Hi Mark,
depending on the version of the UI check the version of CA packages they
have to be 1.52-1
EMI UI
rpm -qa ca-policy-egi-core
ca-policy-egi-core-1.52-1
glite UI
rpm -qa lcg-CA
lcg-CA-1.52-1
The cartificates are always in the same place
/etc/grid-security/certificates.
I can see the file from Manchester.
cheers
alessandra
On 06/02/2013 13:41, Mark Slater wrote:
> I should probably add, this is technically a dq2-get (which is
> essentially an lcg-cp) that seems to work at CERN!
>
> Thanks,
>
> Mark
>
> On 06/02/13 13:36, Mark Slater wrote:
>> Hi All,
>>
>> My knowledge of the UI is not what it should be and I can never
>> figure out where a problem lies when it complains of CAs or certs or
>> whatever. Here is a case in point:
>>
>>
>>
>> Trying SURL
>> srm://osgserv04.slac.stanford.edu:8443/srm/v2/server?SFN=/xrootd/atlas/atlasuserdisk/user.mslater.20130206101208.frD4PD.id_0.data11_7TeV.periodD.physics_Egamma.PhysCont.AOD.pro10_v01.0.00180153.physic.j9.t0.trf0.u9.6348.ANALY_SLAC.merge/user.mslater.030395._1729382588.merge.log.tgz
>> ...
>> [SE][Ls][] httpg://osgserv04.slac.stanford.edu:8443/srm/v2/server:
>> CGSI-gSOAP running on eprex11 reports Error initializing context
>> GSS Major Status: Authentication Failed
>>
>> GSS Minor Status Error Chain:
>> globus_gsi_gssapi: SSLv3 handshake problems
>> OpenSSL Error: s3_clnt.c:915: in library: SSL routines, function
>> SSL3_GET_SERVER_CERTIFICATE: certificate verify failed
>> globus_gsi_callback_module: Could not verify credential
>> globus_gsi_callback_module: The certificate has expired: Credential
>> with subject: /DC=org/DC=DOEGrids/OU=Certificate
>> Authorities/CN=DOEGrids CA 1 has expired.
>>
>>
>> [SE][ReleaseFiles][]
>> httpg://osgserv04.slac.stanford.edu:8443/srm/v2/server: CGSI-gSOAP
>> running on eprex11 reports Error initializing context
>> GSS Major Status: Authentication Failed
>>
>> GSS Minor Status Error Chain:
>> globus_gsi_gssapi: SSLv3 handshake problems
>> OpenSSL Error: s3_clnt.c:915: in library: SSL routines, function
>> SSL3_GET_SERVER_CERTIFICATE: certificate verify failed
>> globus_gsi_callback_module: Could not verify credential
>> globus_gsi_callback_module: The certificate has expired: Credential
>> with subject: /DC=org/DC=DOEGrids/OU=Certificate
>> Authorities/CN=DOEGrids CA 1 has expired.
>>
>> lcg_cp: Communication error on send
>>
>>
>> Where has the DOE cert expired? In the UI install or on their end? If
>> it's on our end, what do I need to update?
>>
>> On a side note, if there's any docs on configuring and administering
>> the UI I'd be very grateful!
>>
>> Thanks,
>>
>> Mark
--
Facts aren't facts if they come from the wrong people. (Paul Krugman)
|