########################################################### xrootd.fslib -2 libXrdEosMgm.so xrootd.seclib libXrdSec.so xrootd.async off nosf xrootd.chksum adler32 ########################################################### xrd.sched mint 8 maxt 256 idle 64 ########################################################### all.export / nolock all.role manager all.sitename cern_tape_archive_ral_antares-dev ########################################################### oss.fdlimit 16384 32768 ########################################################### # UNIX authentication sec.protocol unix # SSS authentication sec.protocol sss -c /etc/eos.keytab -s /etc/eos.keytab # KRB authentication #sec.protocol krb5 -exptkn:/var/eos/auth/krb5# host/@CERN.CH #sec.protocol krb5 host/@CERN.CH # GSI authentication # # Start with gridmap auth, if the DN is present, use that mapping # the mapping in the gridmap file will then require a matching 'gsi' vid mapping in EOS. e.g. # # > cat grid-mapfile # "/C=UK/O=eScience/OU=CLRC/L=RAL/CN=tom byrne" dteamprod # > eos vid ls # gsi:"dteamprod":gid => dteam # gsi:"dteamprod":uid => dteam001 # # Would map that DN to dteam001:dteam # # # If gmapfile lookup fails, voms extration will occur and voms mapping will be attempted. # As client for a delegated proxy cert --> -dlgpxy:request (same as -dlgpxy:1) # Makes the certificate available via the XrdSecEntity.creds --> -exppxy:=creds # Require an up-to-date CRL for each CA --> -crl:require (same as -crl:3) sec.protparm gsi -vomsfun:libXrdSecgsiVOMS.so -vomsfunparms:certfmt=pem|grpopt=usefirst|dbg sec.protocol gsi -dlgpxy:request -exppxy:=creds -crl:require -cert:/etc/grid-security/xrootd/hostcert.pem -key:/etc/grid-security/xrootd/hostkey.pem -gridmap:/etc/grid-security/grid-mapfile -gmapopt:1 -d:1 ########################################################### # the unix binding for '*' can only be used if the unix auth is not enabled in EOS # enabling unix auth in EOS allows for direct mapping from client id to EOS vid, which is not secure # In our case all clients using unix auth will be mapped onto the alicesgm user, which only has # permissions to access parts of the namespace , controlled by the alice auth library (libXrdAliceTokenAcc.so) # sec.protocol ztn sec.protbind * only ztn gsi unix sec.protbind antares-dev-tpc*.scd.rl.ac.uk only gsi sec.protbind *.scd.rl.ac.uk sss sec.protbind *.fds.rl.ac.uk sss sec.protbind localhost.localdomain sss unix sec.protbind localhost sss unix ########################################################### mgmofs.fs / mgmofs.targetport 1095 mgmofs.authlib /usr/lib64/libXrdAliceTokenAcc.so mgmofs.authorize 1 mgmofs.macaroonslib libXrdMacaroons.so libXrdAccSciTokens.so alicetokenacc.noauthzhost localhost alicetokenacc.noauthzhost localhost.localdomain ########################################################### #mgmofs.trace all debug # this URL can be overwritten by EOS_BROKER_URL defined in /etc/sysconfig/eos xrootd.tls capable all http.header2cgi Authorization authz xrd.tls /etc/grid-security/daemon/hostcert.pem /etc/grid-security/daemon/hostkey.pem xrd.tlsca certdir /etc/grid-security/certificates/ #mgmofs.broker root://localhost:1097//eos/ #mgmofs.broker root://host-172-16-112-243:1097//eos/ # this name can be overwritten by EOS_INSTANCE_NAME defined in /etc/sysconfig/eos mgmofs.instance eosantaresdev # configuration, namespace , transfer and authentication export directory mgmofs.configdir /var/eos/config mgmofs.metalog /var/eos/md mgmofs.txdir /var/eos/tx mgmofs.authdir /var/eos/auth mgmofs.archivedir /var/eos/archive # report store path mgmofs.reportstorepath /var/eos/report # this defines the default config to load mgmofs.autoloadconfig default #------------------------------------------------------------------------------- # Config Engine Configuration #------------------------------------------------------------------------------- mgmofs.cfgtype quarkdb # this has to be defined if we have a failover configuration via alias - can be overwritten by EOS_MGM_ALIAS in /etc/sysconfig/eos #mgmofs.alias eosdev.cern.ch #------------------------------------------------------------------------------- # Configuration for the authentication plugin EosAuth #------------------------------------------------------------------------------- # Set the number of authentication worker threads running on the MGM #mgmofs.auththreads 10 # Set the front end port number for incoming authentication requests #mgmofs.authport 15555 ########################################################### # Set the FST gateway host and port #mgmofs.fstgw someproxy.cern.ch:3001 #------------------------------------------------------------------------------- # Configuration for the authentication plugin EosAuth #------------------------------------------------------------------------------- # Set the number of authentication worker threads running on the MGM #mgmofs.auththreads 10 # Set the front end port number for incoming authentication requests #mgmofs.authport 15555 #------------------------------------------------------------------------------- # Set the namespace plugin implementation #------------------------------------------------------------------------------- #mgmofs.nslib /usr/lib64/libEosNsInMemory.so mgmofs.nslib libEosNsQuarkdb.so # Quarkdb custer configuration used for the namespace mgmofs.qdbcluster antares-eos14.scd.rl.ac.uk:9999 mgmofs.qdbpassword_file /etc/qdb_pass xrd.network keepalive ofs.tpc redirect delegated antares-dev-tpc01.scd.rl.ac.uk:1094 # HTTP with VOMS extraction works only with XRootD 5 !! # if exec xrootd xrd.protocol XrdHttp:9000 libXrdHttp.so http.cadir /etc/grid-security/certificates/ http.cert /etc/grid-security/xrootd/hostcert.pem http.key /etc/grid-security/xrootd/hostkey.pem http.gridmap /etc/grid-security/http-grid-mapfile http.trace all http.exthandler xrdtpc libXrdHttpTPC.so http.exthandler EosMgmHttp libEosMgmHttp.so eos::mgm::http::redirect-to-https=0 mgmofs.macaroonslib libXrdMacaroons.so macaroons.secretkey /etc/xrootd/macaroon-secret macaroons.trace all fi scitokens.trace all #------------------------------------------------------------------------------- # Configuration for the MGM workflow engine #------------------------------------------------------------------------------- # The SSI protocol buffer endpoint for notification messages from "proto" workflow actions mgmofs.protowfendpoint cta-front07.scd.rl.ac.uk:10955 mgmofs.protowfresource /ctafrontend #------------------------------------------------------------------------------- # Confguration parameters for tape #------------------------------------------------------------------------------- mgmofs.tapeenabled true mgmofs.prepare.dest.space retrieve #------------------------------------------------------------------------------- # Confguration parameters for HTTP Tape REST API #------------------------------------------------------------------------------- taperestapi.sitename ral-cta-antares-dev #------------------------------------------------------------------------------- # Configuration for the tape aware garbage collector #------------------------------------------------------------------------------- # EOS spaces for which the tape aware garbage collector should be enabled mgmofs.tgc.enablespace default retrieve