Print

Print


When trying several possible authentication methods, only one of them prints something:

/tmp$ xrdcp  root://eosproject-i00:1094//proc /tmp/foo
190218 14:42:24 17779 secgsi_InitProxy: cannot access private key file: /eos/user/A/ABC/.globus/userkey.pem

This has confused some of our users in the past - if the message precedes some other error, they assume that the two are linked.

I would suggest to downgrade this message to "Debug" level, perhaps unless the user has explicitly specified GSI to be be used (via "XrdSecPROTOCOL=gsi"). This would be consistent with how the other auth methods are being tried - these fail silently (i.e only visible at "Debug" level):

[2019-02-18 14:42:12.136860 +0100][Debug  ][XRootDTransport   ] [eosproject-i00:1094 #0.0] Authentication is required: &P=krb5,[log in to unmask]&P=gsi,v:10300,c:ssl,ca:5168735f.0|4339b4bc.0&P=unix&P=sss,0.13:/etc/eos.keytab
[2019-02-18 14:42:12.136871 +0100][Debug  ][XRootDTransport   ] [eosproject-i00:1094 #0.0] Sending authentication data
[2019-02-18 14:42:12.138679 +0100][Debug  ][XRootDTransport   ] [eosproject-i00:1094 #0.0] Trying to authenticate using krb5
[2019-02-18 14:42:12.139140 +0100][Debug  ][XRootDTransport   ] [eosproject-i00:1094 #0.0] Cannot get credentials for protocol krb5: Seckrb5: No or invalid credentials; No credentials cache found ([log in to unmask]).
[2019-02-18 14:42:12.145168 +0100][Debug  ][XRootDTransport   ] [eosproject-i00:1094 #0.0] Trying to authenticate using gsi
190218 14:42:12 17762 secgsi_InitProxy: cannot access private key file: /eos/user/A/ABC/.globus/userkey.pem
[2019-02-18 14:42:12.160033 +0100][Debug  ][XRootDTransport   ] [eosproject-i00:1094 #0.0] Cannot get credentials for protocol gsi: Secgsi: ErrParseBuffer: error getting user proxies: kXGS_init
[2019-02-18 14:42:12.160224 +0100][Debug  ][XRootDTransport   ] [eosproject-i00:1094 #0.0] Trying to authenticate using unix


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/xrootd/xrootd","title":"xrootd/xrootd","subtitle":"GitHub repository","main_image_url":"https://github.githubassets.com/images/email/message_cards/header.png","avatar_image_url":"https://github.githubassets.com/images/email/message_cards/avatar.png","action":{"name":"Open in GitHub","url":"https://github.com/xrootd/xrootd"}},"updates":{"snippets":[{"icon":"DESCRIPTION","message":"RFE: downgrade \"secgsi_InitProxy: cannot access private key file:\" to Debug (#909)"}],"action":{"name":"View Issue","url":"https://github.com/xrootd/xrootd/issues/909"}}} [ { "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://github.com/xrootd/xrootd/issues/909", "url": "https://github.com/xrootd/xrootd/issues/909", "name": "View Issue" }, "description": "View this Issue on GitHub", "publisher": { "@type": "Organization", "name": "GitHub", "url": "https://github.com" } } ]

Use REPLY-ALL to reply to list

To unsubscribe from the XROOTD-DEV list, click the following link:
https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1