[GE users] Another csp problem

Andre Alefeld Andre.Alefeld at Sun.COM
Tue Nov 2 10:44:10 GMT 2004


Hi,

are the times on th two machines in sync ?
You can have a look at the certs with:

$SGE_ROOT/util/sgeCA/sge_ca -print /var/sgeCA/sge_commd/default/<user>/cert.pem

check if they are correct.
Another reason could be certs under $USER/.sge/...


Andre


Co Thai Ngo wrote:
> Hi, 
>  
> I've done the following steps to install master and execution nodes.  
>  
> On the master node: 
>  
> ********* 
> master# install_qmaster -csp  
> tar cvpf sge.tar /var/sgeCA/sge_commd/default 
> ********** 
>  
> Both master and execution node have openssl 0.9.7b installed. 
>  
> ******* 
> master# openssl version 
> OpenSSL 0.9.7b 10 Apr 2003 
>  
> node2# openssl version 
> OpenSSL 0.9.7b 10 Apr 2003 
> ******** 
>  
> On the execution node,  
>  
> ************* 
> node2# tar xvpf sge.tar 
> node2# ls -lR /var/sgeCA/sge_commd 
> total 1 
> drwxr-xr-x  4 sgeadmin  wheel  512 Nov  1 10:30 default 
>  
> /var/sgeCA/sge_commd/default: 
> total 2 
> drwx------  2 sgeadmin  wheel  512 Nov  1 10:30 private 
> drwxr-xr-x  4 sgeadmin  wheel  512 Nov  1 10:30 userkeys 
>  
> /var/sgeCA/sge_commd/default/private: 
> total 4 
> -rw-------  1 sgeadmin  wheel   887 Nov  1 10:30 cakey.pem 
> -rw-------  1 sgeadmin  wheel   887 Nov  1 10:30 key.pem 
> -rw-------  1 sgeadmin  wheel  1024 Nov  1 10:30 rand.seed 
> -rw-------  1 sgeadmin  wheel   753 Nov  1 10:30 req.pem 
>  
> /var/sgeCA/sge_commd/default/userkeys: 
> total 2 
> dr-x------  2 root      wheel  512 Nov  1 10:30 root 
> dr-x------  2 sgeadmin  wheel  512 Nov  1 10:30 sgeadmin 
>  
> /var/sgeCA/sge_commd/default/userkeys/root: 
> total 7 
> -r--------  1 root  wheel  3663 Nov  1 10:30 cert.pem 
> -r--------  1 root  wheel   887 Nov  1 10:30 key.pem 
> -r--------  1 root  wheel  1024 Nov  1 10:30 rand.seed 
> -r--------  1 root  wheel   761 Nov  1 10:30 req.pem 
>  
> /var/sgeCA/sge_commd/default/userkeys/sgeadmin: 
> total 7 
> -r--------  1 sgeadmin  wheel  3669 Nov  1 10:30 cert.pem 
> -r--------  1 sgeadmin  wheel   887 Nov  1 10:30 key.pem 
> -r--------  1 sgeadmin  wheel  1024 Nov  1 10:30 rand.seed 
> -r--------  1 sgeadmin  wheel   761 Nov  1 10:30 req.pem 
> *********** 
>  
> I got the following error when I run install_execd -csp on the execution node.    
>  
> ************* 
> # Version: 5.3 
> # 
>  
> Grid Engine group id range 
> -------------------------- 
>  
> When jobs are started under the control of Grid Engine an additional group id 
>  
> Checking hostname resolving 
> --------------------------- 
> error: certificate not yet valid 
> error: failed verify own certificate 
> critical error: failed initialize security data 
>  
> Command failed: bin/nbsd-i386/qconf -sh 
>  
> Probably a permission problem. Please check file access permissions. 
> Check root read/write permission. Check if SGE daemons are running. 
>  
> error: certificate not yet valid 
> error: failed verify own certificate 
> critical error: failed initialize security data 
>  
> Command failed: bin/nbsd-i386/qconf -sconf global 
>  
> Probably a permission problem. Please check file access permissions. 
> Check root read/write permission. Check if SGE daemons are running. 
>  
>  
> This host has the local hostname >node2.cluster<. 
>  
> This host is unknown on the qmaster host. 
>  
> Please make sure that you added this host as administrative host! 
> If you did not, please add this host now with the command 
>  
>    # qconf -ah HOSTNAME 
>  
> on your qmaster host. 
>  
> Check again (y/n) [y] >> 
>  
> ************************ 
>  
> It's definitely certificate problem because when I run install without csp 
> option, I got no error. The node2 is added as an administrative host. And I got 
> the error when I ran qconf from the node2. 
>  
> ***** 
> node2# bin/nbsd-i386/qconf 
> error: certificate not yet valid 
> error: failed verify own certificate 
> critical error: failed initialize security data 
> ****** 
>  
> Any help to resolve this problem is highly appreciated. 
>  
> --  
> Co Thai Ngo  
> Dept. of Biology   
> New Mexico State University   
> 
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: users-unsubscribe at gridengine.sunsource.net
> For additional commands, e-mail: users-help at gridengine.sunsource.net
> 

-- 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Andre Alefeld                Phone: ++49 (0)941 3075-255
Software Engineering         Fax:   ++49 (0)941 3075-222
Sun Microsystems GmbH
Dr.-Leo-Ritter-Str. 7	     mailto: andre.alefeld at sun.com
D-93049 Regensburg           http://www.sun.com/grid


---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe at gridengine.sunsource.net
For additional commands, e-mail: users-help at gridengine.sunsource.net




More information about the gridengine-users mailing list