Better late than never ;-)

On Tue, 2016-04-12 at 10:56 +0200, Dennis van Dok wrote:
> > - configure the location where they're created
> Not sure if your request was meant as OR or AND; it's not hard to
> implement
> but the installation in /etc/grid-security/certificates is already a
> kludge.
The request was mostly an AND,... i.e. being able to selectively choose
WHICH certs are enabled (which is already possible) and also WHERE
they're created (i.e. whether it's /etc/grid-security or something
else).


> Not sure if I understand this correctly. Couldn't dcache be told to
> look in
> /etc/grid-security/certificates?
One can, in it does so even per default...

Being able to select WHERE certs go, could however be a first step to
decouple the trusted CAs for different "grid" services on the same
node.
E.g. having something like:
/etc/grid-security/certificates
where basically the whole IGTF bundle is found and which is used for
"normal" file transfers and having:
/etc/dcache/pki/certificates
where only a small subset e.g. GermanGrid is found, and which are used
to for client auth to the management web interface of dCache.


> I've not run into this sort of trouble at all; maybe it's worthwhile
> investigating
> why fetch-crl is not behaving as expected. Normally CRLs are fetched
> every 6 hours
> and they have a lifetime of a week, so complete failures due to CRL
> expiry are very
> rare.
Admittedly, I haven't seen this problem that often anymore (if at all).
Previously we had some less well performing CAs where the servers for
the CRLs were often dead.


> I *think* you can tell rsync to copy symlinks as files with -L.
One can, but then really all files get de-referenced, i.e. even the
<hash>.* symlinks... well probably not the end of the world either.



Cheers,
Chris.

Attachment: smime.p7s
Description: S/MIME cryptographic signature

Reply via email to