Uploaded image for project: 'Pegasus'
  1. Pegasus
  2. PM-1946

Improve Auth Token Acquisition For Globus Transfers

XMLWordPrintable

    • Type: Icon: Improvement Improvement
    • Resolution: Unresolved
    • Priority: Icon: Major Major
    • 5.1.0, 5.0.8
    • Affects Version/s: 5.0.7
    • Component/s: CLI: pegasus-transfer
    • None

      To accommodate Globus transfers, users can authorize Pegasus via "pegasus-globus-online-init" to execute transfers between Globus endpoints/collections.

      However, new requirements have been introduced to some sites for authentication while using the Globus transfer service, and the tokens acquired by "pegasus-globus-online-init" do not meet all the requirements.

      An example is OLCF where they require users to "sign" the token against their domain identity. If the token hasn't been linked with the required domain identity then transfers fail with the following error. 

      "None of your identities are from domains allowed by resource policies"

      Some more background on this can be find on Globus Docs:

            Assignee:
            georgpap George Papadimitriou
            Reporter:
            georgpap George Papadimitriou
            Watchers:
            3 Start watching this issue

              Created:
              Updated: