Print

Print


Why precisely does GSI authentication require a client certificate? There's no underlying technical reason - it's just that the current implementation requires it.

Indeed - unauthenticated clients should proceed to the authorization stage just like they do elsewhere. If they are unauthenticated and have an authorized token for a TPC, then they should indeed be authorized. That's the whole point of a bearer token.

FWIW - FTS-based transfers work regardless of #691 and we are indeed using them for WLCG replication. I would hardly say that the presence of a technical bug (which should be followed up and fixed, of course) in the handling of a Nagios test makes any implications about "suitability". It just means there's continued room for improvement.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

{"@context":"http://schema.org","@type":"EmailMessage","potentialAction":{"@type":"ViewAction","target":"https://github.com/xrootd/xrootd/issues/694#issuecomment-390767349","url":"https://github.com/xrootd/xrootd/issues/694#issuecomment-390767349","name":"View Issue"},"description":"View this Issue on GitHub","publisher":{"@type":"Organization","name":"GitHub","url":"https://github.com"}} {"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/xrootd/xrootd","title":"xrootd/xrootd","subtitle":"GitHub repository","main_image_url":"https://cloud.githubusercontent.com/assets/143418/17495839/a5054eac-5d88-11e6-95fc-7290892c7bb5.png","avatar_image_url":"https://cloud.githubusercontent.com/assets/143418/15842166/7c72db34-2c0b-11e6-9aed-b52498112777.png","action":{"name":"Open in GitHub","url":"https://github.com/xrootd/xrootd"}},"updates":{"snippets":[{"icon":"PERSON","message":"@bbockelm in #694: Why precisely does GSI authentication require a client certificate? There's no underlying technical reason - it's just that the current implementation requires it.\r\n\r\nIndeed - unauthenticated clients should proceed to the authorization stage just like they do elsewhere. If they are unauthenticated and have an authorized token for a TPC, then they should indeed be authorized. That's the whole point of a bearer token.\r\n\r\nFWIW - FTS-based transfers work regardless of #691 and we are indeed using them for WLCG replication. I would hardly say that the presence of a technical bug (which should be followed up and fixed, of course) in the handling of a Nagios test makes any implications about \"suitability\". It just means there's continued room for improvement."}],"action":{"name":"View Issue","url":"https://github.com/xrootd/xrootd/issues/694#issuecomment-390767349"}}} { "@type": "MessageCard", "@context": "http://schema.org/extensions", "hideOriginalBody": "false", "originator": "37567f93-e2a7-4e2a-ad37-a9160fc62647", "title": "Re: [xrootd/xrootd] TPC requires server-to-server XRootDTransport authentication (#694)", "sections": [ { "text": "", "activityTitle": "**Brian Bockelman**", "activityImage": "https://cloud.githubusercontent.com/assets/143418/15842166/7c72db34-2c0b-11e6-9aed-b52498112777.png", "activitySubtitle": "@bbockelm", "facts": [ ] } ], "potentialAction": [ { "name": "Add a comment", "@type": "ActionCard", "inputs": [ { "isMultiLine": true, "@type": "TextInput", "id": "IssueComment", "isRequired": false } ], "actions": [ { "name": "Comment", "@type": "HttpPOST", "target": "https://api.github.com", "body": "{\n\"commandName\": \"IssueComment\",\n\"repositoryFullName\": \"xrootd/xrootd\",\n\"issueId\": 694,\n\"IssueComment\": \"{{IssueComment.value}}\"\n}" } ] }, { "name": "Close issue", "@type": "HttpPOST", "target": "https://api.github.com", "body": "{\n\"commandName\": \"IssueClose\",\n\"repositoryFullName\": \"xrootd/xrootd\",\n\"issueId\": 694\n}" }, { "targets": [ { "os": "default", "uri": "https://github.com/xrootd/xrootd/issues/694#issuecomment-390767349" } ], "@type": "OpenUri", "name": "View on GitHub" }, { "name": "Unsubscribe", "@type": "HttpPOST", "target": "https://api.github.com", "body": "{\n\"commandName\": \"MuteNotification\",\n\"threadId\": 328188433\n}" } ], "themeColor": "26292E" }

Use REPLY-ALL to reply to list

To unsubscribe from the XROOTD-DEV list, click the following link:
https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1