV list, click the following link:
https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1
|