Friday, August 29, 2014

GOC Ticket Emergency Maintenance 21:00-21:30 UTC

There will be a service impacting outage on GOC Ticket today, August 29 2014, between 21:00-21:30 UTC.

We are very sorry for the inconvenience. Please do not submit or update any tickets during this window. Please do not submit, issue or approve any cert requests, which are linked to tickets.

Wednesday, August 20, 2014

GOC Service Update - Tuesday, August 26th at 13:00 UTC

The GOC will upgrade the following services beginning Tuesday, August 26th, 2014 at 13:00 UTC. The GOC reserves 8 hours in the unlikely event that unexpected problems are encountered.

OSG Web Hosts (web1/
- Adding redirection (OIM-11)

OIM 3.34
- Reverting to OpenJDK JVM in order to correct issues such as invalid PKCS12 export.
- Fixed incorrect filename used for user cert CSR export
- Fixed incorrectly placed tooltip content for GridAdmin enrollment button
- Improved responsive handling of navbar.
- Added disable flag to project table (OIM-103)
- Updated VO / SC / CG and Project servlet to hide disabled (removed) record if the user is non admin, and if the user doesn't have edit access.
- Updated friendlyname attribute on PKCS12 to use user certificate DN (OIM-87)
- Increased the possible size of key for semi-static config table.

GOC Ticket 1.79
- Reimplemented ticket assignment logic administration page. Updated NextAssignee logic to use assignment table. (TICKET-17)
- Fixed an issue where solr autocomplete search is returning duplicate research result (TICKET-97)
- Pathed PHP notice for missing ticket_type.
- Added IP prefix for IPV6 (both eth0 and eth1) for GOC VLAN.
- Fixed the Security label issue on ticket viewer (it wasn't using the correct bootstrap class).
- Made the ticket ID displayed on "Successfully updated ticket XXX" to be a HTML link
- Added SUBMITTER metadata to BulkresourceController
- The GOC will upgrade the following services beginning Tuesday, August 26th, 2014 at 13:00 UTC. The GOC reserves 8 hours in the unlikely event that unexpected problems are encountered.

Blogs, GratiaWeb
- Moving host certificates to standard location

GratiaWeb 1.2-29
- Upgrading to osg-measurments-metrics-db/web 1.2-29
- Kernel updates at FNAL, outage expected to be brief.

MyOSG 2.25
- Improved responsiveness of navbar and simplified the homepage title (to make it handle responsive layout better)
- Fixed various issues on support center summary page. Index based query update wasn't working, active filter was still present, and active menu indicator wasn't working. Updated various URLs displayed on search result to use index based query.
- Removed unused css file.
- Removed legacyosgwebsiteview Action from scsummary; page that referenced it no longer exists.
- Added project table to myosg search.
- Added disable flag filtering on project model
- Added deprecation announcements for various perfsonar pages

Tuesday, August 12, 2014

Announcing OSG Software versions 3.2.14 and 3.1.38

We are pleased to announce OSG Software versions 3.2.14 and 3.1.38.

OSG 3.2.14 contains:
* GlideinWMS (update from version 3.2.3)
* Many improvements to HTCondor CE (including changes to OSG Configure and RSV)

OSG 3.2.14 ang 3.1.38 contain:
* VO Package v56
* other minor improvements to OSG Configure, GIP, and GridFTP

Release notes and pointers to more documentation can be found at:

Need help? Let us know:

We welcome feedback on this release!

Thursday, August 7, 2014

GOC Service Update - Tuesday, August 12th at 13:00 UTC

The GOC will upgrade the following services beginning Tuesday, August 12th, 2014 at 13:00 UTC. The GOC reserves 8 hours in the unlikely event that unexpected problems are encountered.

GOC Ticket

Moving to and updating release mechanism
Using yum provided php-ZendFramework (1.12.7)
Reports (
Installing OIM DB replication and pki-reports script
RSV Collector (
Upgrading to 1.14
(Tentative) Allocating more memory for tomcat to prevent mysql-connector running out of memory (pending on goc ticket 22013)

MyOSG 2.24

Switched to RPM installed Zend framework
Fixed the broken page title issue (MYOSG-75)
Added package.json for eventjs
Fixed wrong perfsonar MA URL for published mesh config
Made OIM URL configurable similar to GOC ticket
(released) Added escape around rgsummary/xml GOC Ticket title / url info.

OIM 3.33.3

PKI / Applied renewal notification update made for OSGPKI-393 on broader context. Also added CC notification suppression for user/host renewal notification. Left the host cert renewal description the same (not requested)
PKI / Refactored isIssuedX509Cert out of CertificateManager. Renamed Certificate to CertificateBase to avoid conflict with package
PKI / Made user cert pkcs12 download to not output broken pkcs12 file if it fails to create a pkcs12 object.
PKI / Added capability to revoke individual host certificates (OIM-90)
Added sam_uri field for CE service UI. Added link to the htcondor URI twiki doc (OIM-97)
PKI / Fixed host cert progress bar issue.
PKI / Fixed the SQL issue on "host certificate I approve" (OIM-98)
PKI / Added VO field on host certificate list.
Updated divrep for DivRepButton disabled support.
PKI / Made RA/GridAdmin enrollment form button disabled for admin so that they know where the buttons are (OIM-92)
Added indicator for disabled contact for ContactEditor. Also refactored various public contact list and created PersonView view with disabled contact label (OIM-91)
Various cleanups related to recent migration from svn to git
PKI / Made CNValidator to work with both user/host CN. Replaced regex test on CertRequestHostModel to use CNValidator. Renamed CNEditor to UserCNEditor to make it clear that this is for editing UserCN (not HostCN)
PKI / Applied the CNValidator on CertificateRequestHostForm.


Add FNAL, icecube repositories to oasis.

Internal DNS Security Improvement

At the request of the Indiana University Information Policy Office, the caching-only nameserver on each host at OSG Operations will be reconfigured so as to listen only to requests from localhost. Requests from hosts outside the OSG Operations LANs (other than the UIPO’s security testing servers) were already prevented by firewalls, but this will provide an extra layer of security.

IPv6 DNS Addresses

The hostnames of the OSG Operations servers will be given IPv6 addresses in addition to their existing IPv4 addresses in DNS. This is the next step in OSG Operations’ transition to supporting IPv6 in addition to IPv4. No production servers will be transitioning to full dual-stack status at this time, but this will allow us to gauge whether the presence of an IPv6 address in DNS will have any adverse effects on existing services. It is not anticipated that there will be any adverse effects.