Print

Print


Hi Albert,

The date on the doc is the date of the last modification. The last section 
in the doc gives the full hirstory of the doc since it was issued. This 
particular doc has been around since 16-June-2014.

Andy


On Mon, 11 Apr 2022, Albert Rossi via RT wrote:

> Great, thank you Andy.  The doc is what I needed.  Overlooked it (I see it's rather recent, from last June)...
>
> Al
>
> ________________________________________________
> Albert L. Rossi
> Senior Software Developer
> Scientific Computing Division, Scientific Data Services, Distributed Data Development
> FCC 229A
> Mail Station 369 (FCC 2W)
> Fermi National Accelerator Laboratory
> Batavia, IL 60510
> (630) 840-3023
>
> ________________________________
> From: [log in to unmask] via RT <[log in to unmask]>
> Sent: Monday, April 11, 2022 2:28 PM
> Subject: Re: [www.dcache.org #10312] data server behind firewall
>
>
> *********************************************************************************
> This is an automated mail to inform you about a ticket update.
> When replying do not change the squared brackets part in the subject line.
> Type your text above this box and S T R I P  P R E V I O U S  M A I L S please!!
> *********************************************************************************
>
> <URL: https://urldefense.proofpoint.com/v2/url?u=https-3A__rt.dcache.org_Ticket_Display.html-3Fid-3D10312&d=DwIDaQ&c=gRgGjJ3BkIsb5y6s49QqsA&r=60rQ0HHqHmEY1P6VSdyuTQ&m=jvLrAHOobeDBj_z436J39DyaJcRav3b6fPALzgfIjA6JvIJEM2iAOLmJ2fXsxekx&s=cSzMvqfr16j2sivAam1PDtzcc662-hnoqAwZ3DCQ8qw&e=  >
>
> Hi Albert,
>
> The xroot proxy server is similar to many other such servers. However, we
> decided some time ago to make it a powerful addition even if you don't
> need to bridge a firewall. To that extent it is an implementation of a
> data server but uses other data servers as the source/target of all
> requests. This provides a lot of features but does restrict you somewhat
> in the client credentials area. Here we usually need to use the server's
> credentials on the back end while we fully authenticate and authorize
> client credentials on the front end. We do have a mode using sss
> authentication to proxy any client credential but the proxied credential
> cannot be delegated after that point. In practice, this satisfies just
> about all the use cases we've seen. Again, the reference is your
> friend....
>
> https://urldefense.proofpoint.com/v2/url?u=https-3A__xrootd.slac.stanford.edu_doc_dev53_pss-5Fconfig.htm&d=DwIDaQ&c=gRgGjJ3BkIsb5y6s49QqsA&r=60rQ0HHqHmEY1P6VSdyuTQ&m=jvLrAHOobeDBj_z436J39DyaJcRav3b6fPALzgfIjA6JvIJEM2iAOLmJ2fXsxekx&s=nobbCms7RlslDFwgMWbiH20yDbwsebLN5n_un7xMGMA&e=
>
> Andy
>
>
> On Mon, 11 Apr 2022, Albert Rossi via RT wrote:
>
>> *********************************************************************************
>> This is an automated mail to inform you about a ticket update.
>> When replying do not change the squared brackets part in the subject line.
>> Type your text above this box and S T R I P  P R E V I O U S  M A I L S please!!
>> *********************************************************************************
>>
>> Hi Andy (et al.),
>>
>> A quick question.
>>
>> What are the options offered by xrootd for deployment or configuration when all data servers are behind a firewall which blocks all direct access by clients on an external network?
>>
>> Section 4.2 of the configuration documentation<https://urldefense.proofpoint.com/v2/url?u=https-3A__xrootd.slac.stanford.edu_doc_dev55_xrd-5Fconfig.htm-23-5FToc88513970&d=DwIDaQ&c=gRgGjJ3BkIsb5y6s49QqsA&r=60rQ0HHqHmEY1P6VSdyuTQ&m=jvLrAHOobeDBj_z436J39DyaJcRav3b6fPALzgfIjA6JvIJEM2iAOLmJ2fXsxekx&s=f_TeepKIvTNaW4Cr-dUAOt90pMzaK4l-kxTLs26LIyk&e= > seems to suggest a proxy server would be necessary in this case.  Is that correct?
>>
>> If so, what exactly does this proxy server do, and how is it set up?
>>
>> Thanks,
>>
>> Al
>>
>> ________________________________________________
>> Albert L. Rossi
>> Senior Software Developer
>> Scientific Computing Division, Scientific Data Services, Distributed Data Development
>> FCC 229A
>> Mail Station 369 (FCC 2W)
>> Fermi National Accelerator Laboratory
>> Batavia, IL 60510
>> (630) 840-3023
>>
>>
>>
>>
>> *********************************************************************************
>> The Provider of this service, in the legal sense, the Deutsche Elektronen-
>> Synchrotron DESY.
>>
>> Handling personal information: DESY takes the protection of personal information
>> seriously. DESY undertakes to protect the private sphere of all persons using its
>> services and to treat any personal information provided in strictest confidence.
>> The information is solely used for the respective purposes given and will not be
>> passed on to third parties. It will be deleted as soon as it has served the given
>> purpose. More info: https://www.desy.de/data_privacy_policy/index_eng.html
>> *********************************************************************************
>>
>> ########################################################################
>> Use REPLY-ALL to reply to list
>>
>> To unsubscribe from the XROOTD-DEV list, click the following link:
>> https://urldefense.proofpoint.com/v2/url?u=https-3A__listserv.slac.stanford.edu_cgi-2Dbin_wa-3FSUBED1-3DXROOTD-2DDEV-26A-3D1&d=DwIDaQ&c=gRgGjJ3BkIsb5y6s49QqsA&r=60rQ0HHqHmEY1P6VSdyuTQ&m=jvLrAHOobeDBj_z436J39DyaJcRav3b6fPALzgfIjA6JvIJEM2iAOLmJ2fXsxekx&s=Vr1SHCZzQ3tAZ16sJIuQx6Cxw_PrMNIxGcSnq8A_L-o&e=
>>
>
> ########################################################################
> Use REPLY-ALL to reply to list
>
> To unsubscribe from the XROOTD-DEV list, click the following link:
> https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1
>

########################################################################
Use REPLY-ALL to reply to list

To unsubscribe from the XROOTD-DEV list, click the following link:
https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1