Hi @olifre - What do you use locally for site-level authorization? Locally, we authorize first through LCMAPS (using the XrdLcmaps plugin - see https://github.com/opensciencegrid/xrootd-lcmaps), mapping things to a username and set of groups. Another approach is to simply map based on VOMS attributes (which goes to `g`) instead of hardcoding DNs. Once it's a unix username instead of a DN, it's a bit simpler to manipulate the authdb. Brian -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/xrootd/xrootd/issues/712#issuecomment-391404625 ######################################################################## Use REPLY-ALL to reply to list To unsubscribe from the XROOTD-DEV list, click the following link: https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1