ah, I am very sorry! after editing with Emacs I had overlooked a backup file~ in my config.d/ - which naturally followed the 'new' conf and overwrote my changes :-[ After deleting the backup file, anonymous access etc. seems to work now Sorry for the noise Thomas On 19/09/2019 16.25, Thomas Hartmann wrote: > Hi all, > > I am currently trying to opening a test cluster to an outside scheduler, > i.e., beyond our domain. > My plan is to start with CLAIMTOBE/ANONYMOUS and then move up the > security ladder to passwords and gsi/ssl certificates. > > However, I am already struggling to connect with the outside schedd to > the collector with claimtobe/anonymous. > > The collector node should be wide open [1] (I think). But still the > client schedd get's rejected with [2.a,2.b] > > The version is at 8.8.5 [3], i.e., without the security settings added > with 8.9 [3.a]. > > One thing I am wondering is that although ALLOW_* is set to *, the > applied config has *.$(UID_DOMAIN) [4] > > So, I wonder why my sched still is not allowed to connect to the > collector, although it should be wide open(?) ? > > Cheers, > Thomas
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature