So globusrun-ws will behave inconsistently from other GSI clients in the case of DNS round-robin and DNS aliases?

http://bugzilla.globus.org/bugzilla/show_bug.cgi?id=318

Joseph Bester wrote:
In 4.2, globusrun-ws doesn't rely on DNS lookups for determining the hostname to use for authorization decisions in the mutual authentication from client to service and from service to notification consumer. Instead, the host information provided on the command-line (or in the EPR) is used.

Since the epr contains only an ip address (and not the hostname) globusrun-ws is failing to authenticate the connection because it doesn't know what name should be used. I'll file a bug to add DNS resolution in the case where the address is an IPv4 or IPV6 address and not a host name to catch this issue, but in general, using logicalHost is a good option in the meantime.

Joe

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to