Joininig the ILDG VO
A description of the process for joining the ILDG Virtual Organisation.
joining_ILDG_VO.txt
—
Plain Text,
3Kb
File contents
Summary of process for joining the ILDG VO ========================================== To access ILDG resources and data, a person needs to be a member of the ILDG Virtual Organisation (VO). The VO is hosted on a VOMS system [1] that is administered by a registration service (VOMRS) [2]. The process of joining the VO can be completed via the VOMRS web interface: https://grid-voms.desy.de:8443/vo/ildg/vomrs -- provided that the user has a grid certificate from a recognised Certification Authority (CA). The user should access the VOMRS main page from a web browser in which the certificate that they intend to use for authentication has been imported: they should identify themselves using this certificate. The Distinguished Name (DN) of the certificate with which the user has authenticated themselves and the DN of the CA that issued the certificate are displayed at the bottom of each web page in VOMRS. A person registers with the ILDG VO in two phases. During the first phase, the person (classed as a 'visitor' by VOMRS) completes a registration form that is used to confirm the person's identity. Once this phase is completed, the person is reclassified as a 'candidate'. A candidate may proceed to the second phase of the registration process, during which they confirm their intent to comply with the ILDG VO Policy. Having completed the second phase of registration process, the person is reclassified as an 'applicant'. During the second phase of the registration process, the candidate is asked to nominate a representative from the regional grid to which they are associated. Upon completion of this phase of registration, an (email) alert is sent to the VO administrators and the appointed representative. The ILDG VO Policy determines that it is then the responsibility of the representative to either approve the application and assign the applicant to the VOMS sub-group that corresponds to their regional grid, or to reject the application. Once approved, an applicant becomes a 'member' of the VO. Notes and caveats: - An applicant can be assigned to a VOMS sub-group without being approved as a member of the VO. However, until they are approved (and become a member of the VO), they will not be recognised by ILDG resources. This is a point of confusion that has led to membership applications being delayed in the past. - Only the nominated representative (and the VO administrators) receive notification of a membership application. A decision on an application may therefore be delayed if, for example, the representative is away from their email. On a related note, only the nominated representative (and the VO administrators) can approve an application. Even if an application is noted by another representative (for the same regional grid), they cannot approve it. Note that a VO Administrator can change the nominated representative. - Once an application is approved, the status change is quickly propagated to the VOMS service. However, it may take more time for regional grid services to support access for new members since they pull the VO membership lists at non-specified time intervals (ranging from once per hour to once per day). - A user has to register again with the VO if either his DN or the DN of the CA that issued the certificate has changed. References ---------- [1] VOMS -- http://infnforge.cnaf.infn.it/projects/voms [2] VOMRS -- http://www.uscms.org/SoftwareComputing/Grid/VO/
