Hi Ming Chao,
it has been a while since this discussion began, but I am presently submitting a large number of MC production jobs for t2k.org and I am seeing many jobs fail again due to proxy expiration, presumably because the automatic renewal has failed.
I presently create 3 long-term proxies every week:
# IFIC WMS not trusted by RAL myproxy server, define
export IFIC_WMS=/DC=es/DC=irisgrid/O=ific/CN=wms01.ific.uv.es
# now delegate a proxy specifically to IFIC WMS
myproxy-init -v -d -n -x -R $IFIC_WMS -s $MYPROXY_SERVER --voms t2k.org:/t2k.org/Role=production -k ific
# generate a myproxy that allows automatic delegataion of short term proxies (requires password file)
myproxy-init -v -d -a -s $MYPROXY_SERVER --voms t2k.org:/t2k.org/Role=production -k renew
# a default (no name) long term proxy used by RAL (trusted) WMSs, FTS etc
myproxy-init -v -d -n -s $MYPROXY_SERVER --voms t2k.org:/t2k.org/Role=production
the first is delegated specifically to the IFIC WMS because this WMS is not 'trusted' by the RAL myproxy server as per this thread; the second is a proxy that enables automatic delegation via a password file, which isn't really needed for processing/production - I just have a cron job that retrieves a fresh voms proxy every 12 hrs from this one to keep my UI certified; the third is the generic (note it has no name) long-term proxy on the RAL myproxy server that all the other WMSs use.
I then submit jobs via the command:
glite-wms-job-submit -a -c autowms.conf -o <output_path>.jid <jdl_file>.jdl
Can you see anything obviously wrong with this approach?
Best regards
Jonathan
|