[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Condor-users] GSI auth in Windows



On 21 Aug 2012, at 10:33, Zachary Miller wrote:
> 
> looks good except for one thing:
>> SEC_CLIENT_AUTHENTICATION_METHODS = fs, password, ssl
> 
> the guide you were following was from a linux point of view.  FS authentication
> does exist on windows, so the line should actually read:
>  SEC_CLIENT_AUTHENTICATION_METHODS = ntsspi, password, ssl

Ah, of course!  That sorted it out.  Thanks.  Presumably my Condor cluster is now secure, even though I have ALLOW_WRITE = *.my.domain configured?  It is impossible for someone to send spoof WRITE commands without authenticating a daemon to do so?

Is it worth contributing my condor_config.local to the "Condor on Windows" bit of the wiki?

Thanks,

Chris


--
Dr Chris Jewell
Lecturer in Biostatistics
Institute of Fundamental Sciences
Massey University
Private Bag 11222
Palmerston North 4442
New Zealand
Tel: +64 (0) 6 350 5701 Extn: 3586