[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [HTCondor-users] New HTCondor Version Scheme



Tim-

1. It would be a modest improvement if the various repos used the same GPG key.
2. The structure of the repos leads me to the conclusion that I should not give as much of my trust to the X.Y.Z>=1 releases as much as the X.Y.0 releases. I'm already buying into some measure of living on the edge by following you from 9.2.0 to 9.3.0 but you're telling me that 9.2.1 should be a separate opt-in.

1 has a simple reason: a good build process for a Docker image or a re-usable image for a VM probably should focus on installation rather than configuration. In particular, security configurations like the POOL password probably shouldn't end up in your image. So I don't want to use get_htcondor for that reason alone, although I understandÂthe motivation.

The most secure and would-work-even-in-environments-without-outbound-internet build process would allow me to download aÂsigning key thatÂidentifies the CHTC as a trusted source for all your repos. I could then use a local copy of that key for several years until you publicly announce a key rotation.

Status quo: I have to reconstruct the right key file from variables in get_htcondor.

Low on your priority list: but apt-key is deprecated in Debian 11; you're supposed to add "signed-by" a specific path to a key. Read up on it a bit, but it's a security improvement.

Tom

On Thu, Sep 23, 2021 at 8:28 AM Brian Lin <blin@xxxxxxxxxxx> wrote:
Hi Will,

Yes, 9.0.X will have what you need to support SciTokens and WLCG tokens.

- Brian

On 9/23/21 8:25 AM, William Strecker-Kellogg via HTCondor-users wrote:
> On 9/22/21 18:19, Bockelman, Brian wrote:
>> X.0.Y are now the "Long Term Support" releases and available through
>> the stable release channel. They are the equivalent to the old prod
>> series and have similar support lifetime and guarantees.
>
> Is it reasonable to expect that (for example) a major WLCG site like a
> Tier 1 can run a stable 9.0.X and still have all the features required
> for things like the upcoming token transition?
>
> Will
> _______________________________________________
> HTCondor-users mailing list
> To unsubscribe, send a message to htcondor-users-request@xxxxxxxxxxx
> with a
> subject: Unsubscribe
> You can also unsubscribe by visiting
> https://lists.cs.wisc.edu/mailman/listinfo/htcondor-users
>
> The archives can be found at:
> https://lists.cs.wisc.edu/archive/htcondor-users/

_______________________________________________
HTCondor-users mailing list
To unsubscribe, send a message to htcondor-users-request@xxxxxxxxxxx with a
subject: Unsubscribe
You can also unsubscribe by visiting
https://lists.cs.wisc.edu/mailman/listinfo/htcondor-users

The archives can be found at:
https://lists.cs.wisc.edu/archive/htcondor-users/