Hi Simon, Thanks! I am quite happy with a different username attached to my certificate. The next issue I am trying to understand / sort out is how to use this certificate to access data on ECHO. I am fairly certain that I am going to end up in a fairly detailed mess, but that is for another day I suppose. Regards, Raja. On 25/10/19 11:58, Simon Fayer wrote:
Hi Raja,
On Fri, Oct 25, 2019 at 09:51:07AM +0100, Raja Nandakumar wrote:
Due to a limitation of ECHO storage at RAL, I am not able to use my normal DN for accessing DUNE data (while I suppose I will need it for accessing it at other sites).
Just when I thought we'd finally got past the point where users had to have multiple-DNs to access storage as different VOs!
For this, is it possible add a second DN (below) for me so that I can submit DUNE jobs to DIRAC with the DN below? /DC=org/DC=cilogon/C=US/O=Fermi National Accelerator Laboratory/OU=People/CN=Raja Nandakumar/CN=UID:nraja
I did some minimal tests and multiple-DNs in DIRAC appears to work, but I'm not convinced that DN isn't used as a primary key somewhere. Our auto-user-configuration agent certainly has limitations: - The "listMembers" SOAP call we do against the VOMS server only returns the primary DN. - We currently update users with their primary DN, which would overwrite any manually added multiple-DNs.
Could you live with having that DN registered as a completely different user to your primary DN in DIRAC? If so, I could probably just manually register it for you in the dune_user group for testing.
Regards, Simon