Re: [Condor-users] Condor-G + Globus proxy delegation problem ( Unknown CA )

Hi Ian,

Yes there is a signing_policy file that I post below:

# ca-signing-policy.conf, see ca-signing-policy.doc for more information
# This is the configuration file describing the policy for what CAs are
# allowed to sign whoses certificates.
# This file is parsed from start to finish with a given CA and subject
# name.
# subject names may include the following wildcard characters:
#    *    Matches any number of characters.
#    ?    Matches any single character.
# CA names must be specified (no wildcards). Names containing whitespaces
# must be included in single quotes, e.g. 'Certification Authority'.
# Names must not contain new line symbols.
# The value of condition attribute is represented as a set of regular
# expressions. Each regular _expression_ must be included in double quotes.
# This policy file dictates the following policy:
#   -The Globus CA can sign Globus certificates
# Format:
#  token type  | def.authority |                value
# EACL entry #1|

 access_id_CA      X509         '/O=Grid/OU=GlobusTest/OU=simpleCA-pc222771.corp.ad.emb/CN=Globus Simple CA'

 pos_rights        globus        CA:sign

 cond_subjects     globus       '"/O=Grid/OU=GlobusTest/OU=simpleCA-pc222771.corp.ad.emb/*"'

# end of EACL

The list of files that are available at $GLOBUS_LOCATION/share/certificates are:

globus@pc222771:~> ls -l $GLOBUS_LOCATION/share/certificates
total 20
-rw-r--r-- 1 root root  952 2008-12-02 14:08 7a6f0f62.0
-rw-r--r-- 1 root root 1357 2008-12-02 14:08 7a6f0f62.signing_policy
-rw-r--r-- 1 root root 2719 2008-12-02 14:08 globus-host-ssl.conf.7a6f0f62
-rw-r--r-- 1 root root 2830 2008-12-02 14:08 globus-user-ssl.conf.7a6f0f62
-rw-r--r-- 1 root root 1375 2008-12-02 14:08 grid-security.conf.7a6f0f62

Seems to be according to the refered link.


> The Condor Gridmanagerlog log file has some messages:
> ...
> 2/18 08:48:49 [4098] GAHP[4100] (stderr) ->  
> org.globus.common.ChainedIOException: Authentication failed [Caused  
> by: Failure unspecified at GSS-API level [Caused by: Unknown CA]]



It looks like there's an authentication problem because the CA isn't  

One idea: Do you have a signing_policy file?  It would be:

See also:




