Ticket #330 (closed defect: worksforme)

Opened 13 years ago

Last modified 13 years ago

[s] we may need a bit of latitude on starting time for access certificates

Reported by: lawrence Owned by: pjkersha
Priority: desirable Milestone: PreAlpha
Component: security Version:
Keywords: Cc:

Description

AccessError?: Adding Credential: Current time 07/06/2006 17:58:53 is before Attribute Certificate's not before time of 07/06/2006 18:01:50

Clock slippage may cause trouble ...

Attachments

forPhil2.jpg Download (71.0 KB) - added by lawrence 13 years ago.
Screenshot of the error message

Change History

Changed 13 years ago by lawrence

Screenshot of the error message

comment:1 Changed 13 years ago by lawrence

  • Milestone changed from PreBeta to PreAlpha

Damn, I thought this was only a problem on my laptop, but it appears to be a problem on glue too ... can we set a 10 minute earlier than real time as a temporary not before time (we might need all ndg sites to use ntp in the longer term).

comment:2 Changed 13 years ago by pjkersha

  • Status changed from new to closed
  • Resolution set to fixed

Already come across this one :) You can make a 'window' to allow for clock slew by modifying the parameter

attCertNotBeforeOff

in the AA's configuration file /usr/local/NDG/conf/attAuthorityProperties.xml

Give a negative slew in seconds as required. It's currently set to -600 giving you a possible 10 minutes slew.

There's a note about using NTP in:

 http://bscw.badc.rl.ac.uk/bscw/bscw.cgi/d77103/NDG%20Security%20-%20Security%20Measures%20for%20Installation

This is the best long term solution. I will also explicitly raise it as a ticket.

comment:3 Changed 13 years ago by lawrence

  • Status changed from closed to reopened
  • Resolution fixed deleted

Still not resolved.

comment:4 Changed 13 years ago by lawrence

  • Status changed from reopened to closed
  • Resolution set to worksforme

Phil has found and fixed a bug which would have caused this. Assume it's fixed until we know different.

Note: See TracTickets for help on using tickets.