Unsupported Pilot Service Certs [in progress]
- InCommon / Let’s Encrypt don’t support service certs
- Most pilots use service certs to auth with CEs, e.g:
- /DC=org/DC=opensciencegrid/O=Open Science Grid/OU=Services/CN=glideinwms/osg-flock.grid.iu.edu
- Brian L / Brian B considering implications of using plain host certs for pilots
- Problem - requires possibly disruptive changes to site HTCondor CE configs
- High Urgency - OSG flock pilot cert expires soonest 2019-04-11
- Brian B came up with possible workaround
- TODO - test workaround with a frontend using InCommon / Let’s Encrypt hostcert as pilot credential, perhaps the GLOW test frontend?
- Requires coordination with factory ops and software team