Presentation is loading. Please wait.

Presentation is loading. Please wait.

Enabling Grids for E-sciencE INFSO-RI Virtual Ids and VOMS integration DPM supports virual Ids and VOMS : –each user/group is internally mapped.

Similar presentations


Presentation on theme: "Enabling Grids for E-sciencE INFSO-RI Virtual Ids and VOMS integration DPM supports virual Ids and VOMS : –each user/group is internally mapped."— Presentation transcript:

1 Enabling Grids for E-sciencE INFSO-RI-508833 1 Virtual Ids and VOMS integration DPM supports virual Ids and VOMS : –each user/group is internally mapped to a "virtual Id". –This allows Access Control Lists (ACLs) to be fully supported. DNs are mapped to virtual UIDs: the virtual uid is created on the fly the first time the system receives a request for this DN (no pool account) VOMS roles are mapped to virtual GIDs A given user may have one DN and several roles, so a given user may be mapped to one UID and several GIDs Currently only the primary role is used in DPM –Two different VOMS roles are mapped to two different gids –The same user might not be able to access his/her own file, depending on his/her VOMS credentials Support for normal proxies and VOMS proxies

2 Enabling Grids for E-sciencE INFSO-RI-508833 2 DPNS metadata and Virtual ids mapping tables –The mappings are stored in :  the Cns_userinfo table, for the users  the Cns_groupinfo table, for the groups –When the user issues a grid-proxy-init or voms-proxy-init without VOMS parameters, the /opt/lcg/etc/lcgdm-mapfile file is used to know to which group the user should be mapped. CNS_USERINFO USERID 18947 USERNAME /C=CH/O=CERN/OU=GRID/CN=Sophie Lemaitre 2268 CNS_GROUPINFO GID 2688 GROUPNAME dteam CNS_FILE_METADATA Fileid 246 Parent_fileid 245 Name file01.log Guid a8d6ac51-e4d4-4f3d-bfa6-755d7554544c Owner_uid 1250 Gid 1399 ACL … mysql> select * from Cns_groupinfo; +-------+------+--------+ | rowid | gid | groupname | +-------+------+--------+ | 1 | 2688 | dteam | | …. | 13 | 34003 | atlas/Role=production |.. | 25 | 34008 | atlas/Role=lcgadmin |

3 Enabling Grids for E-sciencE INFSO-RI-508833 3 User / group mapping No valid proxy –“No valid credential found” User DN –Added automatically to Cns_userinfo, if it doesn’t exist User group –grid-proxy-init or simple voms-proxy-init  Group taken from /opt/lcg/etc/lcgdm-mapfile –voms-proxy-init –voms myVO  Group taken from the VOMS role  Added automatically, if doesn’t exist "/C=CH/O=CERN/OU=GRID/CN=Simone Campana 7461 - ATLAS" atlas "/C=CH/O=CERN/OU=GRID/CN=Sophie Lemaitre 2268" dteam atlas atlas/Role=lcgadmin atlas/Role=production Cns_groupinfo


Download ppt "Enabling Grids for E-sciencE INFSO-RI Virtual Ids and VOMS integration DPM supports virual Ids and VOMS : –each user/group is internally mapped."

Similar presentations


Ads by Google