middleware:Globus/extension/aba

From Dgiref
Jump to: navigation, search
Please open a NGI-DE ticket if you experience any Installation or Configuration problem.

Globus/42/authorization

Install

Note-icon.png
  
The original description can be downloaded from d-grid site.

To apply the Attribute-based authorization to the Globus Toolkit, the following components should be additionally installed:

  • Virtual Organization Membership Server (VOMS) Authorization Interceptors for the Globus Web-Services (GRAM and RFT. The service security should be configured accordingly).
  • Authorization callout C-API for the Globus GridFTP should be used for attributes mapping.
  • The aba-glite.tar.gz file regarding the attribute based authorization is supposed to be installed in /opt/glite

Configure

  1. setup the voms server certificates
  2. Configure the sudo for WSGRAM
  3. Mappings for VOMS FQAN
  4. ln -s /etc/grid-security/voms-attr-authz /etc/grid-security/voms-lcmaps-mapfile
  5. configure the /opt/glite/etc/vomses file (see the file /opt/glite/etc/vomses.template for instructions, for accessing the voms server)
Note-icon.png
  
To avoid the error message: "<username> is not in the grid mapfile", all local accounts, which attributes should be mapped, the similar empty record in the grid-mapfile should be assigned:
vi /etc/grid‐security/grid‐mapfile 
 "" uhdtsgm


Personal tools