Skip to content

[9.0] Improved error messages when dirac-proxy-init fails - #8818

Open
chrisburr wants to merge 2 commits into
DIRACGrid:rel-v9r0from
chrisburr:feat/proxy-init-debug-user
Open

chrisburr wants to merge 2 commits into
DIRACGrid:rel-v9r0from
chrisburr:feat/proxy-init-debug-user

Conversation

@chrisburr

Copy link
Copy Markdown
Member

BEGINRELEASENOTES

*Core
NEW: Improved error messages when dirac-proxy-init fails

ENDRELEASENOTES

…ation errors

dirac-admin-debug-user looks up a user by certificate DN, username, CERN
account, email or CERN person ID and reports common registry problems
(CA mismatch, no groups, suspension, expiring affiliation and, with the
ProxyManagement property, uploaded proxies). If there is no exact match
similar users are shown, matching on CERN person ID/account and name
similarity. As an unregistered user cannot query the CS, it is intended
to be run by a colleague on behalf of the user.

dirac-proxy-init now prints the certificate subject and issuer together
with the corresponding dirac-admin-debug-user command when the DN is not
registered or VOMS refuses to issue an AC. In --strict mode the VOMS
error was also printed twice, it is now only printed once.
Operations/<vo>/ProxyInit/NotRegisteredMessage and VOMSFailureMessage
are shown when the DN is not registered or VOMS refuses to give an AC,
for example to link to the VO's documentation. As CFG values can't span
multiple lines "\n" is replaced with a line break.
@aldbr
aldbr force-pushed the feat/proxy-init-debug-user branch from c50f27b to 364eeaa Compare October 9, 2026 06:30

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant