Content of this topic is adapted from https://www.gridpp.ac.uk/wiki/Instruction_for_VO_administrators#CA_rollover by kind permission of the authors with changes for the general case.

Grid users renewing their personal certificates

If your certificate identity (the Subject or DN) changes you must register the new identity in your VO(s) to maintain access to the Grid. For example, your certificate identity will change if -

In 2006 both the CERN CA and the UK eScience CA changed their certificates so the following instructions generally apply to users of these CAs when they first renew their certificate after the changes were applied.

If there are no changes to the certificate identity when the certificate is renewed then no action is necessary at the VO.

If your certificate identity does change when the certificate is renewed then the correct action depends on the registration service software that the VO uses -

The following schematic shows in outline the workflow for a user to register a new certificate. Detailed instructions for each step are given below.

Instructions for users of VOs using the VOMS-Admin registration interface

You have to register again. This process effectively creates a new user in the VO.

With the *new* certificate loaded in your browser, go to the VO Registration page and submit a new request to join the VO. The VO Admin will then approve (or deny) the new request.

The VO registration page is a URL like https://VOMS_Server:8443/voms/VOname/webui/request/user/create where VOMS_Server and VOname need to be replaced with the correct host address and VO name. For example, users of the Biomed VO should go to URL https://voms-biomed.in2p3.fr:8443/voms/biomed/webui/request/user/create. Note that -

Instructions for users of VOs using the VOMRS registration interface

There are 2 ways depending on your old certificate having expired or not. In both cases the entry point is the registration page for the VO: https://VOMRS_Server:8443/vo/VOname/vomrs where VOMS_Server and VOname need to be replaced with the correct host address and VO name. Common large VOMRS VO links to be used are ATLAS ALICE CMS LHCb DTEAM

Instructions for VO Managers.

These instructions only apply to VOMRS VO administrators -

Comprehensive help is available at the "Help about.." link on the Registration Homepage

Attachments

regCert.vsd



Grid users renewing their personal certificates (last edited 2006-12-11 14:33:30 by IanNeilson)