Enable VO egrid with YAIM
The following steps are necessary to enable the VO egrid with YAIM
In the file defined in your site-info.def by the variabile USER_CONF check if the following entry is present:
60001:egrid001:60000:egrid:egrid:: 60002:egrid002:60000:egrid:egrid:: 60003:egrid003:60000:egrid:egrid:: 60004:egrid004:60000:egrid:egrid:: 60005:egrid005:60000:egrid:egrid:: 60006:egrid006:60000:egrid:egrid:: 60007:egrid007:60000:egrid:egrid:: 60008:egrid008:60000:egrid:egrid:: 60009:egrid009:60000:egrid:egrid:: 60010:egrid010:60000:egrid:egrid:: 60011:egrid011:60000:egrid:egrid:: 60012:egrid012:60000:egrid:egrid:: 60013:egrid013:60000:egrid:egrid:: 60014:egrid014:60000:egrid:egrid:: 60015:egrid015:60000:egrid:egrid:: 60016:egrid016:60000:egrid:egrid:: 60017:egrid017:60000:egrid:egrid:: 60018:egrid018:60000:egrid:egrid:: 60019:egrid019:60000:egrid:egrid:: 60020:egrid020:60000:egrid:egrid:: 60099:egridsgm:60000:egrid:egrid:sgm: 60100:egridadm:60000:egrid:egrid:adm:
In the group file defined in your site-info.def by the variable GROUS_CONF check if the following entry is present:
"/VO=egrid/GROUP=/egrid":::: "/VO=egrid/GROUP=/egrid/ROLE=lcgadmin":::sgm:
In your site-info.def
insert the following line:
VO_EGRID_VOMS_SERVERS="vomss://voms.cnaf.infn.it:8443/voms/egrid?/egrid" VO_EGRID_VOMSES="egrid voms.cnaf.infn.it 15014 /C=IT/O=INFN/OU=Host/L=CNAF/CN=voms.cnaf.infn.it egrid"
remove if present the following entry:
VO_EGRID_SGM= VO_EGRID_USER=
Add egrid in ALL_VOMS_VO
Run the YAIM function config_mkgridmap
/opt/glite/yaim/scripts/run_function site-info.def config_mkdgridmap
or if you use ig_yaim run instead
/opt/glite/yaim/scripts/ig_run_function site_info.def config_mkdgridmap
To verify if the configuration is correct run the following command
check /opt/edg/etc/lcmaps/groupmapfile:
# cat /opt/edg/etc/lcmaps/groupmapfile | grep egrid "/VO=egrid/GROUP=/egrid/ROLE=lcgadmin/Capability=NULL" egrid "/VO=egrid/GROUP=/egrid/ROLE=lcgadmin" egrid "/VO=egrid/GROUP=/egrid/Role=NULL/Capability=NULL" egrid "/VO=egrid/GROUP=/egrid" egrid
check /opt/edg/etc/lcmaps/gridmapfile:
#cat /opt/edg/etc/lcmaps/gridmapfile | grep egrid "/VO=egrid/GROUP=/egrid/ROLE=lcgadmin/Capability=NULL" egridsgm "/VO=egrid/GROUP=/egrid/ROLE=lcgadmin" egridsgm "/VO=egrid/GROUP=/egrid/Role=NULL/Capability=NULL" .egrid "/VO=egrid/GROUP=/egrid" .egrid
check /etc/grid-security/grid-mapfile:
# grep ".egrid" /etc/grid-security/grid-mapfile "/C=IT/O=INFN/OU=Personal Certificate/L=CNAF/CN=alessandro paolini/Email=alessandro.paolini@cnaf.infn.it" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=DS Firenze/CN=Christian T. Brownlees" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=DS Firenze/CN=Matteo Guastini" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=Fisica Roma La Sapienza/CN=Alessandra Tedeschi" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=ICTP/CN=Alessio Terpin" egridsgm "/C=IT/O=INFN/OU=Personal Certificate/L=ICTP/CN=Alvise Nobile" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=ICTP/CN=Angelo Leto" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=ICTP/CN=Antonio Messina" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=ICTP/CN=Clement Onime" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=ICTP/CN=Ezio Corso" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=ICTP/CN=Massimo Sponza" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=ICTP/CN=Riccardo Di Meo" egridsgm "/C=IT/O=INFN/OU=Personal Certificate/L=ICTP/CN=Riccardo Murri" egridsgm "/C=IT/O=INFN/OU=Personal Certificate/L=ICTP/CN=Stefano Cozzini" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=INFM Palermo/CN=Adam Ponzi" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=INFM Palermo/CN=Claudia Coronnello" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=INFM Palermo/CN=Fabrizio Lillo" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=INFM Palermo/CN=Michele Tumminello" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=INFM Palermo/CN=Rosario Nunzio Mantegna" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=INFM Palermo/CN=Salvatore Micciche" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=Padova/CN=Silvano Paoli" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=Roma 1/CN=Enzo Marinari" .egrid "/C=IT/O=INFN/OU=Personal Certificate/L=UnitsDipIngMecc/CN=Mattia Ciprian" .egrid
