Skip to content

webserver should write temp tokens, credmon should move and own tokens #11

Open
@jasoncpatton

Description

@jasoncpatton

The webserver should never run as root, but we should secure user's tokens by owning them as root (or HTCondor's real uid). The credmon should be forked by the credd, so it will be running as the correct uid. Current idea: The webserver writes tokens to a temp directory and then pings the credmon (how?) to move and own the tokens into the SEC_CREDENTIAL_DIRECTORY.

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions