Hi Winnie,
> If gridmapdir should be root:glexec to have new pool account mappings made
> by glexec, [...]
The gridmapdir should just be writable for root.
The CERN CREAM CEs had it as follows for historical reasons, without problems:
drwxrwx--- 3 root edguser 970752 Nov 19 21:13 /etc/grid-security/gridmapdir/
|