One complication is that GRAM relies on a delegated proxy to perform service-side file stage in and out for the user's job and also make it available for the user's application in order to interact with other grid services. This delegation is required in the protocol between the gram client and gatekeeper. As a first step, you could simplify and focus on non-staging jobs, then you can avoid needing a delegated proxy on the service-side. You could modify the protocol between client and gatekeeper as needed. Then as a second step, you could reintroduce delegation using a separate delegation service. The gram client would be modified to create a delegated proxy and then the gram service would be modified to fetch the delegated proxy from this new delegation service.

-Stu

On Jul 9, 2009, at Jul 9, 9:13 AM, Nakkapt Boonsri wrote:

Regarding to running a job without proxy certificate,
I'm currently writing my bachelor thesis on authentication in Globus
Toolkit without proxy certicate, but with SAML assertion.
At this moment, an idea is to deactivate the proof of proxy certificate,
which depends on many components to the last step at GateKeeper.
Still many questions about possibility and its consequent.

-Nakkapat

Stuart Martin schrieb:
Right.  Submitting a job with either GRAM4 (WS GRAM) or GRAM5 (the
latest pre-ws based gram) requires security to be setup.

-Stu

On Jul 9, 2009, at Jul 9, 8:46 AM, Vanja Milosevski wrote:

Well the whole point of my question is because I don't want to get any
security overhead.

I did try the -nosec switch already but it still requires me to
initiate a proxy certificate before proceeding even though the
transmition goes through http and not through https. I assume some
sort of encryption is still taking place (maybe message-level?).

So ultimately, as I understand from the discussions above, it is not
possible (at least not straight forward) to submit a job without a
proxy certificate initialised?


-Vanja.






On Thu, Jul 9, 2009 at 7:53 AM, Luis<[email protected]> wrote:
Hello!

You only need to start the globus container with the option -nosec

For example:

$GLOBUS_LOCATION/sbin/globus-start-container-detached -p 8443 - nosec

Regards

El mié, 08-07-2009 a las 19:47 +0100, Vanja Milosevski escribió:
Hello,

Is it possible to submit a job to globus without setting up any
security (i.e. without proxy certificates)?


Thanks,
-Vanja





--
Nakkapat Boonsri
-
Südstr. 152
74072 Heilbronn
Germany
-
email : [email protected]
tel.: +49(0)176/6110-4890
-



Reply via email to