
D2.1.4 IST-033576
pam_xos.conf configuration file: The certificate verification chain for pam_-
xos.so PAM plugin is configured in file /etc/xos/pam_xos.conf, item
VOCAPublicKeyfile. By default, this item defines /etc/xos/certifica-
tes/ as the CA public key directory.
root: cat /etc/xos/pam_xos.conf
...
#VOACConf /etc/xos/mapdata/quota.conf
VOCAPublicKeyfile /etc/xos/certificates/
#NodePrivateKeyfile /tmp/userkey.pem
root:
Starting amsd: The amsd service of XtreemOS is in charge of managing the
translation between local numeric user/group IDs and global identities.
root: ./xtreemos-nss-pam-0.04/src/test/xos_amsd -d
xos_amsd starting ... OK
root:
The xos_amsd service must be run as root in this prototype.
3.4.2 Successfull run of pam_app_conv
Once everything is configured correctly, running the pam_app_conv test pro-
gram as root should produce the following result:
root: xtreemos-nss-pam-0.04/src/test/pam_app_conv
-pem ~yjegou/.xos/firstproxy.pem
vo = [xtreemos], role = [admin]
pam_xos.c:96: PAM:xos_paraparse: Debug mode
pam_xos.c:119: PAM: configure file is: /etc/xos/pam_xos.conf
=============== PAM configure data ===============
work mode: Use external AMS
-- External AMS server: localhost
-- External AMS port: 8000
VO CA dir: /home/yjegou/security/XtreemOS-ca
==================================================
pam_xos.c:329: PAM:current uid is: 0
Verifying certificates ... OK
pam_xos.c:382: PAM:DN = [/C=FR/ST=Bretagne/L=Rennes/O=INRIA/OU=I
RISA/CN=Yvon Jegou/emailAddress=Yvon.Jegou-at-irisa.fr/CN=28216/
CN=10098738018704381327]
pam_xos.c:397: PAM: Get Attrs = [/VO=xtreemos/ROLE=admin]
pam_xos.c:96: PAM:xos_paraparse: Debug mode
21/49 XtreemOS–Integrated Project
Comentários a estes Manuais