[GE users] SGE and Kerberos authentication for resources

weiser m.weiser at science-computing.de
Mon Aug 2 15:15:48 BST 2010


is anyone here running jobs with SGE that use resources authenticated via
Kerberos? We're thinking about migrating to NFSv4 with
Kerberos-Authentication and want to avoid re-inventing the wheel. Our
questions are (quite obviously ;):

- Can it be done?
- Has it been done?
- How to do it?

With NFSv4 we need a service ticket with the user's principal in it. So
the obvious approach it to use constrained delegation or protocol
transition. In the former case there'd need to be a way to attach an SGE
service ticket to the job with which SGE is then able to retrieve an NFS
service ticket in the user's name. In both cases SGE needs to be aware of
the need and able to retrieve the necessary tickets or delegate the task
to some hook or prologue script.

Any hints on how to approach this are highly appreciated,
______________________________creating IT solutions
Michael Weiser                science + computing ag
Martinstrasse 47-55, Haus G   Hagellocher Weg 73
40223 Duesseldorf             72070 Tuebingen, Germany
phone +49 211 302 708 32      www.science-computing.de

Vorstand/Board of Management:
Dr. Bernd Finkbeiner, Dr. Roland Niemeier, 
Dr. Arno Steitz, Dr. Ingrid Zech
Vorsitzender des Aufsichtsrats/
Chairman of the Supervisory Board:
Michel Lepert
Sitz/Registered Office: Tuebingen
Registergericht/Registration Court: Stuttgart
Registernummer/Commercial Register No.: HRB 382196


To unsubscribe from this discussion, e-mail: [users-unsubscribe at gridengine.sunsource.net].

More information about the gridengine-users mailing list