Print

Print


Looking at what I did for XrdLcmaps:

One open question is how we should handle a proxy certificate with multiple VOMS extensions present - i.e., a proxy certificate with both ATLAS and CMS extensions. After all, it's perfectly acceptable for the CMS VOMS server to sign an extensions with FQAN /atlas. It's traditional that CMS group names are prefixed with /cms, but not enforced or validated by the client.


You are receiving this because you commented.
Reply to this email directly, view it on GitHub, or mute the thread.

{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/xrootd/xrootd","title":"xrootd/xrootd","subtitle":"GitHub repository","main_image_url":"https://cloud.githubusercontent.com/assets/143418/17495839/a5054eac-5d88-11e6-95fc-7290892c7bb5.png","avatar_image_url":"https://cloud.githubusercontent.com/assets/143418/15842166/7c72db34-2c0b-11e6-9aed-b52498112777.png","action":{"name":"Open in GitHub","url":"https://github.com/xrootd/xrootd"}},"updates":{"snippets":[{"icon":"PERSON","message":"@bbockelm in #566: Looking at what I did for `XrdLcmaps`:\r\n- *space*-separated list of groups. \r\n- They should start with a slash; VOMS groups are hierarchical (i.e., `/atlas/foo/bar` is distinct from `/atlas/baz`) unlike Unix groups.\r\n\r\nOne open question is how we should handle a proxy certificate with multiple VOMS extensions present - i.e., a proxy certificate with both ATLAS and CMS extensions. After all, it's perfectly acceptable for the CMS VOMS server to sign an extensions with FQAN `/atlas`. It's traditional that CMS group names are prefixed with `/cms`, but not enforced or validated by the client."}],"action":{"name":"View Issue","url":"https://github.com/xrootd/xrootd/issues/566#issuecomment-323732506"}}}

Use REPLY-ALL to reply to list

To unsubscribe from the XROOTD-DEV list, click the following link:
https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1