Bug 662598 - [RFE] authenticate user ability to work with jobs in condor via qmf
Summary: [RFE] authenticate user ability to work with jobs in condor via qmf
Keywords:
Status: CLOSED DUPLICATE of bug 756534
Alias: None
Product: Red Hat Enterprise MRG
Classification: Red Hat
Component: condor-qmf
Version: 1.3
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: 2.1
: ---
Assignee: Pete MacKinnon
QA Contact: MRG Quality Engineering
URL:
Whiteboard:
Depends On: 649919
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-12-13 10:33 UTC by Martin Kudlej
Modified: 2012-06-22 20:18 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-11-23 20:56:25 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Bugzilla 644041 1 None None None 2021-01-20 06:05:38 UTC

Internal Links: 644041

Description Martin Kudlej 2010-12-13 10:33:43 UTC
Description of problem:
Now only authenticated user "cumin" can work with Condor QMF jobs, see bug 644041. I think all authenticated users in broker should work(Submit/Hold/Remove/Release) with Condor QMF jobs without QUEUE_ALL_USERS_TRUSTED=True in Condor configuration.

Version-Release number of selected component (if applicable):
MRG 1.3.0.1

How reproducible:
100%

 
Actual results:
Only authenticated user "cumin" can work with Condor QMF jobs.

Expected results:
All authenticated broker users can work with Condor QMF jobs.

Comment 2 Pete MacKinnon 2011-02-02 00:04:16 UTC
We need proper QMF agent-side ACL for this to be properly implemented in the 2.0 timeframe.

Ted, any thoughts or update on this?

Comment 4 Matthew Farrellee 2011-11-22 02:02:25 UTC
QUEUE_ALL_USERS_TRUSTED=TRUE is not necessary, see bug 644041. Authentication is performed by the broker and authorization by the Scheduler object. Current (7.6.5-0.7) authorization restricts access to the "cumin" user only. If this was intended to be an RFE to allow authorization of users beyond "cumin", please open a BZ describing that. Also, note that implementation of such a feature should occur in the QMF library and currently depends on bug 649919.


Note You need to log in before you can comment on or make changes to this bug.