[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Condor-users] Condor doesn't appear to respect X509_USER_PROXY



 I have my X509_USER_PROXY pointing to a valid proxy cert in my
NFS-mounted home directory (/nfs/home/ijstokes/.globus/x509up_u1004),
but condor seems to insist on looking for it in /tmp, despite what the
docs say here:

http://www.cs.wisc.edu/condor/manual/v7.4/3_6Security.html

I can copy the proxy cert to /tmp, but I need it in the NFS location for
other services on other hosts, and copying it around is just asking for
problems later, when one expires, and the other is renewed/updated.

Is this a bug, or am I doing something wrong?  Trace below.

Thanks,

Ian

$ echo $X509_USER_PROXY
/nfs/home/ijstokes/.globus/x509up_u1004

$ voms-proxy-info
WARNING: Unable to verify signature! Server certificate possibly not
installed.
Error: Cannot verify AC signature!
subject   : /DC=org/DC=doegrids/OU=People/CN=Ian Stokes-Rees 411174/CN=proxy
issuer    : /DC=org/DC=doegrids/OU=People/CN=Ian Stokes-Rees 411174
identity  : /DC=org/DC=doegrids/OU=People/CN=Ian Stokes-Rees 411174
type      : proxy
strength  : 1024 bits
path      : /nfs/home/ijstokes/.globus/x509up_u1004
timeleft  : 185:19:16


$ condor_version
$CondorVersion: 7.5.3 Jun 25 2010 BuildID: 250654 $
$CondorPlatform: X86_64-LINUX_RHEL5 $


$ condor_submit_dag -debug 2 -outfile_dir ../config ../config/yn_p4b.dag

Submitting job(s)
ERROR:
GSS Major Status: General failure
GSS Minor Status Error Chain:
import_cred.c:gss_import_cred:183:
Unable to read credential for import: Couldn't open the file:
/tmp/x509up_u1004

ERROR: condor_submit failed; aborting.

begin:vcard
fn:Ian Stokes-Rees, PhD
n:Stokes-Rees;Ian
org:Harvard Medical School;Biological Chemistry and Molecular Pharmacology
adr:250 Longwood Ave;;SGM-105;Boston;MA;02115;USA
email;internet:ijstokes@xxxxxxxxxxxxxxxxxxx
title:Research Associate, Sliz Lab
tel;work:+1.617.432.5608 x75
tel;fax:+1.617.432.5600
tel;cell:+1.617.331.5993
url:http:/sbgrid.org
version:2.1
end:vcard