(Adding LEGACY_ALLOW_SEMANTICS = TRUE doesn't solve the
problem. )
Trying to drain a node using:
The worker node seems to look only for GSI
2/04/22
10:34:41 DC_AUTHENTICATE: required authentication of
CM_IP failed: AUTHENTICATE:1003:Failed to authenticate
with any method|AUTHENTICATE:1004:Failed to authenticate
using GSI|GSI:5003:Failed to authenticate. Globus is
reporting error (851968:254). There is probably a problem
with your credentials. (Did you run
grid-proxy-init?)|AUTHENTICATE:1004:Failed to authenticate
using KERBEROS|AUTHENTICATE:1004:Failed to authenticate
using FS|FS:1004:Unable t
o lstat(/tmp/FS_XXXZpyt30)
Looking at the DAEMON nobs at both the CM and the startd:
cm
~]# sudo grep -R DAEMON /etc/condor/*
/etc/condor/config.d/50-security:SEC_DAEMON_AUTHENTICATION
= REQUIRED
/etc/condor/config.d/50-security:SEC_DAEMON_INTEGRITY =
REQUIRED
/etc/condor/config.d/50-security:SEC_DAEMON_AUTHENTICATION_METHODS =
PASSWORD
/etc/condor/config.d/50-security:ALLOW_DAEMON =
condor_pool@*/*, condor@*/$(IP_ADDRESS)
cm
~]# condor_config_val -dump | grep DAEMON
ALLOW_DAEMON =
condor_pool@*/*, condor@*/$(IP_ADDRESS)
AUTO_INCLUDE_CREDD_IN_DAEMON_LIST = false
AUTO_INCLUDE_SHARED_PORT_IN_DAEMON_LIST = true
DAEMON_LIST =
MASTER COLLECTOR NEGOTIATOR
DAEMON_SOCKET_DIR =
auto
DC_DAEMON_LIST =
GSI_DAEMON_CERT =
GSI_DAEMON_DIRECTORY =
GSI_DAEMON_KEY =
GSI_DAEMON_NAME =
GSI_DAEMON_PROXY =
GSI_DAEMON_TRUSTED_CA_DIR
=
MASTER_DAEMON_AD_FILE =
SCHEDD_DAEMON_AD_FILE =
$(SPOOL)/.schedd_classad
SEC_DAEMON_AUTHENTICATION
= REQUIRED
SEC_DAEMON_AUTHENTICATION_METHODS
= PASSWORD
SEC_DAEMON_INTEGRITY =
REQUIRED
SHARED_PORT_DAEMON_AD_FILE =
$(LOCK)/shared_port_ad
START_DAEMONS =
wn001:~$
sudo grep -R DAEMON /etc/condor/*
/etc/condor/config.d/50-security:SEC_DAEMON_AUTHENTICATION = REQUIRED
/etc/condor/config.d/50-security:SEC_DAEMON_INTEGRITY =
REQUIRED
/etc/condor/config.d/50-security:SEC_DAEMON_AUTHENTICATION_METHODS =
PASSWORD
/etc/condor/config.d/50-security:ALLOW_DAEMON =
condor_pool@*/*, condor@*/$(IP_ADDRESS)
wn001:~$
condor_config_val -dump | grep DAEMON
ALLOW_DAEMON =
condor_pool@*/*, condor@*/$(IP_ADDRESS)
AUTO_INCLUDE_CREDD_IN_DAEMON_LIST = false
AUTO_INCLUDE_SHARED_PORT_IN_DAEMON_LIST = true
DAEMON_LIST =
MASTER, STARTD
DAEMON_SOCKET_DIR =
auto
DC_DAEMON_LIST =
GSI_DAEMON_CERT =
GSI_DAEMON_DIRECTORY =
GSI_DAEMON_KEY =
GSI_DAEMON_NAME =
GSI_DAEMON_PROXY =
GSI_DAEMON_TRUSTED_CA_DIR
=
MASTER_DAEMON_AD_FILE =
SCHEDD_DAEMON_AD_FILE =
$(SPOOL)/.schedd_classad
SEC_DAEMON_AUTHENTICATION
= REQUIRED
SEC_DAEMON_AUTHENTICATION_METHODS
= PASSWORD
SEC_DAEMON_INTEGRITY =
REQUIRED
SHARED_PORT_DAEMON_AD_FILE =
$(LOCK)/shared_port_ad
START_DAEMONS =