next up previous contents
Next: Bibliography Up: A local Globus install Previous: Local modifications   Contents

Administrative environment

There should be two accounts:

gridadm
A Globus/Grid administation account. This pseudo-user owns the files related to the globus install and deployment. It is preferably part of the ices group, so it can use the installed base at /global/ices. It should not run any globus services.
griduser
A (temporary) account for testing grid services. It should preferably be in its own group, not be able to write anywhere accept for its home directory (and /tmp), akin to user `nobody'.

The gatekeeper should run as root, either from inetd or as a stand-alone daemon. On selected hosts, Globus should be started by default from the system startup scripts. The `services' may include reference to the globus gatekeeper on port 2119. These actions require a certain amount of trust regarding the Globus admin person.



A number of rulesets should preperably be added to the hef-router configuration to secure the Globus deployment:

These rules might later be relaxed slightly to allow access from selected WCW sites participating in the Virtual Lab or from participating DutchGrid institutes like KNMI/SARA. Persons submitting jobs to the Grid via Globus should have a local account.


next up previous contents
Next: Bibliography Up: A local Globus install Previous: Local modifications   Contents
David Groep
2001-01-25