Hi Ben,
if this is a home grown install I would recommend using a tar ball, in
my experience they are a lot easier to install (no worrying about
repos etc) if only because in my experience 99% of all UIs are tar
ball installs.
You can check where the UI is looking for its CAs by doing sourcing
the grid_env.sh (to set up the UI) and then do env | sort
and check where X509_CERT_DIR etc are pointing to.
Cheers,
Daniela
On 15 February 2011 09:37, Ben Still <[log in to unmask]> wrote:
> Hi Stephen,
> Thank you for your response. On Chris' suggestion I asked the user in
> question to install the EGI trust
> anchors https://wiki.egi.eu/wiki/EGI_IGTF_Release he did this as root but is
> till recieving errors (see below). Is this due to some environment variable
> not being set? Or something else?
> Cheers,
> Ben
> $ voms-proxy-init -voms t2k.org
> Enter GRID pass phrase:
> Your identity: /C=JP/O=KEK/OU=CRC/OU=TRIUMF/CN=Kenji Hamano
> Creating temporary proxy ............................. Done
> Contacting voms.gridpp.ac.uk:15003
> [[log in to unmask]]
> "t2k.org" Failed
> Error: Error during SSL
> handshake:error:8006641C:lib(128):verify_callback:remote certificate signed
> by unknown CA:sslutils.c:2547
> remote certificate signed by unknown CA:verify_callback
> error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify
> failed:s3_clnt.c:915
> certificate verify failed:SSL3_GET_SERVER_CERTIFICATE
> Trying next server for t2k.org.
> Creating temporary proxy ............................................ Done
> Contacting voms.gridpp.ac.uk:15003
> [[log in to unmask]]
> "t2k.org" Failed
> Error: Error during SSL
> handshake:error:8006641C:lib(128):verify_callback:remote certificate signed
> by unknown CA:sslutils.c:2547
> remote certificate signed by unknown CA:verify_callback
> error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify
> failed:s3_clnt.c:915
> certificate verify failed:SSL3_GET_SERVER_CERTIFICATE
> None of the contacted servers for t2k.org were capable
> of returning a valid AC for the user.
> On 14 Feb 2011, at 09:52, Stephen Burke wrote:
>
> Testbed Support for GridPP member institutes
> [mailto:[log in to unmask]] On Behalf Of Ben Still said:
>
> Error: Error during SSL
> handshake:error:8006641C:lib(128):verify_callback:remote
>
> certificate signed by unknown CA:sslutils.c:2547
>
> remote certificate signed by unknown CA:verify_callback
>
> That looks like the UI where the command is being issued doesn't have the UK
> CA installed.
>
> Stephen
>
> Dr Ben Still
> Postdoctoral Research Assistant
> Particle Physics Research Centre
> Queen Mary, University of London
> G.O. Jones Building
> 327 Mile End Road
> London
> E1 4NS, UK
> [log in to unmask]
>
>
>
>
>
>
--
-----------------------------------------------------------
[log in to unmask]
HEP Group/Physics Dep
Imperial College
Tel: +44-(0)20-75947810
http://www.hep.ph.ic.ac.uk/~dbauer/
|