<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-GB">
	<id>https://t2bwiki.iihe.ac.be/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Shkelzen+Rugovac</id>
	<title>T2B Wiki - User contributions [en-gb]</title>
	<link rel="self" type="application/atom+xml" href="https://t2bwiki.iihe.ac.be/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Shkelzen+Rugovac"/>
	<link rel="alternate" type="text/html" href="https://t2bwiki.iihe.ac.be/Special:Contributions/Shkelzen_Rugovac"/>
	<updated>2026-04-20T11:13:55Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.5</generator>
	<entry>
		<id>https://t2bwiki.iihe.ac.be/index.php?title=Monitoring&amp;diff=671</id>
		<title>Monitoring</title>
		<link rel="alternate" type="text/html" href="https://t2bwiki.iihe.ac.be/index.php?title=Monitoring&amp;diff=671"/>
		<updated>2016-05-06T10:10:02Z</updated>

		<summary type="html">&lt;p&gt;Shkelzen Rugovac: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|  &#039;&#039;&#039;Nagios old style&#039;&#039;&#039;&lt;br /&gt;
|  &#039;&#039;&#039;Nagios Check_mk style&#039;&#039;&#039;&lt;br /&gt;
|  &#039;&#039;&#039;Nagios History&#039;&#039;&#039;&lt;br /&gt;
|  &#039;&#039;&#039;JSON&#039;&#039;&#039;  &lt;br /&gt;
|  &#039;&#039;&#039;Python&#039;&#039;&#039; &lt;br /&gt;
|-&lt;br /&gt;
|  [[https://etf-cms-prod.cern.ch/etf/nagios/cgi-bin/status.cgi?host=cream02.iihe.ac.be][cream02]]&lt;br /&gt;
|  [[https://etf-cms-prod.cern.ch/etf/check_mk/view.py?view_name=host&amp;amp;host=cream02.iihe.ac.be][cream02]]  &lt;br /&gt;
|  [[https://etf-cms-prod.cern.ch/etf/nagios/cgi-bin/notifications.cgi?host=cream02.iihe.ac.be][cream02]]  &lt;br /&gt;
|  [[https://etf-cms-prod.cern.ch/etf/check_mk/view.py?view_name=host&amp;amp;host=cream02.iihe.ac.be&amp;amp;output_format=json][cream02]]  &lt;br /&gt;
|  [[https://etf-cms-prod.cern.ch/etf/check_mk/view.py?view_name=host&amp;amp;host=cream02.iihe.ac.be&amp;amp;output_format=python][cream02]]   &lt;br /&gt;
|-&lt;br /&gt;
|  [[https://etf-cms-prod.cern.ch/etf/nagios/cgi-bin/status.cgi?host=maite.iihe.ac.be][maite]]  &lt;br /&gt;
|  [[https://etf-cms-prod.cern.ch/etf/check_mk/view.py?view_name=host&amp;amp;host=maite.iihe.ac.be][maite]] &lt;br /&gt;
|  [[https://etf-cms-prod.cern.ch/etf/nagios/cgi-bin/notifications.cgi?host=maite.iihe.ac.be][maite]]  &lt;br /&gt;
|  [[https://etf-cms-prod.cern.ch/etf/check_mk/view.py?view_name=host&amp;amp;host=maite.iihe.ac.be&amp;amp;output_format=json][maite]]  &lt;br /&gt;
|  [[https://etf-cms-prod.cern.ch/etf/check_mk/view.py?view_name=host&amp;amp;host=maite.iihe.ac.be&amp;amp;output_format=python][maite]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Links:&lt;br /&gt;
&lt;br /&gt;
*VUB-ULB GRID:&lt;br /&gt;
**Ganglia http://mon.iihe.ac.be/ganglia&lt;br /&gt;
&lt;br /&gt;
*BEgrid:&lt;br /&gt;
**Ganglia https://ganglia.begrid.be/ganglia/&lt;br /&gt;
**GridIce https://gridice.begrid.be/gridice&lt;br /&gt;
&lt;br /&gt;
*LCG&lt;br /&gt;
**GocDB/Gstat http://goc.grid.sinica.edu.tw/gstat/&lt;br /&gt;
**GridIce http://gridice2.cnaf.infn.it:50080/gridice/site/site.php&lt;br /&gt;
**Admin SFTs https://monitoring.egee.man.poznan.pl/admin2&lt;br /&gt;
**GGUS Ticket Service https://gus.fzk.de/pages/home.php&lt;br /&gt;
**Accounting Info http://www2.egee.cesga.es/gridsite/accounting/CESGA/tree_egee.php?Path=1.7&lt;br /&gt;
**Availabilty/Reliabilty http://gridview.cern.ch/GRIDVIEW/same_index.php&lt;br /&gt;
**Modded version (only displays UCL and ULB-VUB): http://mon.iihe.ac.be/modded_gridview/same_index.php&lt;br /&gt;
**Basic plots&lt;br /&gt;
***Select &amp;lt;tt&amp;gt;Tier-2 Site Availability&amp;lt;/tt&amp;gt;&lt;br /&gt;
***Select both sites&lt;br /&gt;
***Select eg daily plots for one month&lt;br /&gt;
&lt;br /&gt;
*Belnet Network Monitor http://monitor.belnet.be/graph/grapherrd.php: (This page only works from whitin BELNET client network.)&lt;br /&gt;
**the Inbound/Outbound are from BELNET view (ie Outbound BELNET = Incoming university traffic)&lt;br /&gt;
**the &amp;quot;Free traffic&amp;quot; is Research traffic, the red line is a limit for commercial traffic. &lt;br /&gt;
**UCL (whole campus) http://monitor.belnet.be/graph/grapherrd.php?page=lln.cfg&amp;amp;target=ucl&lt;br /&gt;
**ULB-VUB (whole campus) http://monitor.belnet.be/graph/grapherrd.php?page=brussels.cfg&amp;amp;target=ulb-vub&lt;br /&gt;
&lt;br /&gt;
*CMS&lt;br /&gt;
**Dashboard http://arda-dashboard.cern.ch/cms/&lt;br /&gt;
**Monalisa http://monalisa.cacr.caltech.edu:9090/&lt;br /&gt;
**CRAB http://cmsgridweb.pg.infn.it/crab/crabmon.php&lt;br /&gt;
**Phedex Heartbeat http://cmsdoc.cern.ch/cms/aprom/TransferHeartbeat/browser&lt;br /&gt;
**Phedex on Dashboard http://pcardabg.cern.ch:8080/dashboard/phedex/&lt;br /&gt;
**Installed software https://twiki.cern.ch/twiki/bin/view/CMS/CMSSWInstStatus&lt;br /&gt;
**SC4&lt;br /&gt;
**SC4 Site Status https://twiki.cern.ch/twiki/bin/view/CMS/SWIntSC4SiteStatus&lt;br /&gt;
**CSA06&lt;br /&gt;
**Wiki: https://uimon.cern.ch/twiki/bin/view/CMS/CSA06&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{TracNotice|{{PAGENAME}}}}&lt;/div&gt;</summary>
		<author><name>Shkelzen Rugovac</name></author>
	</entry>
	<entry>
		<id>https://t2bwiki.iihe.ac.be/index.php?title=Network_bond_and_tag&amp;diff=670</id>
		<title>Network bond and tag</title>
		<link rel="alternate" type="text/html" href="https://t2bwiki.iihe.ac.be/index.php?title=Network_bond_and_tag&amp;diff=670"/>
		<updated>2016-04-21T12:46:59Z</updated>

		<summary type="html">&lt;p&gt;Shkelzen Rugovac: /* On the switch */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== On the host ===&lt;br /&gt;
&lt;br /&gt;
In &#039;&#039;&#039;/etc/sysconfig/network-scripts&#039;&#039;&#039;:&lt;br /&gt;
:* ifcfg-bond0&lt;br /&gt;
&amp;lt;pre&amp;gt;DEVICE=&amp;quot;bond0&amp;quot;&lt;br /&gt;
BOOTPROTO=none&lt;br /&gt;
IPADDR=192.168.10.135&lt;br /&gt;
BROADCAST=192.168.255.255&lt;br /&gt;
NETMASK=255.255.0.0&lt;br /&gt;
NM_CONTROLLED=&amp;quot;no&amp;quot;&lt;br /&gt;
ONBOOT=&amp;quot;yes&amp;quot;&lt;br /&gt;
USERCTL=no&lt;br /&gt;
BONDING_MASTER=yes&lt;br /&gt;
TYPE=Bond&lt;br /&gt;
BONDING_OPTS=&amp;quot;mode=4 miimon=100 lacp_rate=0&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To get second bond interface tagged to vlan 2 (PUB) &lt;br /&gt;
 vconfig add bond0 2&lt;br /&gt;
&lt;br /&gt;
:* ifcfg-bond0.2&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
DEVICE=&amp;quot;bond0.2&amp;quot;&lt;br /&gt;
BOOTPROTO=none&lt;br /&gt;
ONPARENT=yes&lt;br /&gt;
IPADDR=193.58.172.92&lt;br /&gt;
BROADCAST=&amp;quot;193.58.172.127&amp;quot;&lt;br /&gt;
NETMASK=255.255.255.128&lt;br /&gt;
GATEWAY=193.58.172.2&lt;br /&gt;
NM_CONTROLLED=&amp;quot;no&amp;quot;&lt;br /&gt;
ONBOOT=&amp;quot;yes&amp;quot;&lt;br /&gt;
USERCTL=no&lt;br /&gt;
VLAN=yes&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Aggregate interfaces eth0 and eth1 to the bond:&lt;br /&gt;
** ifcfg-eth0&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
DEVICE=&amp;quot;eth0&amp;quot;&lt;br /&gt;
BOOTPROTO=none&lt;br /&gt;
NM_CONTROLLED=&amp;quot;no&amp;quot;&lt;br /&gt;
ONBOOT=&amp;quot;yes&amp;quot;&lt;br /&gt;
USERCTL=no&lt;br /&gt;
MASTER=bond0&lt;br /&gt;
SLAVE=yes&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
:* ifcfg-eth1&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
DEVICE=&amp;quot;eth1&amp;quot;&lt;br /&gt;
BOOTPROTO=none&lt;br /&gt;
NM_CONTROLLED=&amp;quot;no&amp;quot;&lt;br /&gt;
ONBOOT=&amp;quot;yes&amp;quot;&lt;br /&gt;
USERCTL=no&lt;br /&gt;
MASTER=bond0&lt;br /&gt;
SLAVE=yes&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== On the switch ===&lt;br /&gt;
We are configuring everything in LACP [&amp;lt;=&amp;gt; mode=4 in MODPROBE_OPTS for bond0]&lt;br /&gt;
* Adding the PoX interface on the 10G switch&lt;br /&gt;
** Using the interface, create the lacp port first in tab &#039;&#039;&#039;ETH Mgmt&#039;&#039;&#039;, click on &#039;&#039;&#039;Link Aggregation&#039;&#039;&#039;, Provide in the box &#039;&#039;&#039;LAG Interface Number&#039;&#039;&#039; PoX (X a number).&lt;br /&gt;
** On tab &#039;&#039;&#039;Ports&#039;&#039;&#039;, click on the port you want to add, select &#039;&#039;&#039;LAG&#039;&#039;&#039;: PoX, &#039;&#039;&#039;LAG mode&#039;&#039;&#039;: active (&#039;&#039;&#039;LACP rate&#039;&#039;&#039; is auto on slow [&amp;lt;=&amp;gt; lacp_rate=0 in MODPROBE_OPTS for bond0] )&lt;br /&gt;
::: &#039;&#039;If it does not work and complains about vlans, follow the section &#039;&#039;&#039;Adding a new port to PoX&#039;&#039;&#039; below&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* on the switch in CLI:&lt;br /&gt;
** the PoX port is going to be in hybrid mode, to have untagged[=access] vlan1 and tagged[=hybrid allowed-vlan] vlan 2 (ex: Po5): &#039;&#039;&#039;[ vlan1 cannot be tagged on the switch ]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
melswitch1 [standalone: master] &amp;gt; enable&lt;br /&gt;
melswitch1 [standalone: master] # config term&lt;br /&gt;
melswitch1 [standalone: master] (config) # interface port-channel 5&lt;br /&gt;
melswitch1 [standalone: master] (config interface port-channel 5) # switchport mode hybrid&lt;br /&gt;
melswitch1 [standalone: master] (config interface port-channel 5) # switchport access vlan 1&lt;br /&gt;
melswitch1 [standalone: master] (config interface port-channel 5) # switchport hybrid allowed-vlan 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
:* Adding a new port to PoX (ex: ethernet 1/27)&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
melswitch1 [standalone: master] (config) # interface ethernet 1/27&lt;br /&gt;
melswitch1 [standalone: master] (config interface ethernet 1/27) # switchport mode hybrid&lt;br /&gt;
melswitch1 [standalone: master] (config interface ethernet 1/27) # switchport access vlan 1&lt;br /&gt;
melswitch1 [standalone: master] (config interface ethernet 1/27) # switchport hybrid allowed-vlan 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
then on the interface, add the port to PoX following the previous section.&lt;/div&gt;</summary>
		<author><name>Shkelzen Rugovac</name></author>
	</entry>
	<entry>
		<id>https://t2bwiki.iihe.ac.be/index.php?title=Network_bond_and_tag&amp;diff=669</id>
		<title>Network bond and tag</title>
		<link rel="alternate" type="text/html" href="https://t2bwiki.iihe.ac.be/index.php?title=Network_bond_and_tag&amp;diff=669"/>
		<updated>2016-04-21T12:45:49Z</updated>

		<summary type="html">&lt;p&gt;Shkelzen Rugovac: /* On the switch */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== On the host ===&lt;br /&gt;
&lt;br /&gt;
In &#039;&#039;&#039;/etc/sysconfig/network-scripts&#039;&#039;&#039;:&lt;br /&gt;
:* ifcfg-bond0&lt;br /&gt;
&amp;lt;pre&amp;gt;DEVICE=&amp;quot;bond0&amp;quot;&lt;br /&gt;
BOOTPROTO=none&lt;br /&gt;
IPADDR=192.168.10.135&lt;br /&gt;
BROADCAST=192.168.255.255&lt;br /&gt;
NETMASK=255.255.0.0&lt;br /&gt;
NM_CONTROLLED=&amp;quot;no&amp;quot;&lt;br /&gt;
ONBOOT=&amp;quot;yes&amp;quot;&lt;br /&gt;
USERCTL=no&lt;br /&gt;
BONDING_MASTER=yes&lt;br /&gt;
TYPE=Bond&lt;br /&gt;
BONDING_OPTS=&amp;quot;mode=4 miimon=100 lacp_rate=0&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
To get second bond interface tagged to vlan 2 (PUB) &lt;br /&gt;
 vconfig add bond0 2&lt;br /&gt;
&lt;br /&gt;
:* ifcfg-bond0.2&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
DEVICE=&amp;quot;bond0.2&amp;quot;&lt;br /&gt;
BOOTPROTO=none&lt;br /&gt;
ONPARENT=yes&lt;br /&gt;
IPADDR=193.58.172.92&lt;br /&gt;
BROADCAST=&amp;quot;193.58.172.127&amp;quot;&lt;br /&gt;
NETMASK=255.255.255.128&lt;br /&gt;
GATEWAY=193.58.172.2&lt;br /&gt;
NM_CONTROLLED=&amp;quot;no&amp;quot;&lt;br /&gt;
ONBOOT=&amp;quot;yes&amp;quot;&lt;br /&gt;
USERCTL=no&lt;br /&gt;
VLAN=yes&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Aggregate interfaces eth0 and eth1 to the bond:&lt;br /&gt;
** ifcfg-eth0&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
DEVICE=&amp;quot;eth0&amp;quot;&lt;br /&gt;
BOOTPROTO=none&lt;br /&gt;
NM_CONTROLLED=&amp;quot;no&amp;quot;&lt;br /&gt;
ONBOOT=&amp;quot;yes&amp;quot;&lt;br /&gt;
USERCTL=no&lt;br /&gt;
MASTER=bond0&lt;br /&gt;
SLAVE=yes&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
:* ifcfg-eth1&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
DEVICE=&amp;quot;eth1&amp;quot;&lt;br /&gt;
BOOTPROTO=none&lt;br /&gt;
NM_CONTROLLED=&amp;quot;no&amp;quot;&lt;br /&gt;
ONBOOT=&amp;quot;yes&amp;quot;&lt;br /&gt;
USERCTL=no&lt;br /&gt;
MASTER=bond0&lt;br /&gt;
SLAVE=yes&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== On the switch ===&lt;br /&gt;
We are configuring everything in LACP [&amp;lt;=&amp;gt; mode=4 in MODPROBE_OPTS for bond0]&lt;br /&gt;
* Adding the PoX interface on the 10G switch&lt;br /&gt;
** Using the interface, create the lacp port first in tab &#039;&#039;&#039;ETH Mgmt&#039;&#039;&#039;, click on &#039;&#039;&#039;Link Aggregation&#039;&#039;&#039;, Provide in the box &#039;&#039;&#039;LAG Interface Number&#039;&#039;&#039; PoX (X a number).&lt;br /&gt;
** On tab &#039;&#039;&#039;Ports&#039;&#039;&#039;, click on the port you want to add, select &#039;&#039;&#039;LAG&#039;&#039;&#039;: PoX, &#039;&#039;&#039;LAG mode&#039;&#039;&#039;: active (&#039;&#039;&#039;LACP rate&#039;&#039;&#039; is auto on slow [&amp;lt;=&amp;gt; lacp_rate=0 in MODPROBE_OPTS for bond0] )&lt;br /&gt;
::: &#039;&#039;If is does not work and complains about vlans, follow the section &#039;&#039;&#039;Adding a new port to PoX&#039;&#039;&#039; below&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* on the switch in CLI:&lt;br /&gt;
** the PoX port is going to be in hybrid mode, to have untagged[=access] vlan1 and tagged[=hybrid allowed-vlan] vlan 2 (ex: Po5): &#039;&#039;&#039;[ vlan1 cannot be tagged on the switch ]&#039;&#039;&#039;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
melswitch1 [standalone: master] &amp;gt; enable&lt;br /&gt;
melswitch1 [standalone: master] # config term&lt;br /&gt;
melswitch1 [standalone: master] (config) # interface port-channel 5&lt;br /&gt;
melswitch1 [standalone: master] (config interface port-channel 5) # switchport mode hybrid&lt;br /&gt;
melswitch1 [standalone: master] (config interface port-channel 5) # switchport access vlan 1&lt;br /&gt;
melswitch1 [standalone: master] (config interface port-channel 5) # switchport hybrid allowed-vlan 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
:* Adding a new port to PoX (ex: ethernet 1/27)&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
melswitch1 [standalone: master] (config) # interface ethernet 1/27&lt;br /&gt;
melswitch1 [standalone: master] (config interface ethernet 1/27) # switchport mode hybrid&lt;br /&gt;
melswitch1 [standalone: master] (config interface ethernet 1/27) # switchport access vlan 1&lt;br /&gt;
melswitch1 [standalone: master] (config interface ethernet 1/27) # switchport hybrid allowed-vlan 2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
then on the interface, add the port to PoX following the previous section.&lt;/div&gt;</summary>
		<author><name>Shkelzen Rugovac</name></author>
	</entry>
	<entry>
		<id>https://t2bwiki.iihe.ac.be/index.php?title=UpdateCertificates&amp;diff=657</id>
		<title>UpdateCertificates</title>
		<link rel="alternate" type="text/html" href="https://t2bwiki.iihe.ac.be/index.php?title=UpdateCertificates&amp;diff=657"/>
		<updated>2016-03-25T13:22:46Z</updated>

		<summary type="html">&lt;p&gt;Shkelzen Rugovac: /* Renew Certificates */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== Deprecated content ! Please read before going any further on this page ! ==&lt;br /&gt;
The procedure to request certificates has changed since a few months. The new procedure is described [http://wikit.iihe.ac.be/index.php/SSL_Certificates here].&lt;br /&gt;
&lt;br /&gt;
So, what is written below is not valid anymore and needs to be adapted...&lt;br /&gt;
&lt;br /&gt;
== Update and request server certificates ==&lt;br /&gt;
[[PageOutline]]&lt;br /&gt;
----&lt;br /&gt;
=== Introduction ===&lt;br /&gt;
All certificates for our machines will have to be updated every year. We will receive mails starting 2 weeks before the certificates expire. &amp;lt;br&amp;gt;&lt;br /&gt;
the decision was taken to update all the certificates at once and Stein De Weirdt wrote a script to do just that. &amp;lt;br&amp;gt;&lt;br /&gt;
The last update of the certificates happened on 2 mai 2008 on a cloudy but warm afternoon.&lt;br /&gt;
&lt;br /&gt;
=== Procedure ===&lt;br /&gt;
&lt;br /&gt;
Log in on &#039;&#039;&#039;ccq3&#039;&#039;&#039; and generate all the necessary certificates with this tool:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/opt/CB6/tmp/src/begrid/cb-client/certificate_tool.py &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
the tools help output gives:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Usage: &lt;br /&gt;
    --mode    Mode: new,renew,conv,get (default: renew)&lt;br /&gt;
                    renew: make new server requests from existing certificates (in directory --dir) and upload the requests&lt;br /&gt;
                    get: - will make quattor templates in &amp;lt;--dir&amp;gt;/private&lt;br /&gt;
                         - public key need to be put in &amp;lt;--dir&amp;gt;/PemDir (to be created)&lt;br /&gt;
                         - the matching private key is looked for in &amp;lt;--dir&amp;gt;&lt;br /&gt;
                    new: make new server request (with DN attributes --att and create the requests/key in --dir)&lt;br /&gt;
    --dir     Read/write templates to/from dir (default: .)&lt;br /&gt;
  &lt;br /&gt;
    --debug   Set debug mode. (default: False) &lt;br /&gt;
    --att     DN Attributes, comma separated list eg (OU=IIHE,CN=gridce.iihe.ac.be,emailAddress=grid_admin@listserv.vub.ac.be) &lt;br /&gt;
              - assumes C=BE and O=BEGRID &lt;br /&gt;
              - emailAddress is mandatory (and should be last att)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;1.&#039;&#039;&#039; Create/renew certificate&lt;br /&gt;
==== Create New Certificate ====&lt;br /&gt;
To create a new certificate, do:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/opt/CB6/tmp/src/begrid/cb-client/certificate_tool.py --mode=new --dir=/root/new-cert/ --att=OU=IIHE,CN=behar050.iihe.ac.be,emailAddress=grid_admin@listserv.vub.ac.be --debug&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
==== Renew Certificates ====&lt;br /&gt;
To renew all certificates, first remove all .pem files in /root/new-cert/. Move the .tpl files from /root/new-cert/private to /root/new-cert/. Then, remove everything from the 2 subdirectories (private and PemDir)&amp;lt;br&amp;gt;&lt;br /&gt;
Then Do:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/opt/CB6/tmp/src/begrid/cb-client/certificate_tool.py --mode=renew --dir=/root/new-cert/ --debug&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;2.&#039;&#039;&#039;All the keys need to be uploaded one by one to the belnet site. Go to https://gridra.belnet.be , click &amp;quot;Request a Certificate&amp;quot;, choose server from the drop down box. Upload one generate certificate (the ones with -req). On OU needs to be added. For this chose &#039;VUB&#039;. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;3.&#039;&#039;&#039; All the generated certificates will be send via mail. Download them all (choose only the one ending in _iihe_ac_be.pem from every mail) and put them in /root/new-cert/PemDir and do:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/opt/CB6/tmp/src/begrid/cb-client/certificate_tool.py --mode=get  --dir=/root/new-cert/ --debug&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
all the certificates templates will be saved in /root/new-cert/private. &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;4.&#039;&#039;&#039; next step is to update all the quattor files and to make the clients connect for their new certificates. &amp;lt;br&amp;gt;&lt;br /&gt;
For this, put the private templates on ccq3, /opt/CB6/private or /opt/CB5/private, in the appropriate glite version dir.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
cd /opt/CB6/svncheck/&lt;br /&gt;
./runcheck&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;5.&#039;&#039;&#039; This will broadcast a message to all the machines and they will respond within 5 minutes and start updating. All services except one will update fine &amp;lt;br&amp;gt; &amp;lt;br&amp;gt;&lt;br /&gt;
&#039;&#039;&#039;6.&#039;&#039;&#039; We now check that the update was complete and for this we first log in to &#039;&#039;&#039;maite&#039;&#039;&#039;. &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
grep filecopy /var/log/ncm-cdispd.log&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Or alternatively&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
less /var/log/ncm/component-filecopy.log&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Now, check the certificate:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
openssl x509 -in /etc/grid-security/hostcert.pem -noout -dates&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
And make sure the new end date is indeed a year from now.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;7.&#039;&#039;&#039; We now perform a final check: log in to any UI and do&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
srmls srm://maite.iihe.ac.be:8443/pnfs/iihe/cms&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
also try to copy some files from storage to the use disk using dccp. &lt;br /&gt;
All directories should be listed.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;8.&#039;&#039;&#039; Restart argus service on argus&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
service argus stop&lt;br /&gt;
service argus start&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If this is not enough think of restarting the node.&lt;br /&gt;
&lt;br /&gt;
If the DN of the machine changes (new certificate provider, ...) then its need to be added explicitly into the template of argus. The affected variable is PAP_HOST_DN. &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;9.&#039;&#039;&#039; (Optional) Adapt GOCDB server entry&lt;br /&gt;
&lt;br /&gt;
If the DN of the machine changes (especially needed for APEL) then go to the GOCDB page and edit the corresponding entry to reflect the new DN. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{TracNotice|{{PAGENAME}}}}&lt;/div&gt;</summary>
		<author><name>Shkelzen Rugovac</name></author>
	</entry>
	<entry>
		<id>https://t2bwiki.iihe.ac.be/index.php?title=Register_to_the_CMS_VO&amp;diff=543</id>
		<title>Register to the CMS VO</title>
		<link rel="alternate" type="text/html" href="https://t2bwiki.iihe.ac.be/index.php?title=Register_to_the_CMS_VO&amp;diff=543"/>
		<updated>2015-11-05T16:17:36Z</updated>

		<summary type="html">&lt;p&gt;Shkelzen Rugovac: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Go to the [https://voms2.cern.ch:8443/voms/cms/user/home.action  VOMS page]. On the eventual certificate prompt, select the one you just created. &amp;lt;br&amp;gt;&lt;br /&gt;
** Enter the email address registered at cern, then click submit.&amp;lt;br&amp;gt;&lt;br /&gt;
** You should appear just below. If it&#039;s you, well click on the correct button !&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
:: [[ File:vocms1.png|center]]&amp;lt;br&amp;gt;&lt;br /&gt;
:* If it doesn&#039;t find you with the email you entered after clicking on submit, then look in the [https://phonebook.cern.ch/phonebook/ CERN phonebook] for your email. If you cannot find yourself, then make sure you are registered to CERN or CMS at least.&lt;br /&gt;
:: [[File:cern_phonebook.png|center]]&lt;br /&gt;
:* Fill in all fields, accept the policy, then submit.&lt;br /&gt;
:: [[File:vocms_form.png|center]]&lt;br /&gt;
:* The procedure is nearly finished, look at your inbox corresponding to the CERN email.&lt;br /&gt;
[[File:vocms_email.png|center]]&lt;br /&gt;
:* Just click on the confirmation link in the email received.&lt;br /&gt;
[[File:vocms_end.png|center]]&lt;br /&gt;
&lt;br /&gt;
* Now you only need to wait 1 or 2 hours for your membership to be approved !&lt;br /&gt;
&lt;br /&gt;
* You can [[SiteDB | follow the wiki]] to check SiteDB if your certificate as well as membership are fine.&lt;/div&gt;</summary>
		<author><name>Shkelzen Rugovac</name></author>
	</entry>
	<entry>
		<id>https://t2bwiki.iihe.ac.be/index.php?title=Certificates_and_VOs&amp;diff=425</id>
		<title>Certificates and VOs</title>
		<link rel="alternate" type="text/html" href="https://t2bwiki.iihe.ac.be/index.php?title=Certificates_and_VOs&amp;diff=425"/>
		<updated>2015-09-23T15:01:42Z</updated>

		<summary type="html">&lt;p&gt;Shkelzen Rugovac: /* CMS */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== Getting access the IIHE T2B ==&lt;br /&gt;
&lt;br /&gt;
*In order to get access to grid and the Tier2 at the IIHE you need obtain a BEgrid Certificate and get access to the User Interfaces of the IIHE. &lt;br /&gt;
*BEgrid certificates are managed by [http://www.begrid.be/ BELNET]&lt;br /&gt;
*The access to the IIHE UI&#039;s, called the Mx machines (x representing a number) is explained [[First_access_to_t2b|here]]&lt;br /&gt;
*&#039;&#039;&#039;First registration&#039;&#039;&#039;: The registration procedure consist of several steps outlined below in the section [#Firstregistration:Outlineofregistrationprocedure First registration]&lt;br /&gt;
*&#039;&#039;&#039;Certificate Renewal&#039;&#039;&#039;: The procedure to renew your certificate is described in section [#Certificaterenewal:Updatecertificate Certificate Renewal]&lt;br /&gt;
&lt;br /&gt;
==== Password advice ====&lt;br /&gt;
In the registration procedure that is described here, a number of passwords will be requested from you. Please choose good ones and don&#039;t share them with other people (or write them on post-its ;). &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
=== First registration: Outline of registration procedure === &lt;br /&gt;
&lt;br /&gt;
*First, a very important preliminary remark before going into the steps of the certificate request procedure : you can use Firefox or IE, but please DON&#039;T USE CHROME and KEEP THE SAME BROWSER AND LAPTOP/PC DURING ALL THE PROCEDURE.&lt;br /&gt;
*If you request a certificate for the very first time, you can follow the procedure [http://quattor.begrid.be/trac/centralised-begrid-v5/wiki/Access_to_BEgrid here]. The section &#039;&#039;Get a BEgrid Certificate&#039;&#039; should provide you with a BEgrid certificate and should allow you to prepare your browser&lt;br /&gt;
**Get a BEgrid certificate&lt;br /&gt;
**Browser preparation&lt;br /&gt;
&lt;br /&gt;
*The next step is to Join a Virtual organisation &#039;&#039;VO&#039;&#039; as described further on this page in the section &#039;&#039;Virtual Organisation&#039;&#039;. You can make several choices. If you intend to use the CMS grid infrastructure your VO is CMS. For BEgrid applications join beapps or betest.  &lt;br /&gt;
*A summary of the steps you should take is given here:&lt;br /&gt;
**VO CMS :&lt;br /&gt;
**# VO CMS registration&lt;br /&gt;
**#Become a member of the group /cms/becms&lt;br /&gt;
**VO BEAPPS :&lt;br /&gt;
**#VO BEAPPS registration&lt;br /&gt;
**VO BETEST :&lt;br /&gt;
**#VO BETEST registration&lt;br /&gt;
&lt;br /&gt;
*If you join the CMS VO you still need to do following steps as described in section &#039;&#039;Mailing-list and access to Mx-machines&#039;&#039;&lt;br /&gt;
**Create your Hypernews account&lt;br /&gt;
**Register your DN in SiteDB&lt;br /&gt;
**Else CRAB will not work.&lt;br /&gt;
**First, make a public certificate [https://ca.cern.ch/ca/Help/?kbid=023010 Instructions]&lt;br /&gt;
**Next, upload this public certificate in this [https://accountmap.web.cern.ch/accountmap/Mapping/Certificates.aspx page]&lt;br /&gt;
**After ~15 minutes, the changes should be reflected on [https://cmsweb.cern.ch/sitedb/dev/people this page]&lt;br /&gt;
&lt;br /&gt;
==== Virtual Organisation ====&lt;br /&gt;
What VO should I join?&lt;br /&gt;
*Depending on your experiment or type of application, you have to choose a corresponding VO. If you have no clue which it is, ask your contact person. Unless you really know what your doing (but why are you reading this page?), don&#039;t join &amp;lt;tt&amp;gt;dteam&amp;lt;/tt&amp;gt; or &amp;lt;tt&amp;gt;ops&amp;lt;/tt&amp;gt;.&lt;br /&gt;
==== CMS ====&lt;br /&gt;
For all people that are in the CMS collaboration and that need access to something.&lt;br /&gt;
*You need to have your browsercertificate loaded.&lt;br /&gt;
*Go to: [https://voms2.cern.ch:8443/voms/cms/user/home.action VO CMS registration]&lt;br /&gt;
**[https://voms2.cern.ch:8443/voms/cms/user/home.action Phase I]&lt;br /&gt;
**fill in a valid email address&lt;br /&gt;
***the email address must be known in the CERN database and in the CMS database (normally this is the address used when registering with CMS for the first time)&lt;br /&gt;
***in case you have problems, try the [http://consult.cern.ch/xwho CERN xwho database] to find your known email address&lt;br /&gt;
**select &#039;&#039;Marti Pimia&#039;&#039; as representative&lt;br /&gt;
**fill in your first name and last name&lt;br /&gt;
**wait for an email to go to Phase II&lt;br /&gt;
**click on the link in the email. It will take you to the Phase II registration page.&lt;br /&gt;
**fill in your personal information&lt;br /&gt;
**pick any additional roles (if really needed). the default should be ok for lost people.&lt;br /&gt;
**on the bottom: read the &#039;&#039;GRID Acceptable Use Policy&#039;&#039; and select ok&lt;br /&gt;
**click to register&lt;br /&gt;
**&#039;&#039;&#039;Also send an email to the admins&#039;&#039;&#039; [ grid_admin[AT]listserv.vub.ac.be ] to tell them who you are. Also put your team leader in CC, in this way we know that you are part of the Belgian collaborators (it is impossible for us to know all new members)&lt;br /&gt;
**you now have to wait for approval of your request. this can take some time and you will notified by email. &lt;br /&gt;
**at latest one day after this approval you will be able to use the CMS grid resources.&lt;br /&gt;
*After you are member of the VO cms, you need to join the group &amp;lt;tt&amp;gt;/cms/becms&amp;lt;/tt&amp;gt;&lt;br /&gt;
**Goto the [https://voms2.cern.ch:8443/voms/cms/user/home.action Select Groups &amp;amp; Group Roles]&lt;br /&gt;
**Select the group &amp;lt;tt&amp;gt;/cms/becms&amp;lt;/tt&amp;gt;&lt;br /&gt;
**Press &amp;lt;tt&amp;gt;Submit&amp;lt;/tt&amp;gt; at the bottom of the page&lt;br /&gt;
**[[Image(cms-groups-becms.png, 50%)]]&lt;br /&gt;
&lt;br /&gt;
==== BEapps ====&lt;br /&gt;
*Not needed if you are in CMS&lt;br /&gt;
*For all people that want to have their application running in BEgrid on a production level.&lt;br /&gt;
*You must have your browser certificate loaded.&lt;br /&gt;
*Go to: [https://voms01.begrid.be:8443/voms/beapps/StartRegistration.do VO BEapps registration]&lt;br /&gt;
==== BEtest ====&lt;br /&gt;
*Not needed if you are in CMS&lt;br /&gt;
*For all people that want to test their application running in BEgrid.&lt;br /&gt;
*You must have your browser certificate loaded.&lt;br /&gt;
*Go to: [https://voms01.begrid.be:8443/voms/betest/StartRegistration.do VO BEtest registration]&lt;br /&gt;
&lt;br /&gt;
==== Hypernews &amp;amp; SiteDb ====&lt;br /&gt;
&lt;br /&gt;
*HN account&lt;br /&gt;
**[https://hypernews.cern.ch/HyperNews/CMS/add-member.pl New member info]&lt;br /&gt;
**If you have a lxplus account, you can register yourself&lt;br /&gt;
**If not, you need to send an email to the cms hn admin.&lt;br /&gt;
**Register HN account in SiteDB ([https://twiki.cern.ch/twiki/bin/view/CMS/SiteDBForCRAB instructions])&lt;br /&gt;
**Else CRAB will not work.&lt;br /&gt;
**First, make a public certificate [https://ca.cern.ch/ca/Help/?kbid=023010 Instructions]&lt;br /&gt;
**Next, upload this public certificate in this [https://accountmap.web.cern.ch/accountmap/Mapping/Certificates.aspx page]&lt;br /&gt;
**After ~15 minutes, the changes should be reflected on [https://cmsweb.cern.ch/sitedb/dev/people this page]&lt;br /&gt;
&lt;br /&gt;
*Once you have access to the UIs, you need to install your certificate on these machines. This procedure is described [http://quattor.begrid.be/trac/centralised-begrid-v5/wiki/Access_to_BEgrid here] under the section &#039;&#039;Install your certificate in your new Unix account&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
=== Certificate renewal: Update certificate ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#comment&lt;br /&gt;
As the CA changed, users with a certificate made before November 2008 should ask for a new certificate. This is because the certificate authority changed.&lt;br /&gt;
*Certificate renewal for certificates delivered BEFORE November 2008 &lt;br /&gt;
**First follow the procedure as detailed in &amp;quot;Requesting a certificate for the very first time&amp;quot;&lt;br /&gt;
**Install your newly received certificate in a directory other than .globus, as you will use the old one while waiting for the new one to be approved by cms&lt;br /&gt;
**Then go to https://lcg-voms.cern.ch:8443/vo/cms/vomrs?path=/RootNode/MemberAction/MemberDNs/AddDN&amp;amp;action=execute&amp;amp;do=select&lt;br /&gt;
**Fill in your new Dn (you can obtain this by running the following command: &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#comment&lt;br /&gt;
openssl x509 -in usercert.pem -subject&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#comment&lt;br /&gt;
**Your new DN starts with /C=BE&lt;br /&gt;
**Make sure when you copy, not to add any whitespace before or after the DN&lt;br /&gt;
**also change the CA (dropdown box) to : /C=BE/OU=BEGRID/O=BELNET/CN=BEgrid CA&lt;br /&gt;
***note that a similar one exists with an email address. Do NOT use the one with the email address.&lt;br /&gt;
**In the reasons box, fill in: &amp;quot;Change of CA&amp;quot;&lt;br /&gt;
**Wait until the new certificate is approved and then ...&lt;br /&gt;
**contact the admins to have your dcache acces mapped to your new DN (send us the DN via email)&lt;br /&gt;
**also change your DN into siteDB (https://twiki.cern.ch/twiki/bin/view/CMS/SiteDBForCRAB)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*Certificate renewal&lt;br /&gt;
**Please DON&#039;T USE CHROME and KEEP THE SAME BROWSER AND LAPTOP/PC DURING ALL THE PROCEDURE !&lt;br /&gt;
**Go to the belnet site https://gridra.belnet.be/pub/&lt;br /&gt;
**Go to request a new certificate based on an existing certificate (the renew function does not work on their site)&lt;br /&gt;
**You can install your new certificate directly in your browser with the &amp;quot;Integrate&amp;quot; button (recommended) or download it as a file.&lt;br /&gt;
**then, install your new certificate in your Unix account:&lt;br /&gt;
**The certificate has to be copied on the User Interface server (and saved in a different format ...)&lt;br /&gt;
***Export the certificate from your browser, into a &#039;p12&#039; - file&lt;br /&gt;
***for Firefox: Select Edit/Preferences-&amp;gt;Advanced-&amp;gt;Manage Certificates; Select the Certificate Click &amp;quot;Backup&amp;quot; give the requested password, then Save with file name &amp;quot;cert&amp;quot; (Will create file cert.p12)&lt;br /&gt;
***for Internet Explorer Select Tools/Internet Options Select Content Select Certificates Select Personal Select the Certificate Click &amp;quot;Export&amp;quot; On Certificate Manager Export Wizard Select Next Select &#039;Yes, export the private key&#039; &lt;br /&gt;
***For MAC:&lt;br /&gt;
####Open the Keychain Access utility (Applications -&amp;gt; Utilities)&lt;br /&gt;
       2. Select your certificate or key from the Certificates or Keys category, and do one of the following:&lt;br /&gt;
#####Choose File -&amp;gt; Export items ...&lt;br /&gt;
         b. Right-click, and choose Export [your name]&#039;s ID ...&lt;br /&gt;
       3. In the Save As field, enter cert.12 for the exported item, and click Save.  You will be prompted to enter a new export password for the item.&lt;br /&gt;
**Select Personal Information Exchange PKCS#12 (.PFX) give the requested password, then Save with file name &amp;quot;cert&amp;quot;.( will save cert.pfx, rename this to cert.p12 ) &lt;br /&gt;
***scp the file cert.p12 on the User Interface server.&lt;br /&gt;
***login on the userinterface-server; The file cert.p12 should be in your homedirectory now. Execute fillowing commands (to transform the certificate and private key from the PFX-format into PEM format; they will ask for the passphrase you put on cert.p12 in order to read it, and will ask you for a new passphrase to put on the private key userkey.pem; You can take the same passphrase ... !)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 mkdir ~/.globus&lt;br /&gt;
 openssl pkcs12 -nocerts -in cert.p12 -out ~/.globus/userkey.pem&lt;br /&gt;
 openssl pkcs12 -clcerts -nokeys -in cert.p12 -out ~/.globus/usercert.pem&lt;br /&gt;
 chmod 400 ~/.globus/userkey.pem&lt;br /&gt;
 chmod 644 ~/.globus/usercert.pem&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
  &lt;br /&gt;
----&lt;br /&gt;
=== Questions and Remarks ===&lt;br /&gt;
==== Who is my local BEgrid contact person? ====&lt;br /&gt;
Good question. If you really don&#039;t know or you can&#039;t ask anybody else, you may always contact rosette.vandenbroucke@vub.ac.be with this question.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Some links ====&lt;br /&gt;
*[http://www.alw.nih.gov/Security/Docs/passwd.html www.alw.nih.gov]&lt;br /&gt;
*[http://www.auscert.org.au/render.html?it=2260 www.auscert.org.au]&lt;br /&gt;
*[http://en.wikipedia.org/wiki/Passwords en.wikipedia.org]&lt;br /&gt;
*pisa.belnet.be [http://pisa.belnet.be/pisa/nl/password.htm (dutch)], [http://pisa.belnet.be/pisa/fr/password.htm (french)]&lt;br /&gt;
&lt;br /&gt;
==== Extra ====&lt;br /&gt;
Useful link for all detailed commands on certificates:&lt;br /&gt;
*http://goc.eu-eela.org/operations/certification-authority-and-virtual-organisation-operations/certificate-manipulation/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Problems ====&lt;br /&gt;
==== No certificate matches private key ====&lt;br /&gt;
When the conversion to &amp;lt;tt&amp;gt;.p12&amp;lt;/tt&amp;gt; fails with this message, a number of things might be wrong:&lt;br /&gt;
*Make sure that the request-key is the one matching the certificate (ie the download.cer file).&lt;br /&gt;
*Check the public modulus:&lt;br /&gt;
**&amp;lt;tt&amp;gt;openssl rsa -noout -text -in &amp;lt;request_key&amp;gt;&amp;lt;/tt&amp;gt; &lt;br /&gt;
**&amp;lt;tt&amp;gt;openssl req -noout -text -in  &amp;lt;newcert_request.pem&amp;gt;&amp;lt;/tt&amp;gt;&lt;br /&gt;
**&amp;lt;tt&amp;gt;openssl x509 -noout -text -in &amp;lt;download.cer&amp;gt;&amp;lt;/tt&amp;gt;&lt;br /&gt;
*They should all have the same modulus, eg&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
  Modulus (2048 bit):&lt;br /&gt;
       00:a8:7d:e0:ec:c6:ba:0b:39:87:92:87:2e:1d:03:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
*If this is not the case, something went wrong somewhere. You should contact gridcaNOSPAM@belnet.be and explain them your problem.&lt;br /&gt;
==== Troubleshooting check-list ====&lt;br /&gt;
This section gives a summary of the different steps of the registration procedure detailed on this page. You can use it as a check-list, e.g. to verify that you don&#039;t have missed a step.&lt;br /&gt;
 - Browser preparation&lt;br /&gt;
 - Get a BEgrid certificate&lt;br /&gt;
 - Join a VO (CMS or BEAPPS or BETEST) :&lt;br /&gt;
**VO CMS :&lt;br /&gt;
**VO CMS registration&lt;br /&gt;
**Send a email to the T2B grid-admins (grid_adminNOSPAM@listserv.vub.ac.be) to introduce yourself&lt;br /&gt;
**Become a member of the group /cms/becms&lt;br /&gt;
**Create your Hypernews account&lt;br /&gt;
**Register your DN in SiteDB&lt;br /&gt;
**Register to T2B mailing-list&lt;br /&gt;
**VO BEAPPS :&lt;br /&gt;
**VO BEAPPS registration&lt;br /&gt;
**VO BETEST :&lt;br /&gt;
**VO BETEST registration&lt;br /&gt;
 - Send your SSH key to grid_adminNOSPAM@listserv.vub.ac.be&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Certificates ===&lt;br /&gt;
BEgrid certificates are managed by BELNET&lt;br /&gt;
*[https://gridra.belnet.be/pub/ Homepage of the BELNET CA]&lt;br /&gt;
*Email your questions or remarks to gridcaNOSPAM@belnet.be&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Browser preparation ====&lt;br /&gt;
==== Everybody has to do this at least once : ====&lt;br /&gt;
*Load the certificate authenticating the BEgrid CA by clicking on the appropriate link at https://gridra.belnet.be/&lt;br /&gt;
**This may bring up a so-called &amp;lt;tt&amp;gt;Software Security Device&amp;lt;/tt&amp;gt; that will manage your certifiactes in your browser.&lt;br /&gt;
  When this is the first time you use it, you&#039;ll need to configure it first. &lt;br /&gt;
  Most probably this means setting a password to protect the device.&lt;br /&gt;
**If nothing happens automagically, download the certificate from the above link and import it yourself &lt;br /&gt;
**Mozilla/firefox/etc : Edit -&amp;gt; Preferences -&amp;gt; Advanced -&amp;gt; Manage certificates -&amp;gt; authorities -&amp;gt; import&lt;br /&gt;
*If your CA is CERN, to load the CA certificate go to [https://ca.cern.ch/ca/ the CERN CA homepage], and in the section &#039;&#039;Download CA certificates and CRLs&#039;&#039; click on both [https://ca.cern.ch/ca/CRL/CERN%20Root%20CA.crt CERN Root CA certificate] and [https://ca.cern.ch/ca/CRL/CERN%20Trusted%20Certification%20Authority.crt CERN Trusted Certification Authority Certificate]&lt;br /&gt;
&lt;br /&gt;
==== If your certificate is no longer in your browser : ====&lt;br /&gt;
This can happen if you have changed from laptop or if you have reinstalled everything from scratch on your laptop &#039;&#039;without having restored a backup of your browser environment&#039;&#039;. In this case, if you still have access to our UIs, you can recreate the PKCS12 (*.p12) certificate from the usercert.pem and userkey.pem files located in your ~/.globus. Here is the procedure :&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
On a UI :&lt;br /&gt;
cd ~/.globus&lt;br /&gt;
openssl pkcs12 -export -out cert.p12 -inkey userkey.pem -in usercert.pem&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
It will prompt you to type the password of your userkey.pem, it is the one you use to submit crab jobs. To export the p12 use the same password. So just type 3 times the same password it is easier like that.&lt;br /&gt;
&lt;br /&gt;
After that, copy the cert.p12 file back to your computer. Then you just have to import the certificate on your browser.&lt;br /&gt;
&lt;br /&gt;
Example for Mozilla Firefox: Go to Preferences &amp;gt; Advanced &amp;gt; Encryption &amp;gt; View Certificates &amp;gt;Your certificates &amp;gt; Import&lt;br /&gt;
&lt;br /&gt;
There you just have to choose the cert.p12 and it will ask you for the password you used before.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{TracNotice|{{PAGENAME}}}}&lt;/div&gt;</summary>
		<author><name>Shkelzen Rugovac</name></author>
	</entry>
	<entry>
		<id>https://t2bwiki.iihe.ac.be/index.php?title=First_access_to_t2b&amp;diff=424</id>
		<title>First access to t2b</title>
		<link rel="alternate" type="text/html" href="https://t2bwiki.iihe.ac.be/index.php?title=First_access_to_t2b&amp;diff=424"/>
		<updated>2015-09-23T14:57:20Z</updated>

		<summary type="html">&lt;p&gt;Shkelzen Rugovac: /* Getting access */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;There are a few steps to gain access to the T2:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;First thing to know:&#039;&#039;&#039; our contact mail is &#039;&#039;&#039;&#039;&#039;grid_admin AT listserv.vub.ac.be&#039;&#039;&#039;&#039;&#039; . Please always send mails to this list and not to personnal emails, this way everyone here can respond and keep up-to-date with problems.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
=== Getting access ===&lt;br /&gt;
* Now, to get access to our T2, we need 3 things :&lt;br /&gt;
** To know you: send us a mail with your promotor in cc presenting yourself (name, university, Physics group/experiment). Please do so preferrably from your preferred contact email, as it is the one we will keep to contact you.&lt;br /&gt;
** Add to this email the login you want to use. If you have a CERN account, it would be simpler for it to be the same (although not mandatory).&lt;br /&gt;
** Finally, copy-past the content of your &#039;&#039;&#039;PUBLIC&#039;&#039;&#039; ssh key, in order to have access to our User Interfaces (UIs, or often called the mX machines). To create a pair of ssh keys if you don&#039;t have one already, do the following:&lt;br /&gt;
 &amp;lt;pre&amp;gt;&lt;br /&gt;
in a shell type:&lt;br /&gt;
&amp;gt;  ssh-keygen&lt;br /&gt;
and follow the instructions. The defaults suggested are fine. Just choose a password.&lt;br /&gt;
&lt;br /&gt;
this will create 2 files in the following directory: $HOME/.ssh&lt;br /&gt;
The files are:&lt;br /&gt;
  id_rsa&lt;br /&gt;
  id_rsa.pub&lt;br /&gt;
&lt;br /&gt;
You need to send us the content of id_rsa.pub, which is your public key. The other is your private key and should never be shared.&lt;br /&gt;
Note that if you already have one somewhere else, copying both id_rsa[.pub] files on your computer is fine too.&lt;br /&gt;
 &amp;lt;/pre&amp;gt;&lt;br /&gt;
:* [OPTIONAL] If you already have a certificate, please send us your DN. It is the content of &amp;quot;Identity&amp;quot; when issuing the command voms-proxy-info.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Next Steps ===&lt;br /&gt;
* Now that you have access to our T2, read the following:&lt;br /&gt;
*# [[Media:submission_T2.pdf|PDF giving a short overview of the T2]]&lt;br /&gt;
*# [[Policies|Connecting to our UIs and policy applied]]&lt;br /&gt;
*# [[LocalSubmission|Local job submission]]&lt;br /&gt;
*: ... everything else on the [[Main_Page|twiki front page]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
* If you need a grid certificate, follow this [[Certificates_and_VOs|twiki page]]&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
*You need to register to the t2b user mailing-list&lt;br /&gt;
*# Go to the [https://e-groups.cern.ch/e-groups/EgroupsManageOwnerAdmin.do request page]&lt;br /&gt;
*# search for the list beginning with &#039;&#039;&#039;belgian-t2-users&#039;&#039;&#039;&lt;br /&gt;
*# then hit the button subscribe&lt;br /&gt;
*# If any of this fails, ask someone to contact the mailinglist admins (or ask them to send a mail to this list with your request)&lt;/div&gt;</summary>
		<author><name>Shkelzen Rugovac</name></author>
	</entry>
</feed>