Gidon Moont wrote:
> Hi
>
>> How can I really check the VOMS extension of the user and see if it
>> is really in bad shape?
>
> The openssl command can tell you more - you need to use a more
> uptodate version than the middleware distributed one...
>
> The main thing to notice with clocks is that although proxy
> generation is such that the From time is five minutes in the past -
> to cope with sloppy clocks (so making the total time +5 minutes from
> what you asked for), the VOMS AC is not - see GENERALIZEDTIME bits
> below.
The five minute adjustement is done in the verification code. The ACs
report the correct date, as known to the server.
Ciao,
Vincenzo
|