Both sides previous revisionPrevious revisionNext revision | Previous revisionLast revisionBoth sides next revision |
users:taarre:cert [2014/05/06 19:18] – taarre | users:taarre:cert [2014/05/09 09:49] – [Getting a Grid certificate] taarre |
---|
====== Getting a GRID certificate ====== | ====== Getting a GRID certificate ====== |
Follow the steps at [[https://twiki.cern.ch/twiki/bin/view/Main/CRABPrerequisitesGRIDCredentials|CRABPrerequisitesGRIDCredentials]] to get your certificate. To import the certificate to your Mac follow [[https://www.racf.bnl.gov/docs/howto/grid/osxcertmgmt|these guidelines]].\\ | |
| |
===== Installation of the certificate ===== | ==== Getting a Grid certificate ==== |
| Follow the steps at [[https://twiki.cern.ch/twiki/bin/view/Main/CRABPrerequisitesGRIDCredentials|CRABPrerequisitesGRIDCredentials]] to get your certificate. To import the certificate to your Mac follow [[https://www.racf.bnl.gov/docs/howto/grid/osxcertmgmt|these guidelines]] (Another installation guide can be found at |
| [[https://twiki.cern.ch/twiki/bin/viewauth/CMS/DQMGUIGridCertificate|Grid Certificate installation instructions ]]).\\ |
| |
| ==== Getting a new Grid certificate when having an old one ==== |
| * Request new certificate [[https://gridca.cern.ch/gridca/user/Request.aspx| here]] (using Firefox) |
| * Install it in your browser with the link you get |
| * Backup by Preferences-->Advanced-->View certificates-->Backup. Save .p12 file in your home directory (see under, "Installation of the certificate). If you have an old from before don't delete it, but save the new one under a different name. |
| * If you have an existing cert+key pair in your .globus/ folder, rename the old ones as eg. userkey.pem_old and keep in the globus folder |
| * After having extracted cert+key, remember to copy your new certificates to where you need then (PSI, lxplus, private computer...) by copying the .globus/ folder. Remember to set the permissions again and rename the old .globus/ folder before copying the new one! |
| * To register the new certificate with the CMS vo registration, you need to use your old certificate in the browser. To use the old certificate you might need to do Preferences-->Privacy-->Clear History and Preferences-->Advanced--> Tick "Ask me everytime" for what do do when a server asks for your certificate. Close and reopen your browser and go to the [[https://lcg-voms.cern.ch:8443/vo/cms/vomrs?path=/RootNode | cms VO registration]]. When asked what certificate to use in the pop-up window, choose your old one. |
| * At [[https://lcg-voms.cern.ch:8443/vo/cms/vomrs?path=/RootNode | cms VO registration]], go to Member Info-->Certificates-->Add Certificate. You can get the new DN by doing voms-proxy-info at lxplus. |
| * Once the new certificate is approved, you can make it your primary certificate by going to Member Info-->Certificates-->Change Primary Certificate |
| |
| |
| ==== Installation of the certificate ==== |
| |
After the successful application, the certificate has to be installed in the user's home directory following these instructions:\\ | After the successful application, the certificate has to be installed in the user's home directory following these instructions:\\ |