Hi, First you should have a certificate for the container and for host ...see the documentation for globus certificates ( http://www.globus.org/toolkit/docs/4.0/admin/docbook/ch06.html ) .. this should be in /etc/grid-security : hostcert, hostkey, containercert, containerkey (with the extension .pem) ... verify that you followed the instructions correctly ... second ... you don't need a certificate for the globus user .... instead you need a certificate for other users ....
Regards, Stefan Mosoi On Tue, Sep 15, 2009 at 10:41 AM, Prashanth Chengi <[email protected] > wrote: > Simar, I think you are doing it wrong. > You don't need to have a user certificate to start the globus container and > secondly, why are you starting the container as globus user? Globus user > itself should not have any certificate. Which version of Globus Toolkit are > you using? Have you entered the sudo lines for globus user in /etc/sudoers? > > Regards, > Prashanth Chengi > National PARAM SuperComputing Facility > System Administration and Networking Group > C-DAC Pune > Ext-183 > Mob: 09766044870 > > -- > I don't know about angels, > But it's fear that gives men wings! > -Max Payne > > > On Tue, 15 Sep 2009, simar gill wrote: > > Hi All >> I have configured proxy certificates after signing usercerts which are >> stored in $HOME/.globus/ with userkey.pem. Now I am going to start >> container but the problem occur.various output are shown as follow: >> >> >> >> >> glo...@simar-laptop:~$ $GLOBUS_LOCATION/bin/grid-proxy-init >> Your identity: /O=Grid/OU=GlobusTest/OU=simpleCA-simar-laptop/CN=root >> Enter GRID pass phrase for this identity: >> Creating proxy >> .......................................................................... >> Done >> Your proxy is valid until: Tue Sep 15 22:20:21 2009 >> >> glo...@simar-laptop:~$ $GLOBUS_LOCATION/bin/grid-proxy-info >> subject : >> /O=Grid/OU=GlobusTest/OU=simpleCA-simar-laptop/CN=root/CN=210530596 >> issuer : /O=Grid/OU=GlobusTest/OU=simpleCA-simar-laptop/CN=root >> identity : /O=Grid/OU=GlobusTest/OU=simpleCA-simar-laptop/CN=root >> type : RFC 3820 compliant impersonation proxy >> strength : 512 bits >> path : /tmp/x509up_u1001 >> timeleft : 11:59:49 >> >> >> glo...@simar-laptop:~$ $GLOBUS_LOCATION/bin/globus-start-container >> >> Starting SOAP server at https://127.0.1.1:8443/wsrf/services/ >> 2009-09-15T10:22:48.347+05:30 ERROR container.GSIServiceThread >> [ServiceThread-56,process:142] [JWSCORE-192] Error processing >> requestConnection reset by peer >> [JWSCORE-115] Failed to obtain a list of services from >> 'https://127.0.1.1:8443/wsrf/services/ContainerRegistryService' >> service: ; nested exception is: >> org.globus.common.ChainedIOException: Authentication failed [Caused >> by: Failure unspecified at GSS-API level [Caused by: Bad certificate >> (The signature of >> 'O=Grid,OU=GlobusTest,OU=simpleCA-simar-laptop,CN=host/simar-laptop' >> certificate does not match its issuer)]] >> 2009-09-15T10:22:48.351+05:30 INFO >> container.ServiceContainerCollection [Thread-58,performShutdown:86] >> Container shutting down... >> glo...@simar-laptop:~$ >> >> >> Tell me how I resolve this issue. >> Thanks >> Regards >> Simar Virk >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> >>
