EMI 1 (Kebnekaise) - Update 7 (22.09.2011)

The Update contains:

  • minor releases of ARGUS, v. 1.4.0, UNICORE TSI & UNCIRE/X, v. 6.4.1
  • revision releases of CEMon, v. 1.13.2, gLExec-wn, v. 1.0.1, UNICORE client, v. 6.4.1

ARGUS v. 1.4.0 task #21931

What's New:

  • The Argus services have unbundled some of the required libraries. The VOMS API (vomsjapi.jar), the EMI Trustmanager (trustmanager.jar and trustmanager-axis.jar), and BouncyCastle (bcprov.jar) libraries are now installed separately, and used by the Argus services. Future update of these libraries will not require a repackaging of the Argus services.
  • The Argus services have a new production configuration for the log files:
    • daily log files rotating (midnight) or when the file size >= 100MB
    • rotated log files are gzipped
    • log files are keep for 90 days
  • The Argus services have now a memory limit set (PAP 256MB, PDP 256MB, PEP Server 128MB).
  • An old bug fix was not completely fixed. The timestamp of the lease files was not updated for the first mapping, but only for the successive mapping. This is now fixed https://savannah.cern.ch/bugs/?84846

Deployment Notes:

  • Applying the update will stop the Argus services (PAP, PDP and PEP Server).
  • You must re-configure the Argus services with YAIM. This automatically restart all the services.

Updated Artefacts

Binary
argus-pap-1.4.0-1.sl5.noarch.rpm
argus-pdp-1.4.0-1.sl5.noarch.rpm
argus-pdp-pep-common-1.2.2-1.sl5.noarch.rpm
argus-pep-api-java-2.0.2-1.sl5.noarch.rpm
argus-pep-common-2.1.1-1.sl5.noarch.rpm
argus-pep-server-1.4.0-1.sl5.noarch.rpm
yaim-argus_server-1.4.0-1.sl5.noarch.rpm
Binary tarball
argus-pap-1.4.0-1.tar.gz
argus-pdp-1.4.0-1.tar.gz
argus-pdp-pep-common-1.2.2-1.tar.gz
argus-pep-api-java-2.0.2-1.tar.gz
argus-pep-common-2.1.1-1.tar.gz
argus-pep-server-1.4.0-1.tar.gz
yaim-argus_server-1.4.0-1.tar.gz
Sources RPM
argus-pap-1.4.0-1.sl5.src.rpm
argus-pdp-1.4.0-1.sl5.src.rpm
argus-pdp-pep-common-1.2.2-1.sl5.src.rpm
argus-pep-api-java-2.0.2-1.sl5.src.rpm
argus-pep-common-2.1.1-1.sl5.src.rpm
argus-pep-server-1.4.0-1.sl5.src.rpm
yaim-argus_server-1.4.0-1.sl5.src.rpm
Sources tarball
argus-pap-1.4.0-1.src.tar.gz
argus-pdp-1.4.0-1.src.tar.gz
argus-pdp-pep-common-1.2.2-1.src.tar.gz
argus-pep-api-java-2.0.2-1.src.tar.gz
argus-pep-common-2.1.1-1.src.tar.gz
argus-pep-server-1.4.0-1.src.tar.gz
yaim-argus_server-1.4.0-1.src.tar.gz
Metapackages
emi-argus-1.4.0-1.tar.gz
emi-argus-1.4.0-1.sl5.src.rpm
emi-argus-1.4.0-1.src.tar.gz

CEMon v. 1.13.3 task #22331

What's new

This is an update of the CEMon consumer (client side) and of the configuration tool (yaim, server side). The update of the consumer addresses two bugs. In particular one (the printed peer address was not correct) is relevant for OSG. The update of the configuration tool addresses some issues with Glue 2 publication. This also allows the publication of version information

Deployment notes

  • YAIM (re)configuration is required after installation/update in the CREAM-CE
  • Since CEMon is deployed together with CREAM, please refer to the installation and configuration notes for the whole CREAM-CE

* YAIM reconfiguration is instead not needed in the UI

Updated Artefacts

Binary

glite-ce-monitor-client-api-c-1.13.2-2.sl5.x86_64.rpm
glite-ce-yaim-cream-ce-4.2.1-1.sl5.x86_64.rpm
Binary tarball
glite-ce-monitor-client-api-c-1.13.2-2.tar.gz
glite-ce-yaim-cream-ce-4.2.1-1.tar.gz
Sources RPM
glite-ce-monitor-client-api-c-1.13.2-2.sl5.src.rpm
glite-ce-yaim-cream-ce-4.2.1-1.sl5.src.rpm
Sources tarball
glite-ce-monitor-client-api-c-1.13.2-2.src.tar.gz
glite-ce-yaim-cream-ce-4.2.1-1.src.tar.gz

gLExec-wn v. 1.0.1 ttask #22464

What's new

  • This update of the gLExec workernode fixes a minor bug in the yaim configuration that would cause some variables to have the wrong (or no) default value.
  • The CREAM CE uses gLExec and LCMAPS to resolve a Unix account in one of its deployment options. The certificate chain will be checked by the lcmaps-plugins-verify-proxy component, launched by the gLExec/LCMAPS combination. The component triggers an X509_V_ERR_PROXY_PATH_LENGTH_EXCEEDED error code, even while the chain is fully valid. There are three important triggers required:
    1. The user is required to use a certificate issued from a CA certificate with a path length constraint set to 0 (=zero). This is the case for the Terena eScience Personal, Terena SSL and the FNAL CA.
    2. The job must flow through the CREAM CE frontend service, not directly to gLExec on the shell
    3. The proxy certificate chain must have at least two delegations, or more to trigger the error.

This fix will mitigate the problems in OpenSSL (or Globus OpenSSL) by retrying the Path Length checks for RFC5280 and RFC3820 though a new routine that double checks if the chain is really invalid according to the initially stated failure condition.

For a detailed background story: cream-did-it-using-bugs-in-path-length

Updated Artefacts

Binary
yaim-glexec-wn-2.0.3-5.sl5.noarch.rpm
lcmaps-plugins-verify-proxy-1.4.12-2.sl5.x86_64.rpm
Binary tarball
yaim-glexec-wn-2.0.3-5.tar.gz
lcmaps-plugins-verify-proxy-1.4.12-2.tar.gz
Sources RPM
yaim-glexec-wn-2.0.3-5.sl5.src.rpm
lcmaps-plugins-verify-proxy-1.4.12-2.sl5.src.rpm
Sources tarball
yaim-glexec-wn-2.0.3-5.src.tar.gz
lcmaps-plugins-verify-proxy-1.4.12-2.src.tar.gz

UNICORE Client v. 6.4.1 task #21933

What's new

UCC has been updated to the latest version 6.4.1 of the UNICORE libraries. There are the following improvements:

  • missing filetransfer parameters (e.g. client host for UFTP) are automatically set
  • the "append" option (-a) is now also available for "get-file"

Installation and configuration

Nothing special here.

Known issues

None.

Updated Artefacts

Binary
unicore-ucc-6.4.1-2.noarch.rpm
Binary tarball
ucc-6.4.1-p1-all.tar.gz

UNICORE TSI v. 6.4.1 task #21935

What's new

There are the following fixes:

  • Submit.pm: handle TSI_STDERR and TSI_STDOUT sent from XNJS for redirecting output and error
  • fix: Torque: GetStatusListing.pm now handles non-word characters in queue name
  • updated the manual

And two enhancements

  • tsi_ls is returning more information on files: owner, owning group, full UNIX permissions
  • new module ACL.pm for getting/setting filesystem ACL

Upgrade/deployment notes

  • No special notes on clean deployment.
  • Upgrading: the rpm does yet fully support upgrading. We recommend making a backup of the /etc/unicore/tsi/* files, and
installing from scratch, i.e. erasing unicore-tsi first and then re-installing.

Known Issues

None.

Updated Artefacts

Binary
unicore-tsi-6.4.1-1.noarch.rpm
Binary tarball
unicore-tsi-6.4.1-1.tar.gz
Sources tarball
unicore-tsi-6.4.1-1.src.tar.gz

UNICORE/X v. 6.4.1 task #21934

What's new:

  • This is a minor update to the 6.4.0 release, fixing a few bugs. A minor new feature in this release is ACL support on Linux (provided the file system supports it).

Installation and configuration:

  • After updating the libraries, the UNICORE/X server must be restarted.

Known Issues

  • none

Updated Artefacts

Binary
unicore-unicorex-6.4.1-0.noarch.rpm

-- DoinaCristinaAiftimiei - 19-Sep-2011

Edit | Attach | Watch | Print version | History: r4 < r3 < r2 < r1 | Backlinks | Raw View | WYSIWYG | More topic actions
Topic revision: r4 - 2011-09-22 - DoinaCristinaAiftimiei
 
    • Cern Search Icon Cern Search
    • TWiki Search Icon TWiki Search
    • Google Search Icon Google Search

    EMI All webs login

This site is powered by the TWiki collaboration platform Powered by PerlCopyright & 2008-2020 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback