Better late than never ;-) On Tue, 2016-04-12 at 10:56 +0200, Dennis van Dok wrote: > > - configure the location where they're created > Not sure if your request was meant as OR or AND; it's not hard to > implement > but the installation in /etc/grid-security/certificates is already a > kludge. The request was mostly an AND,... i.e. being able to selectively choose WHICH certs are enabled (which is already possible) and also WHERE they're created (i.e. whether it's /etc/grid-security or something else).
> Not sure if I understand this correctly. Couldn't dcache be told to > look in > /etc/grid-security/certificates? One can, in it does so even per default... Being able to select WHERE certs go, could however be a first step to decouple the trusted CAs for different "grid" services on the same node. E.g. having something like: /etc/grid-security/certificates where basically the whole IGTF bundle is found and which is used for "normal" file transfers and having: /etc/dcache/pki/certificates where only a small subset e.g. GermanGrid is found, and which are used to for client auth to the management web interface of dCache. > I've not run into this sort of trouble at all; maybe it's worthwhile > investigating > why fetch-crl is not behaving as expected. Normally CRLs are fetched > every 6 hours > and they have a lifetime of a week, so complete failures due to CRL > expiry are very > rare. Admittedly, I haven't seen this problem that often anymore (if at all). Previously we had some less well performing CAs where the servers for the CRLs were often dead. > I *think* you can tell rsync to copy symlinks as files with -L. One can, but then really all files get de-referenced, i.e. even the <hash>.* symlinks... well probably not the end of the world either. Cheers, Chris.
smime.p7s
Description: S/MIME cryptographic signature

