In theory the roles can be added to the token, however I would consider not using this option at the redirector. You may want to do the full https/voms authorization at the redirector, and use this option only at the data servers, of course you shall do this only if you don't need data encryption.

About the performance, I can't comment on the use cases cited by Brian, basically involving big streams. I can comment on mine, involving 10-20KHz of transactions of a few bytes, and there used to be a big difference, so for the DPM cluster control protocol this option is giving benefits.


You are receiving this because you commented.
Reply to this email directly, view it on GitHub, or mute the thread.

{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/xrootd/xrootd","title":"xrootd/xrootd","subtitle":"GitHub repository","main_image_url":"https://assets-cdn.github.com/images/email/message_cards/header.png","avatar_image_url":"https://assets-cdn.github.com/images/email/message_cards/avatar.png","action":{"name":"Open in GitHub","url":"https://github.com/xrootd/xrootd"}},"updates":{"snippets":[{"icon":"PERSON","message":"@ffurano in #745: In theory the roles can be added to the token, however I would consider not using this option at the redirector. You may want to do the full https/voms authorization at the redirector, and use this option only at the data servers, of course you shall do this only if you don't need data encryption.\r\n\r\nAbout the performance, I can't comment on the use cases cited by Brian, basically involving big streams. I can comment on mine, involving 10-20KHz of transactions of a few bytes, and there used to be a big difference, so for the DPM cluster control protocol this option is giving benefits.\r\n"}],"action":{"name":"View Issue","url":"https://github.com/xrootd/xrootd/issues/745#issuecomment-401371366"}}} [ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/xrootd/xrootd/issues/745#issuecomment-401371366", "url": "https://github.com/xrootd/xrootd/issues/745#issuecomment-401371366", "name": "View Issue" }, "description": "View this Issue on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } }, { "@type": "MessageCard", "@context": "http://schema.org/extensions", "hideOriginalBody": "false", "originator": "AF6C5A86-E920-430C-9C59-A73278B5EFEB", "title": "Re: [xrootd/xrootd] selfhttps2http does not allow auth based on roles (#745)", "sections": [ { "text": "", "activityTitle": "**Fabrizio Furano**", "activityImage": "https://assets-cdn.github.com/images/email/message_cards/avatar.png", "activitySubtitle": "@ffurano", "facts": [ ] } ], "potentialAction": [ { "name": "Add a comment", "@type": "ActionCard", "inputs": [ { "isMultiLine": true, "@type": "TextInput", "id": "IssueComment", "isRequired": false } ], "actions": [ { "name": "Comment", "@type": "HttpPOST", "target": "https://api.github.com", "body": "{\n\"commandName\": \"IssueComment\",\n\"repositoryFullName\": \"xrootd/xrootd\",\n\"issueId\": 745,\n\"IssueComment\": \"{{IssueComment.value}}\"\n}" } ] }, { "name": "Close issue", "@type": "HttpPOST", "target": "https://api.github.com", "body": "{\n\"commandName\": \"IssueClose\",\n\"repositoryFullName\": \"xrootd/xrootd\",\n\"issueId\": 745\n}" }, { "targets": [ { "os": "default", "uri": "https://github.com/xrootd/xrootd/issues/745#issuecomment-401371366" } ], "@type": "OpenUri", "name": "View on GitHub" }, { "name": "Unsubscribe", "@type": "HttpPOST", "target": "https://api.github.com", "body": "{\n\"commandName\": \"MuteNotification\",\n\"threadId\": 346859151\n}" } ], "themeColor": "26292E" } ]

Use REPLY-ALL to reply to list

To unsubscribe from the XROOTD-DEV list, click the following link:
https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1