Hi all,
If I try globus-url-copy from the pool accounts on WN to the CE, I get
this:
[farm030] /home/dteam005 > globus-url-copy file:/etc/group
gsiftp://serv03.hep.phy.cam.ac.uk/tmp/test.$$
error: globus_l_ftp_control_send_cmd_cb: gss_init_sec_context failed
GSS failure:
GSS Major Status: Authentication Failed
GSS Minor Status Error Chain:
init_sec_context.c:171: gss_init_sec_context: SSLv3 handshake problems
globus_i_gsi_gss_utils.c:881: globus_i_gsi_gss_handshake: Unable to
verify remote side's credentials
globus_i_gsi_gss_utils.c:854: globus_i_gsi_gss_handshake: SSLv3
handshake problems: Couldn't do ssl handshake
OpenSSL Error: s3_clnt.c:840: in library: SSL routines, function
SSL3_GET_SERVER_CERTIFICATE: certificate verify failed
globus_gsi_callback.c:351: globus_i_gsi_callback_handshake_callback:
Could not verify credential
globus_gsi_callback.c:477: globus_i_gsi_callback_cred_verify: Could not
verify credential
globus_gsi_callback.c:769: globus_i_gsi_callback_check_revoked: Invalid
CRL: The available CRL has expired
Running cron job by hand on CE reports:
[root@serv03 root]# /opt/edg/etc/cron/edg-fetch-crl-cron
edg-fetch-crl: [2005/05/23-00:14:19] verify failed for CRL issued by
'/CN=SWITCH' (verify failure)
but all my nodes got 0.29-1 CA rpms installed
[root@serv03 root]# rpm -qa | grep ca_SWITCH
ca_SWITCH-0.29-1
and also synchronized with the time server. Any clue from anybody
what's wrong with swisssign? Can any one please help??
Thanks,
Santanu
On May 19, 2005, at 3:43 PM, Fokke Dijkstra wrote:
> There is no upgrade for ca_DOESG-Root-0.28-1. Should it be removed?
>
> Kind regards,
>
> Fokke Dijkstra
|