krbrefresh.sh failure on fifebatch1
Any idea why the krbrefresh.sh script produces the below error when it sees this job:
[rexbatch@fifebatch1 ~]$ condor_q -constraint 'Owner == "boyd"' -format "%s\n" accountinggroup
Note the error below has "AcctGroup='boone'". What happened to the "u".
-------- Original Message --------
Subject: Cron <rexbatch@fifebatch1> /opt/jobsub/server/admin/krbrefresh.sh --refresh-proxies 10800 > /tmp/refresh-proxies.out
Date: Wed, 14 May 2014 14:22:05 -0500
From: Cron Daemon <firstname.lastname@example.org>
Traceback (most recent call last):
File "/opt/jobsub/server/webapp/auth.py", line 316, in <module>
File "/opt/jobsub/server/webapp/auth.py", line 242, in refresh_proxies
File "/opt/jobsub/server/webapp/auth.py", line 205, in authorize
raise AuthorizationError(dn, acctgroup)
main.AuthorizationError: Error authorizing DN='/DC=gov/DC=fnal/O=Fermilab/OU=Robots/CN=fifegrid/CN=batch/CN=Joe B. Boyd/CN=UID:boyd' for AcctGroup='boone'
#1 Updated by Dennis Box about 6 years ago
- Status changed from New to Assigned
- Target version set to v0.3
- % Done changed from 0 to 80
I can reproduce the problem and can fix it but don't understand why its a problem in the first place. In the python code, line 240 of /opt/jobsub/server/webapp/auth.py there is this instruction:
grp is originally pulled from condor classads and is either group_minos, group_uboone, group_nova, etc. This line is supposed to transform grp into minos, uboone, nova etc. The problem is it transforms group_uboone to boone. I can reproduce it in a python window so there is something going on with the string strip function I do not understand. Note that
works fine and I am replacing this line of code in v0.3.0 but I wish I understood what was happening.