Yaim (General)

Cream Element in igfae.usc.es

  • The new CE in glite-3.2 is ce01.igfae.usc.es
  • install the necessary elements:
    • =yum install glite-CREAM
    • yum install glite-TORQUE_utils glite-TORQUE_server
  • Run Yaim to configure the node:
    • /opt/glite/yaim/bin/yaim -c -s /opt/glite/yaim/etc/USC-LCG2-site-info.def -n creamCE -n TORQUE_server -n TORQUE_utils
  • After having configured CREAM, it is necessary to also configure the BLAH Blparser
    • /opt/glite/yaim/bin/yaim -r -s /opt/glite/yaim/etc/USC-LCG2-site-info.def -n creamCE -f config_cream_blparser
    • Then restart tomcat:
  • Set up the correct number of processors for machines with 4 cores (lhcb43-lhcb63; Physical or hyperthreaded) or with 8 cores (lhcb64-lhcb88; Physical)
  • Restart the following services in the given order:
    • pbs_server (In order to reconfigure the number of avaliable processors for the nodes in pbs queue.)
    • maui (It should be always run after pbs_server.)
  • Be carefull with the creation of sudoers, there is /etc/sudoers.keep for replace.
  • GLITE Cream CE 3.2 SL5 Installation Guide

glite-Apel in igfae.usc.es

bdii in igfae.usc.es

New DPM Storage Element

  • The new se in glite-3.2 is se.igfae.usc.es
  • install the necessary elements:
    • yum install glite-SE_dpm_mysql
  • Run Yaim to configure the node:
    • /opt/glite/yaim/bin/yaim -c -s /opt/glite/yaim/etc/USC-LCG2-site-info.def -n SE_dpm_mysql
  • Due to the format change in groups.conf file YAIM is not able to configure properly the access to the SE for normal users. It is neccessary to edit the file /opt/glite/yaim/functions/config_mkgrid and substitute the line:
    • ord_users=`more ${GROUPS_CONF} | awk -F: '$1 == "\"/$VO_lower'\"" { print $1 }'`
    by the following one:
    • ord_users=`more ${GROUPS_CONF} | awk -F: '$1 == "\"/VO='$VO_lower'/GROUP=/'$VO_lower'\"" { print $1 }'`

Worker Nodes

  • After an installation from scratch of a worker node we should, in the CE's, remove the corresponding entries in /etc/ssh/ssh_known_hosts and then /opt/edg/sbin/edg-pbs-knowhost must be run

Host certificate update

  • Do not forget to remove the password in the hostkey.pem file:
    • openssl rsa -in hostkey.pem -out hostkey.pem_decrypt
    and set its permissions to 400.

  • Do not forget to copy the certs in the MON box to:
    • /opt/glite/var/rgma/.certs
    • /etc/tomcat5
    and restart the necessary services.

  • The SE needs a copy of the certificates in:
    • /etc/grid-security/dpmmgr
    • /home/edguser/.globus
    • /
    and the restart of the following services:
    • dpnsdaemon, dpm, dpmcopyd, dpm-gsiftp
    • srmv1, srmv2, srmv2.2

  • globus-gatekeeper and globus-gridftp need to be restarted in the lcg-CE.

  • tomcat5 and globus-gridftp had to be restarted in cream-CE.

  • tomcat5 needs to own the certificates so we need to copy the usual ones and change the owner.

Migration of components between nodes

  • Do not forget to check that the necessary ports are open in the firewall of the node were we are moving the component to.

IP changes on control nodes

  • All control nodes keep in the /etc/hosts file their IP number so should the case of a IP change arises we have to change the entry in that file too.

