JiscMail Logo
Email discussion lists for the UK Education and Research communities

Help for GRIDPP-STORAGE Archives


GRIDPP-STORAGE Archives

GRIDPP-STORAGE Archives


GRIDPP-STORAGE@JISCMAIL.AC.UK


View:

Message:

[

First

|

Previous

|

Next

|

Last

]

By Topic:

[

First

|

Previous

|

Next

|

Last

]

By Author:

[

First

|

Previous

|

Next

|

Last

]

Font:

Proportional Font

LISTSERV Archives

LISTSERV Archives

GRIDPP-STORAGE Home

GRIDPP-STORAGE Home

GRIDPP-STORAGE  August 2018

GRIDPP-STORAGE August 2018

Options

Subscribe or Unsubscribe

Subscribe or Unsubscribe

Log In

Log In

Get Password

Get Password

Subject:

Voms Admin Interface Thread

From:

sjones <[log in to unmask]>

Reply-To:

sjones <[log in to unmask]>

Date:

Wed, 22 Aug 2018 13:24:33 +0100

Content-Type:

text/plain

Parts/Attachments:

Parts/Attachments

text/plain (167 lines)

Hi All,

I've dumped all the emails into one file, see below.

Ste


-----------------------------------------------
VOMS Admin Interface Emails

--- Steve Timm (DUNE)  ---

Fermilab is in the process of transitioning away from a web-based 
VOMS-Admin server for the DUNE and Fermilab VO's.  This is likely to 
happen on or after September 17.  Once the VOMS-Admin server is turned 
off, we will then distribute the list of Distinguished Names to the 
sites that need it via a manual script that can be pushed to your 
storage element and picked up from there.

The only GridPP site that we currently are aware that needs the list of 
DN's, is RAL's Echo SE. This list of DN's was generated manually when we 
onboarded that site and we have not added anything to it.

However I see that almost all the UK sites are still contacting our 
VOMS-Admin server on a regular basis. So I want to understand what is 
causing that, and if any authentication is likely to break once it does 
go away. The host names we see:


<log list of se, and the dirac server at ICL>

--- Reply from Daniela (GridPP Dirac) ---

Hi Steven, Given that the voms interface is a standard voms component, I 
don't understand why FNAL wants to turn it off. (Even CERN still 
maintains this.) It's just going to make integration with the rest of 
the world harder, because you'll be the only VO out there that does 
this, but you probably know this :-S @Raja: Do you know if DPM webdav 
will be affected ?

--- Reply from Steven Timm ---

The CERN security people keep telling us that they will turn off public 
access to their VOMS-Admin server as well within the next year or so.  
The people who run the actual VOMS servers at CERN know nothing about 
that plan. There are allegedly problems that VOMS-Admin is not 
compatible with GDPR regulations, it lets too much info out.

All US VO's are ditching VOMS-Admin (Against my strong protestations) 
because they can no longer get maintenance for the branch of the 
software they are on.  We will still keep the underlying voms server and 
have voms-proxy-init, voms-proxy-info  and so forth work as they did 
before.

The people at CERN who have a very similar setup say that anything which 
uses Argus for authentication should be able to operate in the mode 
where it just looks at the voms-proxy as presented to it, and they claim 
that the CERN compute side is operating in this mode at the moment.  The 
storage side at cern, which is EOS, doesn't know anything about VOMS 
proxies and just needs the list of DN's.  It is my understanding that we 
are in a similar situation with RAL which just needs the list of DN's.. 
the question is, what are all the DPM SE's doing. Steve

--- Reply from Daniela ---

This is actually worse than I first thought.

When I said dirac01 would disappear because we won't need to support
DUNE any longer on the GridPP DIRAC server I had forgotten that LSST
also uses the FNAL voms server. LSST is just doing a major production
run in the UK *right now* using the GridPP DIRAC instance  and a
subset of the storage elements mentioned here, e.g. Manchester and
QMUL.  If this causes access problems to their data this will be a
major set back.

In DIRAC we use the voms admin interface to automatically register
users if they belong to a VO we support. Until we wrote (and some
people on this mailing list might remember) this automated sync tool
we had to register people by hand which was just not scalable - we
support about 15 VOs of various sizes. Now LSST won't stop working on
day one on DIRAC obviously, but not being able to access a list of VO
members would require a major rewrite of the DIRAC software (unless
Raja tells me LHCb has an alternative solution that does not involve
direct access to a database at CERN).

@Steven Timm: Is that script you were talking about earlier available
somewhere so we can have a look at how we would actually receive the
information and maybe getting a head start ?

It should be noted that EOS/Echo are the exception in the UK and the
voms aware implementations of storage are by far the majority. (The
'only works at CERN/RAL type solutions' are a bit of a sore spot among
the lower ranks here, or maybe it's just me.) I don't really believe
the GRDP hype, most commercial organisations seem to be able to work
around it perfectly fine, but that's beyond the point here.

Regards, Daniela

--- Reply from Steven Timm

Some of my colleagues talked to LSST people and they say that LSST has 
agreed to move their VOMS-Admin server away from Fermilab entirely.  As 
far as I know the new location has not yet been named, nor has that new 
site yet contacted me to get the existing information of the VO.  (We 
will verify all of this before we turn the "off" switch at this end).

--- Steven Timm, this time to Alessandra ---

Hi Alessandra-- Jobs will still arrive with valid coms-proxies signed by 
the VOMS server.
What will not be available are any of the things that require querying 
the voms-admin servers for the list of members.

I am not familiar enough with the guts of the DPM storage element and 
how it does its authorization but it appears that most of the SE's that 
are calling the dune
voms-admin servers are doing the VomsCompatibilityService 
/getGridmapUsers
call for each of the groups in dune.  Is that correct?

Does DPM make a grid-mapfile or is it done by some other means?

I need the technical details so I can correctly make the argument to 
management as to what needs to be done. Steve

--- Ste Jones copies in Sam ---

Hi Steve (Timm), We're trying to find out why an SE queries the admin 
port on your voms server. We'll let you know when we find out. Copying 
in Sam ... Sam, our DPM storage nodes call out to the VOMS port on the 
DUNE/FNAL VOMs Server.  Any idea what that's all about? This is 
happening at a bunch of sites that support DUNE. What does DPM need a 
list of users for? Does it still need to make a gridmapfile? What do you 
think?

--- Reply from Alessandra ---

It (DPM) does (use a gridmapfile)

--- Reply from Daniela ---

I almost suspect some of these warnings actually come from lsst rather
than dune. @Steven T: Would you mind generating a complete list of UK 
services
accessing the voms interface ? I'm just worried that there are other
surprises waiting. Daniela


--- Reply from STeve Timm---

I am attaching three files--these show respectively all the accesses to
https://voms.fnal.gov:8443/voms/dune,
https://voms.fnal.gov:8443/voms/fermilab,
and https://voms.fnal.gov:8443/voms/lsst

This time period is today in UTC time stamps starting from 05:00 UTC = 
00:00 local time at Fermilab.


(SJ Note: the files contained logs of accesses by many storage elements 
at the sites that support Dune, LSST... and also the Dirac requests)

########################################################################

To unsubscribe from the GRIDPP-STORAGE list, click the following link:
https://www.jiscmail.ac.uk/cgi-bin/webadmin?SUBED1=GRIDPP-STORAGE&A=1

Top of Message | Previous Page | Permalink

JiscMail Tools


RSS Feeds and Sharing


Advanced Options


Archives

May 2024
April 2024
March 2024
February 2024
January 2024
December 2023
November 2023
October 2023
September 2023
August 2023
July 2023
June 2023
May 2023
April 2023
March 2023
February 2023
January 2023
December 2022
November 2022
October 2022
September 2022
August 2022
July 2022
June 2022
May 2022
April 2022
March 2022
February 2022
January 2022
December 2021
November 2021
October 2021
September 2021
August 2021
July 2021
June 2021
May 2021
April 2021
March 2021
February 2021
January 2021
December 2020
November 2020
October 2020
September 2020
August 2020
July 2020
June 2020
May 2020
April 2020
March 2020
February 2020
January 2020
December 2019
November 2019
October 2019
September 2019
August 2019
July 2019
June 2019
May 2019
April 2019
March 2019
February 2019
January 2019
December 2018
November 2018
October 2018
September 2018
August 2018
July 2018
June 2018
May 2018
April 2018
March 2018
February 2018
January 2018
December 2017
November 2017
October 2017
September 2017
August 2017
July 2017
June 2017
May 2017
April 2017
March 2017
February 2017
January 2017
December 2016
November 2016
October 2016
September 2016
August 2016
July 2016
June 2016
May 2016
April 2016
March 2016
February 2016
January 2016
December 2015
November 2015
October 2015
September 2015
August 2015
July 2015
June 2015
May 2015
April 2015
March 2015
February 2015
January 2015
December 2014
November 2014
October 2014
September 2014
August 2014
July 2014
June 2014
May 2014
April 2014
March 2014
February 2014
January 2014
December 2013
November 2013
October 2013
September 2013
August 2013
July 2013
June 2013
May 2013
April 2013
March 2013
February 2013
January 2013
December 2012
November 2012
October 2012
September 2012
August 2012
July 2012
June 2012
May 2012
April 2012
March 2012
February 2012
January 2012
December 2011
November 2011
October 2011
September 2011
August 2011
July 2011
June 2011
May 2011
April 2011
March 2011
February 2011
January 2011
December 2010
November 2010
October 2010
September 2010
August 2010
July 2010
June 2010
May 2010
April 2010
March 2010
February 2010
January 2010
December 2009
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008
August 2008
July 2008
June 2008
May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
February 2007
January 2007
December 2006
November 2006
October 2006
September 2006
August 2006
July 2006
June 2006
May 2006
April 2006
March 2006
February 2006
January 2006
December 2005
November 2005
October 2005
September 2005
August 2005
July 2005
June 2005
May 2005
April 2005
March 2005
February 2005
January 2005
December 2004
November 2004
October 2004
September 2004
August 2004
July 2004
June 2004


JiscMail is a Jisc service.

View our service policies at https://www.jiscmail.ac.uk/policyandsecurity/ and Jisc's privacy policy at https://www.jisc.ac.uk/website/privacy-notice

For help and support help@jisc.ac.uk

Secured by F-Secure Anti-Virus CataList Email List Search Powered by the LISTSERV Email List Manager