Hi Nagaraj,
> This seems to happen just after I updated to lcg-CA-1.22-1.noarch on our
> UI and other site nodes.
> When I try simple command (dpns-ls) I get this error. Here are the tail
> of the output when I set CSEC_TRACE=1
>
> ERROR: initializing context: GSS Error: GSS Major Status: Authentication
> Failed, MECH Error: GSS Minor Status Error Chain:, globus_gsi_gssapi:
> SSLv3 handshake problems, OpenSSL Error: s3_clnt.c:842: in library: SSL
> routines, function SSL3_GET_SERVER_CERTIFICATE: certificate verify
> failed, globus_gsi_callback_module: Could not verify credential,
> globus_gsi_callback_module: Could not verify credential: self signed
> certificate in certificate chain
> _Csec_send_token: Sending packet Magic: ca03 Type: 6, Len: 4
> 00 00 00 00
>
> send2nsd: NS002 - send error : Bad credentials
> Csec_clearContext: Clearing context
> Csec_unload_shlib: Entering
>
> DPNS_HOST points to our SE on which I updated lcg-CA, too.
> Which logs should I check to trace this problem?
Do you have X509_CERT_DIR defined on your UI?
If so, does that directory contain the (latest) CAs?
(The default for X509_CERT_DIR is /etc/grid-security/certificates.)
|