December 17, 2015 A Secure VO Software for ATLAS Grid User Management Dantong Yu Brookhaven National Lab
December 17, 2015 The packages I am using: GroupMan: VO server management tools new edg-mkgridmap package
December 17, 2015 Virtual Organization GUMS: A scalable Grid User Management System User info UNM
December 17, 2015 grid-mapfile generation mkgridmap grid-mapfile o=atlas, dc=ppdg-atagrid, dc=org ou=us-atlas, OU=People ou=atlas-dc1, CN=Dantong YuCN=Jason SmithCN=Ed-May DOE Science Grid Certificate Authorities OU=People CN=Dantong YuCN=Jason SmithCN=Ed-May CA server VO server
December 17, 2015 Configure mkgridmap.conf #### GROUP: group URI [lcluser] group ldaps://atlasgrid01.usatlas.bnl.gov:6220/ou=us- atlas,o=atlas,dc=ppdg-datagrid,dc=org #group ldap://grid-vo.nikhef.nl/ou=testbed1,o=atlas,dc=eu- datagrid,dc=org #group ldap://grid-vo.nikhef.nl/ou=testbed1,o=cms,dc=eu- datagrid,dc=org #### Optional - DEFAULT LOCAL USER: default_lcluser lcluser default_lcluser AUTO #### Optional - AUTHORIZED VO: auth URI auth ldap:// spider.usatlas.bnl.gov /ou=people,o=o=atlas,dc=ppdg-datagrid,dc=org #### Optional - ACL: deny|allow pattern_to_match allow *INFN* #### Optional - GRID-MAPFILE-LOCAL #gmf_local /opt/edg/etc/grid-mapfile-local
December 17, 2015 Grid-mapfile generated …. #---The following Users are added on Wed Jun 25 12:30:18 EDT # "/O=doesciencegrid.org/OU=People/CN=Dantong Yu " dtyu "/O=doesciencegrid.org/OU=People/CN=Edward May " enm "/O=doesciencegrid.org/OU=People/CN=Jason A. Smith " smithj4 "/O=doesciencegrid.org/OU=People/CN=Patrick T. McGuigan " grid_a "/O=doesciencegrid.org/OU=People/CN=Richard Baker " rbaker "/O=doesciencegrid.org/OU=People/CN=Robert W. Gardner Jr " rwg #--Above Users added on Wed Jun 25 12:30:18 EDT #
December 17, 2015 Current Status The First Stage Development Is Completed Available to Be Downloaded at: Ready to Run, Detailed Man Page
December 17, 2015 Characteristics Tractable, Flexible Easy Installation and Management, after you do the RPM installation and setup your local configuration, the remain part will be automatically done by the software package Cron Mode to run the script to generate the new gridmap and add them into your original grid-mapfile The VO server could control who can access the VO server. The site has to register with the VO server. The registration process is automatically done by the rpm installation script. It mail out the site host certificate to the VO administrator. ( Dantong is volunteer to act as the administrator) Support GSI, every site which wants to download the VO information must has a host certificate, this host certificate is used to mutually authenticate with the VO server