eulake technical coordination

Europe/Zurich

EULAKE coordination meeting 8th May 2018


Participants:

  • Crystal (Aarnet)
  • Andrew (NIKHEF)
  • Antonio (CNAF)
  • Enrico (CERN)


Coordination update:

  • Agreed to keep the meeting at 14:30 (better for colleagues in Australia)
  • Next meeting on 22nd May 2018


Round table:

  • NIKHEF:
    • A routing issue affecting only traffic over IPv6 in the OPN is inhibiting writes on filesystems at Nikhef
    • The issue is being followed up by network administrators at Nikhef/Sara
  • CNAF:
    • Looking forward to obtaining hardware resources for joining the Lake
    • ETA for hardware is unknown. Update in two weeks during the next meeting
  • CERN:
    • Certification of storage endpoints at Nikhef (firewall/routing) and Sara (dCache via NFS) ongoing
    • Goal for next 2 weeks is to establish access rights to all of us for eulake read/write tests: Via xrdcp Third Party Copy (TPC) (eulake.cern.ch) and gridftp (eulakeftp.cern.ch)
    • Test inner lake and outer lake transfers with the various available protocols: eoscp, xroot (xrdcp), gridftp, fts, etc.
    • Namespace latencies when doing ops from outside
    • Which authn/authz do we use? (i.e., begining with x509 would enable both protocols)

 

Access/authn/authz information coordination:

  • IP trusted ranged from the sites (TPC need to see all nodes in the lake)
  • Identity management: We start with x509, list of trusted DNs (then we fetch from CAs?)
  • Future of keytab base deployment
There are minutes attached to this event. Show them.
    • 14:30 14:35
      Coordination update 5m
    • 14:35 14:55
      Round table 20m

      CERN:
      - Certification of storage endpoints at Nikhef (Firewall/routing) and Sara (dCache) ongoing.
      - Goal for next 2 weeks is to establish access rights to all of us for eulake read/write tests: via xrdcp (eulake.cern.ch) and gridftp (eulakeftp.cern.ch).
      - Which auth/authz do we use? (ie. begining with x509 would enable both protocols)
      - Test inner lake and outer lake transfers with the various available protocols: eoscp, xroot (xrdcp), gridftp, fts, etc.
      - Namespace latencies when doing ops from outside.

      Access/auth/authz information coordination:
      - IP trusted ranged from the sites (TPC need to see all nodes in the lake)
      - Identity management: we start with x509, list of trusted DNs( then we fetch from CAs?)
      - Future of keytab base deployment

    • 14:55 15:00
      AOB 5m