Print

Print


Hi @olifre -

What do you use locally for site-level authorization?

Locally, we authorize first through LCMAPS (using the XrdLcmaps plugin - see https://github.com/opensciencegrid/xrootd-lcmaps), mapping things to a username and set of groups. Another approach is to simply map based on VOMS attributes (which goes to g) instead of hardcoding DNs.

Once it's a unix username instead of a DN, it's a bit simpler to manipulate the authdb.

Brian


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

{"@context":"http://schema.org","@type":"EmailMessage","potentialAction":{"@type":"ViewAction","target":"https://github.com/xrootd/xrootd/issues/712#issuecomment-391404625","url":"https://github.com/xrootd/xrootd/issues/712#issuecomment-391404625","name":"View Issue"},"description":"View this Issue on GitHub","publisher":{"@type":"Organization","name":"GitHub","url":"https://github.com"}} {"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/xrootd/xrootd","title":"xrootd/xrootd","subtitle":"GitHub repository","main_image_url":"https://cloud.githubusercontent.com/assets/143418/17495839/a5054eac-5d88-11e6-95fc-7290892c7bb5.png","avatar_image_url":"https://cloud.githubusercontent.com/assets/143418/15842166/7c72db34-2c0b-11e6-9aed-b52498112777.png","action":{"name":"Open in GitHub","url":"https://github.com/xrootd/xrootd"}},"updates":{"snippets":[{"icon":"PERSON","message":"@bbockelm in #712: Hi @olifre -\r\n\r\nWhat do you use locally for site-level authorization?\r\n\r\nLocally, we authorize first through LCMAPS (using the XrdLcmaps plugin - see https://github.com/opensciencegrid/xrootd-lcmaps), mapping things to a username and set of groups. Another approach is to simply map based on VOMS attributes (which goes to `g`) instead of hardcoding DNs.\r\n\r\nOnce it's a unix username instead of a DN, it's a bit simpler to manipulate the authdb.\r\n\r\nBrian"}],"action":{"name":"View Issue","url":"https://github.com/xrootd/xrootd/issues/712#issuecomment-391404625"}}} { "@type": "MessageCard", "@context": "http://schema.org/extensions", "hideOriginalBody": "false", "originator": "37567f93-e2a7-4e2a-ad37-a9160fc62647", "title": "Re: [xrootd/xrootd] acc.authdb does not support DNs with whitespace (#712)", "sections": [ { "text": "", "activityTitle": "**Brian Bockelman**", "activityImage": "https://cloud.githubusercontent.com/assets/143418/15842166/7c72db34-2c0b-11e6-9aed-b52498112777.png", "activitySubtitle": "@bbockelm", "facts": [ ] } ], "potentialAction": [ { "name": "Add a comment", "@type": "ActionCard", "inputs": [ { "isMultiLine": true, "@type": "TextInput", "id": "IssueComment", "isRequired": false } ], "actions": [ { "name": "Comment", "@type": "HttpPOST", "target": "https://api.github.com", "body": "{\n\"commandName\": \"IssueComment\",\n\"repositoryFullName\": \"xrootd/xrootd\",\n\"issueId\": 712,\n\"IssueComment\": \"{{IssueComment.value}}\"\n}" } ] }, { "name": "Close issue", "@type": "HttpPOST", "target": "https://api.github.com", "body": "{\n\"commandName\": \"IssueClose\",\n\"repositoryFullName\": \"xrootd/xrootd\",\n\"issueId\": 712\n}" }, { "targets": [ { "os": "default", "uri": "https://github.com/xrootd/xrootd/issues/712#issuecomment-391404625" } ], "@type": "OpenUri", "name": "View on GitHub" }, { "name": "Unsubscribe", "@type": "HttpPOST", "target": "https://api.github.com", "body": "{\n\"commandName\": \"MuteNotification\",\n\"threadId\": 338355081\n}" } ], "themeColor": "26292E" }

Use REPLY-ALL to reply to list

To unsubscribe from the XROOTD-DEV list, click the following link:
https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1