Print

Print


Recently, XRootD started to be unable to find the Kerberos credentials cache. When trying `xrdcp` or `uproot.open()` with an xrootd path (CERN EOS), it fails with 
```
Run: [ERROR] Server responded with an error: [3010] Unable to give access - user access restricted - unauthorized identity used ; Permission denied (source)
```
Running with debugging messages enabled, I see
```
[2023-03-28 13:19:00.725690 +0200][Debug  ][XRootDTransport   ] [eoslhcb.cern.ch:1094.0] Logged in, session: 217a7e00c2330400000a000045778600
[2023-03-28 13:19:00.725695 +0200][Debug  ][XRootDTransport   ] [eoslhcb.cern.ch:1094.0] Authentication is required: &P=krb5,[log in to unmask]&P=gsi,v:10600,c:ssl,ca:5168735f.0|4339b4bc.0&P=sss,0.+13:/etc/eos.keytab&P=unix
[2023-03-28 13:19:00.725704 +0200][Debug  ][XRootDTransport   ] [eoslhcb.cern.ch:1094.0] Sending authentication data
[2023-03-28 13:19:00.743189 +0200][Debug  ][XRootDTransport   ] [eoslhcb.cern.ch:1094.0] Trying to authenticate using krb5
[2023-03-28 13:19:00.744740 +0200][Debug  ][XRootDTransport   ] [eoslhcb.cern.ch:1094.0] Cannot get credentials for protocol krb5: Seckrb5: No or invalid credentials; No credentials cache found ([log in to unmask]).
```
Running `klist` shows that the credentials are there (and `ssh` can find and use them)
```
Credentials cache: API:6136D20A-21F8-4FF3-B968-A4415990AFF1
        Principal: [log in to unmask]

  Issued                Expires               Principal
Mar 28 13:18:54 2023  Mar 28 23:18:52 2023  [log in to unmask]
Mar 28 13:18:55 2023  Mar 28 23:18:52 2023  [log in to unmask]
```

-- 
Reply to this email directly or view it on GitHub:
https://github.com/xrootd/xrootd/issues/1981
You are receiving this because you are subscribed to this thread.

Message ID: <[log in to unmask]>

########################################################################
Use REPLY-ALL to reply to list

To unsubscribe from the XROOTD-DEV list, click the following link:
https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1