Hi Luke,
The developer before me appears to have added GSI support to the Puppet module. I don't have any of those set in Puppet or on the machine. Yes I meant the 10_security file. We have the CERTIFICATE_MAPFILE set which is generated in Puppet and converts the canonical host names to their function in the pool, the top line specifices the kerberos regex. Authentication works between the rest of the nodes and worked on the CE pre puppet config. I was able to submit and run jobs, plus execute schedd actions. Running a condor_status on the CE would still show the pool even with the bad config. It seems to be something specific to the puppet module's schedd configuration as all the other nodes are configured via puppet as well (workers and cm). Thanks, Iain From: HTCondor-users [htcondor-users-bounces@xxxxxxxxxxx] on behalf of L Kreczko [L.Kreczko@xxxxxxxxxxxxx]
Sent: 25 March 2015 10:14 To: HTCondor-Users Mail List Subject: Re: [HTCondor-users] Configuring a CE/Schedd Dear Iain,
It seems that the authentication between your nodes is not working. Condor attempts FS, then KERBEROS, then GSI authentication and fails on each of them.use_cert_map_file = true use_kerberos_auth = true use_password_auth = false ? condor_ping -addr <condor node>:9618 -table WRITE READ On 24 March 2015 at 18:48, Iain Bradford Steers
<iain.steers@xxxxxxx> wrote:
-- *********************************************************
Dr Lukasz Kreczko +44 (0)117 928 8724 CMS Group School of Physics University of Bristol ********************************************************* |