[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [HTCondor-users] dirty AFS hook stuff?



For both AFS and DFS in the past I used an encrypted stored copy of the users password stored in the users own account. Since all processes start as root there was no concern about storing this information protected 0600 with standard acl's. 

Mcrypt and mdecrypt are simple tools to use for this purpose.

Yes I admit it's a hack. It does not however open all of your users up to being compromised if one account gets hacked.

I have used this approach with condor, LSF, NQS, torque, PBSPro and load leveler a condor derivative. 

Rich

Sent from my iPad

> On Nov 9, 2013, at 21:29, "Brian Bockelman" <bbockelm@xxxxxxxxxxx> wrote:
> 
> Hi Daniel,
> 
> I don't know much about AFS myself, but this page may be relevant:
> 
> http://www.hep.wisc.edu/~dan/Globus_AFS.html
> 
> HTH,
> 
> Brian
> 
>> On Nov 8, 2013, at 6:15 AM, Pek Daniel <pekdaniel@xxxxxxxxx> wrote:
>> 
>> Hi,
>> 
>> I know that HTCondor processes do not run authenticated to AFS. I'd
>> like to solve this issue by some dirty hack with hook scripts, etc.
>> Have anybody tried to do it so far, or have some clues where to start
>> to make it real? Users should be able to submit jobs which would run
>> in their names and have access to their AFS stuff.
>> 
>> Thanks,
>> Daniel
>> _______________________________________________
>> HTCondor-users mailing list
>> To unsubscribe, send a message to htcondor-users-request@xxxxxxxxxxx with a
>> subject: Unsubscribe
>> You can also unsubscribe by visiting
>> https://lists.cs.wisc.edu/mailman/listinfo/htcondor-users
>> 
>> The archives can be found at:
>> https://lists.cs.wisc.edu/archive/htcondor-users/
> 
> _______________________________________________
> HTCondor-users mailing list
> To unsubscribe, send a message to htcondor-users-request@xxxxxxxxxxx with a
> subject: Unsubscribe
> You can also unsubscribe by visiting
> https://lists.cs.wisc.edu/mailman/listinfo/htcondor-users
> 
> The archives can be found at:
> https://lists.cs.wisc.edu/archive/htcondor-users/
Notice:  This e-mail message, together with any attachments, contains
information of Merck & Co., Inc. (One Merck Drive, Whitehouse Station,
New Jersey, USA 08889), and/or its affiliates Direct contact information
for affiliates is available at 
http://www.merck.com/contact/contacts.html) that may be confidential,
proprietary copyrighted and/or legally privileged. It is intended solely
for the use of the individual or entity named on this message. If you are
not the intended recipient, and have received this message in error,
please notify us immediately by reply e-mail and then delete it from 
your system.