LoginTutorial: Difference between revisions

From Mu2eWiki
Jump to navigation Jump to search
(Created page with " *kinit *kx509 *vomsCert *machine tour *disk tour Category:Computing Category:Tutorial")
 
No edit summary
Line 1: Line 1:
To login to the central machines at Fermilab, you will need first need your [[ComputingAccounts|accounts created]].  This process may take a day or wo, and will result in three authentications:
* kerberos used for loggins into central machines, among others
* a services account for email, servicedesk and other uses
* CILogin certificate, for submitting jobs, transferring and uploading data
You can read more about this at [[Authentication]], which you should at least scan before continuing.
If you are sitting at a Fermilab linux computer, you can use your kerberos login at the login screen.  If you are at a university computer with kerberos installed, you may or may not be able to obtain your kerberos authentication.  If you are already on a Fermilab desktop or a Mu2e central computer, you can get this authentication with:
kinit <your user name>@FNAL.GOV
If you have problems, please look through [[Authentication]] and the links it points to, in particular, if you are on a University machine, you might need to configure kerberos with a new krb5.conf file. 
If you are on a windows laptop, you will want to install [[ComputingLogin#Logging_in_From_PC.27s|Putty and xming]].  If you are on a Mac, see [[ComputingLogin#Logging_in_from_Linux_or_Mac.27s|Mac's]].
You probably want to try out your email, by going to email.fnal.gov and putting in your services password.  Some official communications are sent only to this address so check it regularly or forward it to a preferred account.
OK, from here on we will assume you are on a central machine.
You can see your ticket with the '''klist''' command:
<pre>
> klist
Ticket cache: FILE:/tmp/krb5cc_1311_xShHU10541
Default principal: rlc@FNAL.GOV
Valid starting    Expires            Service principal
06/18/19 12:58:54  06/19/19 14:58:50  krbtgt/FNAL.GOV@FNAL.GOV
        renew until 06/25/19 12:58:50
</pre>
If you stay logged on overnight, it will expire and you will need to renew it with '''kinit'''.
You can use your kerberos identity to invoke your certifcate identity with '''kx509''.
<pre>
> kx509
Authorizing ...... authorized
Fetching certificate ..... fetched
Storing certificate in /tmp/x509up_u1311
Your certificate is valid until: Tue Jun 25 13:18:18 2019
</pre>
[https://fermi.service-now.com/kb_view.do?sysparm_article=KB0011548 download] your cert into your browsers.


*kinit
*kinit

Revision as of 18:18, 18 June 2019

To login to the central machines at Fermilab, you will need first need your accounts created. This process may take a day or wo, and will result in three authentications:

  • kerberos used for loggins into central machines, among others
  • a services account for email, servicedesk and other uses
  • CILogin certificate, for submitting jobs, transferring and uploading data

You can read more about this at Authentication, which you should at least scan before continuing.

If you are sitting at a Fermilab linux computer, you can use your kerberos login at the login screen. If you are at a university computer with kerberos installed, you may or may not be able to obtain your kerberos authentication. If you are already on a Fermilab desktop or a Mu2e central computer, you can get this authentication with:

kinit <your user name>@FNAL.GOV

If you have problems, please look through Authentication and the links it points to, in particular, if you are on a University machine, you might need to configure kerberos with a new krb5.conf file.

If you are on a windows laptop, you will want to install Putty and xming. If you are on a Mac, see Mac's.

You probably want to try out your email, by going to email.fnal.gov and putting in your services password. Some official communications are sent only to this address so check it regularly or forward it to a preferred account.

OK, from here on we will assume you are on a central machine.

You can see your ticket with the klist command:

 > klist
Ticket cache: FILE:/tmp/krb5cc_1311_xShHU10541
Default principal: rlc@FNAL.GOV

Valid starting     Expires            Service principal
06/18/19 12:58:54  06/19/19 14:58:50  krbtgt/FNAL.GOV@FNAL.GOV
        renew until 06/25/19 12:58:50

If you stay logged on overnight, it will expire and you will need to renew it with kinit.

You can use your kerberos identity to invoke your certifcate identity with 'kx509.

 > kx509
Authorizing ...... authorized
Fetching certificate ..... fetched
Storing certificate in /tmp/x509up_u1311
Your certificate is valid until: Tue Jun 25 13:18:18 2019

download your cert into your browsers.

  • kinit
  • kx509
  • vomsCert
  • machine tour
  • disk tour