<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://leo.leung.xyz/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=174.241.28.194</id>
	<title>Leo&#039;s Notes - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://leo.leung.xyz/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=174.241.28.194"/>
	<link rel="alternate" type="text/html" href="https://leo.leung.xyz/wiki/Special:Contributions/174.241.28.194"/>
	<updated>2026-10-06T08:37:57Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://leo.leung.xyz/wiki/index.php?title=Self_Signed_SSL_Certificates&amp;diff=6614</id>
		<title>Self Signed SSL Certificates</title>
		<link rel="alternate" type="text/html" href="https://leo.leung.xyz/wiki/index.php?title=Self_Signed_SSL_Certificates&amp;diff=6614"/>
		<updated>2022-02-06T21:51:59Z</updated>

		<summary type="html">&lt;p&gt;174.241.28.194: /* See Also */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Self signed SSL certificates can be generated using [[OpenSSL]].&lt;br /&gt;
&lt;br /&gt;
== Steps ==&lt;br /&gt;
=== Private Key ===&lt;br /&gt;
Generate a new private key. The output will be a Privacy-Enhanced Mail (PEM) format.&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
## Generate a new private key&lt;br /&gt;
# openssl genrsa -out server.key 4096&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=== Certificate Signing Request ===&lt;br /&gt;
Generate the certificate signing request.&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl req -new -sha256 \&lt;br /&gt;
        -key server.key \&lt;br /&gt;
        -subj &amp;quot;/C=CA/ST=Alberta/O=Steamr/CN=steamr.com&amp;quot; \&lt;br /&gt;
        -reqexts SAN \&lt;br /&gt;
        -extensions SAN \&lt;br /&gt;
        -config &amp;lt;(cat /etc/ssl/openssl.cnf &amp;lt;(printf &amp;quot;[SAN]\nsubjectAltName=DNS:x.steamr.com,DNS:y.steamr.com&amp;quot;)) \&lt;br /&gt;
        -out server.csr&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
The {{code|-subj}} value contains:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Field !! Description !! Example&lt;br /&gt;
|-&lt;br /&gt;
| C || Country - The 2 letter International Standards Organization ISO abbreviation for your country || CA&lt;br /&gt;
|-&lt;br /&gt;
| ST || State - The state or province of your organization || Alberta&lt;br /&gt;
|-&lt;br /&gt;
| O || Organization - The legal name of the organization || Steamr Corp.&lt;br /&gt;
|-&lt;br /&gt;
| CN || Common Name - The fully qualified domain name for the certificate || steamr.com&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Additionally, the {{code|[SAN]}} section passed in through the {{code|-config}} flag is used to define any SANs the certificate should have and can be removed if unneeded.&lt;br /&gt;
&lt;br /&gt;
You can verify your CSR using:&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl req -noout -text -in server.csr&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
After you have verified your CSR, you can either continue to self sign with the next step, or submit it to a CA to purchase a SSL certificate.&lt;br /&gt;
&lt;br /&gt;
=== Signing ===&lt;br /&gt;
Sign your certificate signing request.&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl x509 \&lt;br /&gt;
        -req \&lt;br /&gt;
        -days 730 \&lt;br /&gt;
        -extfile &amp;lt;(printf &amp;quot;subjectAltName=DNS:x.steamr.com,DNS:y.steamr.com&amp;quot;) \&lt;br /&gt;
        -signkey server.key \&lt;br /&gt;
        -in server.csr \&lt;br /&gt;
        -out server.crt&lt;br /&gt;
}}&lt;br /&gt;
The {{code|-days}} value defines the number of days the certificate will be valid for from the time of signing. If not given, a default of 30 days will be used. &lt;br /&gt;
&lt;br /&gt;
Any SANs will also need to be passed through using the {{code|-extfile}} flag.&lt;br /&gt;
&lt;br /&gt;
You can verify the signed certificate by running:&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl x509 -noout -text -in server.crt&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=== Renewing ===&lt;br /&gt;
If the certificate has expired, you can &#039;renew&#039; it by first regenerating a certificate signing request (CSR):&lt;br /&gt;
&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl x509 -x509toreq -in expired_certificate.crt -out new_csr.csr -signkey domain_private.key&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
Then signing the CSR with the private key to produce a new certificate:&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl x509 -req -days 3650 -in new_csr.csr -signkey domain_private.key -out new_certificate.crt&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
Replace the expired certificate with the new certificate and reload any services that are using the certificate for it to be applied.&lt;br /&gt;
&lt;br /&gt;
== Trusting Your Self Signed SSL Certificates ==&lt;br /&gt;
The key and certificate generated with the steps above will not be signed by a trusted certificate authority and therefore cannot be verified by your browser, resulting in a security warning. To get around this, you can add your certificate directly into your browser or operating system&#039;s list of trusted certificate authorities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== See Also ==&lt;br /&gt;
* [[OpenSSL]-most-common-openssl-commands.html&lt;br /&gt;
&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>174.241.28.194</name></author>
	</entry>
	<entry>
		<id>https://leo.leung.xyz/wiki/index.php?title=OpenSSL&amp;diff=6613</id>
		<title>OpenSSL</title>
		<link rel="alternate" type="text/html" href="https://leo.leung.xyz/wiki/index.php?title=OpenSSL&amp;diff=6613"/>
		<updated>2022-02-06T21:47:55Z</updated>

		<summary type="html">&lt;p&gt;174.241.28.194: /* Verification */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;OpenSSL allows you to create, modify, and view certificates and private keys. You can use it to generate [[Self Signed SSL Certificates]].&lt;br /&gt;
&lt;br /&gt;
==General OpenSSL Commands==&lt;br /&gt;
&lt;br /&gt;
=== Generate Keys and Certificate Signing Requests ===&lt;br /&gt;
These commands allow you to generate CSRs, Certificates, Private Keys and do other miscellaneous tasks.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!Task&lt;br /&gt;
!Command&lt;br /&gt;
|-&lt;br /&gt;
|Generate a new private key&lt;br /&gt;
|{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl req -out CSR.csr -new -newkey rsa:2048 -nodes -keyout privateKey.key&lt;br /&gt;
}}Or just a 4096 bit RSA:{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl genrsa -out server.key 4096&lt;br /&gt;
}}&lt;br /&gt;
|-&lt;br /&gt;
|Generate a new private key and Certificate Signing Request&lt;br /&gt;
|{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout privateKey.key -out certificate.crt&lt;br /&gt;
}}&lt;br /&gt;
|-&lt;br /&gt;
|Generate a certificate signing request with an existing private key&lt;br /&gt;
|{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl req -out CSR.csr -key privateKey.key -new&lt;br /&gt;
}}&lt;br /&gt;
|-&lt;br /&gt;
|Generate a certificate signing request based on an existing certificate&lt;br /&gt;
|{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl x509 -x509toreq -in certificate.crt -out CSR.csr -signkey privateKey.key&lt;br /&gt;
}}&lt;br /&gt;
|-&lt;br /&gt;
|Generate a certificate signing request for various SANs.&lt;br /&gt;
|{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl req -new -sha256 \&lt;br /&gt;
        -key server.key \&lt;br /&gt;
        -subj &amp;quot;/C=CA/ST=Alberta/O=Steamr/CN=steamr.com&amp;quot; \&lt;br /&gt;
        -reqexts SAN \&lt;br /&gt;
        -extensions SAN \&lt;br /&gt;
        -config &amp;lt;(cat /etc/ssl/openssl.cnf &amp;lt;(printf &amp;quot;[SAN]\nsubjectAltName=DNS:x.steamr.com,DNS:y.steamr.com&amp;quot;)) \&lt;br /&gt;
        -out server.csr&lt;br /&gt;
}}&lt;br /&gt;
|-&lt;br /&gt;
|Remove a passphrase from a private key&lt;br /&gt;
|{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl rsa -in privateKey.pem -out newPrivateKey.pem&lt;br /&gt;
}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Verification ===&lt;br /&gt;
{| class&lt;br /&gt;
!Task&lt;br /&gt;
!Command&lt;br /&gt;
|-&lt;br /&gt;
|View a PEM certificate&lt;br /&gt;
|{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl x509 -in certificate.crt -text -noout&lt;br /&gt;
}}&lt;br /&gt;
|-&lt;br /&gt;
|Check a PKCS#12 file (.pfx or .p12)&lt;br /&gt;
|{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl pkcs12 -info -in keyStore.p12&lt;br /&gt;
}}&lt;br /&gt;
|-&lt;br /&gt;
|View a certificate signing request&lt;br /&gt;
|{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl req -text -noout -verify -in CSR.csr&lt;br /&gt;
}}&lt;br /&gt;
|-&lt;br /&gt;
|Check a private key&lt;br /&gt;
|{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl rsa -in privateKey.key -check&lt;br /&gt;
}}&lt;br /&gt;
|-&lt;br /&gt;
|Check if your certificate matches a key&lt;br /&gt;
|{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl x509 -noout -modulus -in certificate.crt | openssl md5&lt;br /&gt;
# openssl rsa -noout -modulus -iopenssl md5&lt;br /&gt;
}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Checking &amp;amp; Verifying==&lt;br /&gt;
If you are receiving an error that the private doesn&#039;t match the certificate or that a certificate that you installed to a site is not trusted, try one of these commands. It might be a good idea to use an online SSL checker service as well to determine what issues that are with the installed certificate.&lt;br /&gt;
&lt;br /&gt;
The public key should match your private key and must be used in your certificate and certificate signing request. You can verify this by running:&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl x509 -noout -modulus -in certificate.crt | openssl md5&lt;br /&gt;
# openssl rsa -noout -modulus -in privateKey.key | openssl md5&lt;br /&gt;
# openssl req -noout -modulus -in CSR.csr | openssl md5&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
===Remote Server Certificate===&lt;br /&gt;
All the certificates (including Intermediates) should be displayed when using {{code|s_client}}.&lt;br /&gt;
&lt;br /&gt;
SNI allows virtual hosting of multiple domains on the same IP address. It is a mechanism that allows the web server to know which domain is being accessed in order to use the proper certificate when establishing a connection to the client.  For websites that have been assigned a dedicated IP address, using SNI is not required.&lt;br /&gt;
&lt;br /&gt;
If the server is not using SNI:&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl s_client -showcerts -connect www.paypal.com:443&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
If the server is using SNI, you will need to provide the hostname:&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl s_client -showcerts -servername www.paypal.com -connect www.paypal.com:443&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
The x509 certificate can be retrieved in either case by piping the output through {{code| openssl x509 -text}}.&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl s_client -showcerts -connect www.paypal.com:443 | openssl x509 -text&lt;br /&gt;
# openssl s_client -showcerts -servername www.paypal.com -connect www.paypal.com:443 | openssl x509 -text&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
==Certificate and Key Conversion==&lt;br /&gt;
These commands allow you to convert certificates and keys to different formats to make them compatible with specific types of servers or software. For example, you can convert a normal PEM file that would work with Apache to a PFX (PKCS#12) file and use it with Tomcat or IIS. Use our SSL Converter to convert certificates without messing with OpenSSL.&lt;br /&gt;
&lt;br /&gt;
Convert a DER file (.crt .cer .der) to PEM&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl x509 -inform der -in certificate.cer -out certificate.pem&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
Convert a PEM file to DER&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl x509 -outform der -in certificate.pem -out certificate.der&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
Convert a PKCS#12 file (.pfx .p12) containing a private key and certificates to PEM&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl pkcs12 -in keyStore.pfx -out keyStore.pem -nodes&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
You can add {{code|-nocerts}} to only output the private key or add {{code|-nokeys}} to only output the certificates.&lt;br /&gt;
&lt;br /&gt;
Convert a PEM certificate file and a private key to PKCS#12 (.pfx .p12)&lt;br /&gt;
{{highlight|lang=terminal|code=&lt;br /&gt;
# openssl pkcs12 -export -out certificate.pfx -inkey privateKey.key -in certificate.crt -certfile CACert.crt&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
&lt;br /&gt;
*https://www.sslshopper.com/article-most-common-openssl-commands.html&lt;br /&gt;
*[[Self Signed SSL Certificates]]&lt;br /&gt;
&lt;br /&gt;
{{Navbox Linux}}&lt;br /&gt;
[[Category:Linux]]&lt;br /&gt;
[[Category:LinuxUtilities]]&lt;br /&gt;
[[Category:Certificates]]&lt;br /&gt;
{{Navbox Certificates}}&lt;/div&gt;</summary>
		<author><name>174.241.28.194</name></author>
	</entry>
	<entry>
		<id>https://leo.leung.xyz/wiki/index.php?title=Open_OnDemand&amp;diff=6612</id>
		<title>Open OnDemand</title>
		<link rel="alternate" type="text/html" href="https://leo.leung.xyz/wiki/index.php?title=Open_OnDemand&amp;diff=6612"/>
		<updated>2022-02-06T21:46:28Z</updated>

		<summary type="html">&lt;p&gt;174.241.28.194: /* 400 - Bad Request */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Open OnDemand is a open source project by the Ohio Supercomputer Center that provides a web portal for HPC users. It is designed as a platform allowing system administrators to add additional modules or &#039;apps&#039;. Users can use this platform to launch interactive jobs or VNC/SSH sessions, view their job statuses, interact with their files. It supports a variety of authentication mechanisms including federated authentication (OpenID, CAS, Shiboleth) or with an the system&#039;s underlying PAM (ldap, password file, etc.).&amp;lt;br /&amp;gt;&lt;br /&gt;
==Interactive Apps==&lt;br /&gt;
===App Development===&lt;br /&gt;
On Open OnDemand 1.8, you can only enable a specific user access to development mode by creating a directory &amp;lt;code&amp;gt;/var/www/ood/apps/dev/$username&amp;lt;/code&amp;gt;, then symlinking &amp;lt;code&amp;gt;/var/www/ood/apps/dev/$username/gateway&amp;lt;/code&amp;gt; to &amp;lt;code&amp;gt;/home/$username/openondemand/dev&amp;lt;/code&amp;gt;. Restart the PUN web server. A &#039;Develop&#039; section should appear in the navbar. This will only work for &amp;lt;code&amp;gt;$username&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
See: https://osc.github.io/ood-documentation/latest/app-development/enabling-development-mode.html#enable-in-ondemand-v1-6&lt;br /&gt;
&lt;br /&gt;
It may help to look at other apps that are available at:&lt;br /&gt;
&lt;br /&gt;
*https://osc.github.io/ood-documentation/latest/install-ihpc-apps.html&lt;br /&gt;
*https://code.osu.edu/ondemand&lt;br /&gt;
&lt;br /&gt;
====Deploying an app====&lt;br /&gt;
Once you have done developing an app, deploy it by moving it to &amp;lt;code&amp;gt;/var/www/ood/apps/sys&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
===Jupyter Notebooks===&lt;br /&gt;
Running a Jupyter Notebook interactive app requires tweaking the example OSC Jupyter Interactive App (https://github.com/OSC/bc_example_jupyter) to work in your environment. Before you get started, you should be able to submit jobs via Open OnDemand. If this isn&#039;t working, fix your configuration before proceeding with interactive apps. &lt;br /&gt;
&lt;br /&gt;
The easiest way to get this working is to enable App Development on an account and then testing from this account. &lt;br /&gt;
&lt;br /&gt;
#Enable App Development on your account&lt;br /&gt;
#Clone the OSC Jupyter app to &amp;lt;code&amp;gt;~/ondemand/dev/bc_example_jupyter&amp;lt;/code&amp;gt;&lt;br /&gt;
#Tweak the &amp;lt;code&amp;gt;form.yml&amp;lt;/code&amp;gt; (or &amp;lt;code&amp;gt;form.yml.erb&amp;lt;/code&amp;gt;). Add or remove fields as required by you.&lt;br /&gt;
#Tweak &amp;lt;code&amp;gt;submit.yml.erb&amp;lt;/code&amp;gt; to work in your environment.&lt;br /&gt;
#Try launching a Jupyter notebook and fix any issues as you go.&lt;br /&gt;
&lt;br /&gt;
===Remote Desktop===&lt;br /&gt;
&lt;br /&gt;
====Setup====&lt;br /&gt;
Clone one of the existing &amp;lt;code&amp;gt;bc_desktop&amp;lt;/code&amp;gt; apps and edit &amp;lt;code&amp;gt;form.yml&amp;lt;/code&amp;gt;. Set the cluster value to a cluster you have configured in OnDemand (hint: what you have in the &amp;lt;code&amp;gt;clusters.d&amp;lt;/code&amp;gt; directory). You may want to add/remove the CPU, memory, partition fields as desired. The default bc_desktop app includes startup scripts for various desktop managers but I hardcoded this to always use XFCE for my use-case.&lt;br /&gt;
On the compute nodes that are intended to run the VNC sessions, you install the desktop environment (XFCE in my case), TurboVNC, and websockify. On a CentOS 8 machine, this was accomplished manually with:&lt;br /&gt;
&lt;br /&gt;
{{Highlight&lt;br /&gt;
| code = yum install -y nc wget python3-devel python3-pip;&lt;br /&gt;
&lt;br /&gt;
# Websockify&lt;br /&gt;
pip3 install websockify;&lt;br /&gt;
&lt;br /&gt;
# TurboVNC&lt;br /&gt;
wget https://turbovnc.org/pmwiki/uploads/Downloads/TurboVNC.repo;&lt;br /&gt;
mv TurboVNC.repo /etc/yum.repos.d/;&lt;br /&gt;
yum install -y turbovnc ;&lt;br /&gt;
&lt;br /&gt;
# Desktop DM&lt;br /&gt;
yum -y install epel-release;&lt;br /&gt;
yum -y group install &amp;quot;Xfce&amp;quot; &amp;quot;base-x&amp;quot;&lt;br /&gt;
| lang = terminal&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
If everything works correctly, requesting for a desktop will submit a job via the scheduler which launches Xvnc and proxies it via websockify to OnDemand which then renders it via noVNC. &lt;br /&gt;
&lt;br /&gt;
====VirtualGL====&lt;br /&gt;
The setup that was described above will render everything via software rendering (mesa), which you can confirm with &amp;lt;code&amp;gt;glxinfo&amp;lt;/code&amp;gt;. For nodes that have dedicated GPUs, it might be desirable to have the desktop take advantage of hardware acceleration. This can be accomplished using VirtualGL which will draw the user&#039;s application on a local X11 server using hardware acceleration and then copies the rendered output to the user&#039;s virtual VNC display.&lt;br /&gt;
&lt;br /&gt;
I currently have nodes set up so that users may request for 0 or 1 GPUs. If no GPUs are requested, the desktop is rendered using a GPU that is shared with other users on the node. If 1 GPU is requested, the desktop is rendered on a dedicated GPU for that user.&lt;br /&gt;
&lt;br /&gt;
To accomplish this, I had to:&lt;br /&gt;
&lt;br /&gt;
#On Slurm, setup cgroups and a gres for GPUs&lt;br /&gt;
#Make all but the first GPU a gres. This will permit all users to see the first GPU and any other GPUs requested by the job&lt;br /&gt;
#Start X11 on the compute nodes on each GPU. Each Xorg server should target a specific GPU (done so via specific Screen/Device sections in &amp;lt;code&amp;gt;xorg.conf&amp;lt;/code&amp;gt;)&lt;br /&gt;
#Change the script that starts the display manager (like XFCE) so that it loads the xauth cookies for the X11 server corresponding to the assigned GPU and run the display manager with &amp;lt;code&amp;gt;vglrun&amp;lt;/code&amp;gt; with the appropriate &amp;lt;code&amp;gt;VGL_DISPLAY&amp;lt;/code&amp;gt; environment set.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Troubleshooting====&lt;br /&gt;
Here are some issues I ran into. In hindsight, some of them are trivial but hopefully it helps someone.&lt;br /&gt;
&lt;br /&gt;
=====No cluster set=====&lt;br /&gt;
Out of the box, trying to make a desktop results in:{{Quote|quote=The cluster was never set. Either set it in form.yml.erb with `cluster` or `form.cluster` or set `cluster` in submit.yml.erb.&lt;br /&gt;
&lt;br /&gt;
* The Desktop session data for this session can be accessed under the staged root directory.|sign=|source=}}&lt;br /&gt;
You need to tweak the form to work in your environment. You need to edit either define the cluster value in &amp;lt;code&amp;gt;/var/www/ood/apps/sys/bc_desktop/form.yml&amp;lt;/code&amp;gt; or launch your own interactive app. &lt;br /&gt;
&lt;br /&gt;
=====bc_vnc_resolution is not showing=====&lt;br /&gt;
If your &amp;lt;code&amp;gt;bc_vnc_resolution&amp;lt;/code&amp;gt; form field isn&#039;t showing, it&#039;s most likely that you have &amp;lt;code&amp;gt;ENABLE_NATIVE_VNC&amp;lt;/code&amp;gt; set which lets the VNC client to resize the desktop.&lt;br /&gt;
&lt;br /&gt;
=====VNC: Failed to connect to server=====&lt;br /&gt;
Launching the VNC session opens noVNC. However, I got &amp;quot;Failed to connect to server&amp;quot;. Error from apache logs show: &lt;br /&gt;
{{Highlight&lt;br /&gt;
| code = ==&amp;gt; httpd/error.log &amp;lt;==                                                                                                                                                       &lt;br /&gt;
[Fri Jan 22 03:12:49.324498 2021] [proxy:error] [pid 5386:tid 140231151974144] (111)Connection refused: AH00957: WS: attempt to connect to 172.28.0.5:32316 (*) failed        &lt;br /&gt;
[Fri Jan 22 03:12:49.324540 2021] [proxy_wstunnel:error] [pid 5386:tid 140231151974144] [client 136.159.79.128:54416] AH02452: failed to make connection to backend: c2&lt;br /&gt;
| lang = text&lt;br /&gt;
}}&lt;br /&gt;
which is weird because c2 is actually listening on port 5901 not 32316. The job output however clearly shows the websockify binary not being found. Fixing this fixed the VNC connection issue.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Solution&#039;&#039;&#039;: Ensure websockify is found. If it&#039;s installed in a nonstandard location, tweak your &amp;lt;code&amp;gt;clusters.d&amp;lt;/code&amp;gt; yaml file so that the batch_connect/vnc has a script_wrapper that exports the websockify path as &amp;lt;code&amp;gt;WEBSOCKIFY_CMD&amp;lt;/code&amp;gt;.&lt;br /&gt;
{{Highlight&lt;br /&gt;
| code = batch_connect:&lt;br /&gt;
    basic:&lt;br /&gt;
      script_wrapper: {{!}}&lt;br /&gt;
        %s&lt;br /&gt;
      set_host: &amp;quot;host=$(hostname -A {{!}} awk &#039;{print $1}&#039;)&amp;quot;&lt;br /&gt;
    vnc:&lt;br /&gt;
      # websockify by pip3 is in /usr/local/bin&lt;br /&gt;
      script_wrapper: {{!}}&lt;br /&gt;
        module purge&lt;br /&gt;
        export PATH=&amp;quot;/opt/TurboVNC/bin:$PATH&amp;quot;&lt;br /&gt;
        export WEBSOCKIFY_CMD=&amp;quot;/usr/local/bin/websockify&amp;quot;&lt;br /&gt;
        %s&lt;br /&gt;
      set_host: &amp;quot;host=$(hostname -A {{!}} awk &#039;{print $1}&#039;)&amp;quot;&lt;br /&gt;
| lang = yaml&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
=====No Home Environment Error=====&lt;br /&gt;
{{Highlight&lt;br /&gt;
| code = Setting VNC password...&lt;br /&gt;
Error: no HOME environment variable&lt;br /&gt;
Starting VNC server...&lt;br /&gt;
vncserver: The HOME environment variable is not set.&lt;br /&gt;
vncserver: The HOME environment variable is not set.&lt;br /&gt;
vncserver: The HOME environment variable is not set.&lt;br /&gt;
vncserver: The HOME environment variable is not set.&lt;br /&gt;
vncserver: The HOME environment variable is not set.&lt;br /&gt;
| lang = text&lt;br /&gt;
}}&lt;br /&gt;
Slurm job output showed this. It turns out, the nodes I&#039;ve set up didn&#039;t have the user account so it didn&#039;t know what the user&#039;s home directory is.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Solution&#039;&#039;&#039;: Ensure your system has the user account.&lt;br /&gt;
&lt;br /&gt;
===Job Composer===&lt;br /&gt;
To install it, see:&lt;br /&gt;
&lt;br /&gt;
*https://osc.github.io/ood-documentation/latest/applications/job-composer.html&lt;br /&gt;
*https://osc.github.io/ood-documentation/latest/customization.html#custom-job-composer-templates&lt;br /&gt;
&lt;br /&gt;
The actual Job Composer app is at https://github.com/OSC/ondemand/tree/master/apps/myjobs&lt;br /&gt;
&lt;br /&gt;
====CSRF Fail, resulting in &#039;The change you wanted was rejected&#039;====&lt;br /&gt;
For some reason, when trying to create a new job or new template, I get &amp;quot;The change you wanted was rejected.&amp;quot;. PUN logs show &amp;lt;code&amp;gt;FATAL &amp;quot;ActionController::InvalidAuthenticityToken (ActionController::InvalidAuthenticityToken):&amp;lt;/code&amp;gt;&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
This was only &#039;fixed&#039; by disabling CSRF by injecting &amp;lt;code&amp;gt;Rails.application.config.action_controller.forgery_protection_origin_check = false&amp;lt;/code&amp;gt; into &amp;lt;code&amp;gt;config/initializers/new_framework_defaults_5_2.rb&amp;lt;/code&amp;gt;. This is most likely caused by either Traefik (likely) or nginx doing the reverse proxy somehow causing the CSRF check to fail due to a difference in base_url. In fact, this issue prevails across all the other interactive apps and may require the same fix as well.&lt;br /&gt;
&lt;br /&gt;
See also, this issue: https://github.com/rails/rails/issues/22965.&lt;br /&gt;
&lt;br /&gt;
===Shell / Terminal Access===&lt;br /&gt;
The Shell App basically just runs a web SSH client from the Open OnDemand server. You limit which hosts it can connectt to by tweaking the env file:&lt;br /&gt;
{{Highlight&lt;br /&gt;
| code = DEFAULT_SSHHOST=&amp;quot;arc.ucalgary.ca&amp;quot;&lt;br /&gt;
OOD_SSHHOST_ALLOWLIST=&amp;quot;arc.ucalgary.ca&amp;quot;&lt;br /&gt;
| lang = text&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
====Failed to establish a websocket connection.====&lt;br /&gt;
After setting up OnDemand, I had a hard time getting the SSH app to connect. I kept on getting:&lt;br /&gt;
{{Highlight&lt;br /&gt;
| code = Failed to establish a websocket connection. Be sure you are using a browser that supports websocket connections.&lt;br /&gt;
| lang = text&lt;br /&gt;
}}&lt;br /&gt;
Debugging the socket revealed that it was getting a 401 error from PUN. At first, I thought the reverse proxy (traefik 1.7) wasn&#039;t forwarding the authentication headers, but this was a red herring. Something with the PUN application was throwing this 401 error. I verified that the node is able to SSH and that the default hostname is correct in &amp;lt;code&amp;gt;/etc/ood/config/apps/shell/env&amp;lt;/code&amp;gt;. I even tried connecting to a specific host to no avail. I then set &amp;lt;code&amp;gt;OOD_SSH_WRAPPER=/test.sh&amp;lt;/code&amp;gt; with test.sh just dumping the environment to a tmp file which showed me that it wasn&#039;t even reaching the point of calling the SSH wrapper. OOD 1.8 also requires setting the &amp;lt;code&amp;gt;OOD_SSHHOST_ALLOWLIST&amp;lt;/code&amp;gt;, but that didn&#039;t help.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Solution:&#039;&#039;&#039; This only worked after setting &amp;lt;code&amp;gt;OOD_SHELL_ORIGIN_CHECK=&#039;off&#039;&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Authentication==&lt;br /&gt;
Open OnDemand supports a number of authentication methods including plain old system authentication (based on PAM), LDAP/AD (with Dex), and federated authentication services (such as CAS, Shibboleth, OpenID).&lt;br /&gt;
&lt;br /&gt;
For more information, review the docs at https://osc.github.io/ood-documentation-test/init-2.1/authentication.html&lt;br /&gt;
&lt;br /&gt;
===Plain old PAM===&lt;br /&gt;
To have Apache handle authentication using PAM, define the following lines in &amp;lt;code&amp;gt;ood_porta.yml&amp;lt;/code&amp;gt;:&lt;br /&gt;
{{Highlight&lt;br /&gt;
| code = auth:&lt;br /&gt;
  - &#039;AuthType Basic&#039;&lt;br /&gt;
  - &#039;AuthName &amp;quot;Open OnDemand&amp;quot;&#039;&lt;br /&gt;
  - &#039;AuthBasicProvider PAM&#039;&lt;br /&gt;
  - &#039;AuthPAMService ood&#039;&lt;br /&gt;
  - &#039;Require valid-user&#039;&lt;br /&gt;
| lang = terminal&lt;br /&gt;
}}&lt;br /&gt;
When users attempt to access the OnDemand instance, they will authenticate using their web browser using basic authentication. When using this method, the user cannot log out unless they clear their browser of the basic authentication credentials.&lt;br /&gt;
&lt;br /&gt;
===OpenID===&lt;br /&gt;
To get Open OnDemand to authenticate against the Azure AD service that the University of Calgary is using:&lt;br /&gt;
&lt;br /&gt;
#Obtain the OIDC Identity Provider URL, client ID, and client secret.&lt;br /&gt;
#Install the &amp;lt;code&amp;gt;mod_auth_openidc&amp;lt;/code&amp;gt; package.&lt;br /&gt;
#Setup &amp;lt;code&amp;gt;ood_portal.yml&amp;lt;/code&amp;gt; for oidc authentication:&lt;br /&gt;
{{Highlight&lt;br /&gt;
| code = servername: &amp;quot;ood.example.com&amp;quot;&lt;br /&gt;
&lt;br /&gt;
# Use OIDC logout&lt;br /&gt;
logout_redirect: &amp;quot;/oidc/?logout=https%3A%2F%2Food.example.com&amp;quot;&lt;br /&gt;
&lt;br /&gt;
# Authentication via MS results in &#039;user@ucalgary.ca&#039; as the username&lt;br /&gt;
user_map_cmd: &amp;quot;/opt/ood/ood_auth_map/bin/ood_auth_map.regex --regex=&#039;^(.+)@ucalgary.ca&#039; &amp;quot;&lt;br /&gt;
&lt;br /&gt;
oidc_uri: &amp;quot;/oidc/&amp;quot;&lt;br /&gt;
oidc_provider_metadata_url: &amp;quot;https://login.microsoftonline.com/** Provided by MS **/v2.0/.well-known/openid-configuration&amp;quot;&lt;br /&gt;
oidc_client_id: &amp;quot;** Provided by MS **&amp;quot;&lt;br /&gt;
oidc_client_secret: &amp;quot;** Provided by MS **&amp;quot;&lt;br /&gt;
oidc_remote_user_claim: &amp;quot;preferred_username&amp;quot;&lt;br /&gt;
oidc_scope: &amp;quot;openid profile email&amp;quot;&lt;br /&gt;
oidc_session_inactivity_timeout: 28800&lt;br /&gt;
oidc_session_max_duration: 28800&lt;br /&gt;
oidc_state_max_number_of_cookies: &amp;quot;10 true&amp;quot;&lt;br /&gt;
oidc_settings:&lt;br /&gt;
  OIDCPassIDTokenAs: &amp;quot;serialized&amp;quot;&lt;br /&gt;
  OIDCPassRefreshToken: &amp;quot;On&amp;quot;&lt;br /&gt;
  OIDCPassClaimsAs: &amp;quot;environment&amp;quot;&lt;br /&gt;
  OIDCStripCookies: &amp;quot;mod_auth_openidc_session mod_auth_openidc_session_chunks mod_auth_openidc_session_0 mod_auth_openidc_session_1&amp;quot;&lt;br /&gt;
| lang = text&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
If your Open OnDemand system is behind a reverse proxy doing SSL termination, you will still want the &amp;lt;code&amp;gt;OIDCRedirectURI&amp;lt;/code&amp;gt; to be using the &amp;lt;code&amp;gt;https://&amp;lt;/code&amp;gt; URL. However, the ood-portal-generator only uses the https protocol if the SSL certificates are defined in &amp;lt;code&amp;gt;ood_portal.yml&amp;lt;/code&amp;gt; (which we don&#039;t want to do with an external SSL terminator). As a work around, my docker &amp;lt;code&amp;gt;entrypoint.sh&amp;lt;/code&amp;gt; script will replace http with https before starting apache.&lt;br /&gt;
&lt;br /&gt;
See Also:&lt;br /&gt;
&lt;br /&gt;
*https://osc.github.io/ood-documentation/latest/authentication/oidc.html&lt;br /&gt;
*https://github.com/zmartzone/mod_auth_openidc&lt;br /&gt;
&lt;br /&gt;
==Troubleshooting==&lt;br /&gt;
Logs are stored at:&lt;br /&gt;
&lt;br /&gt;
*&amp;lt;code&amp;gt;/var/log/ondemand-nginx/&amp;lt;/code&amp;gt;&lt;br /&gt;
*&amp;lt;code&amp;gt;/var/log/httpd/&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Apps are stored at:&lt;br /&gt;
&lt;br /&gt;
*&amp;lt;code&amp;gt;/var/www/ood/apps/sys&amp;lt;/code&amp;gt;&lt;br /&gt;
*&amp;lt;code&amp;gt;/var/www/ood/apps/dev/$username/gateway&amp;lt;/code&amp;gt; (symlinked to user&#039;s home directory &amp;lt;code&amp;gt;~/ondemand/dev&amp;lt;/code&amp;gt;)&lt;br /&gt;
&lt;br /&gt;
=== 400 - Bad Request ===&lt;br /&gt;
Apache and the nginx instance running the PUN supports a 8k maximum client header request. Exceeding this limit will result in a &amp;lt;code&amp;gt;400 - Bad Request&amp;lt;/code&amp;gt; error being returned by Apache to the client. A likely cause for exceeding this limit is with excessive amounts of cookies.&lt;br /&gt;
&lt;br /&gt;
If there are a large number of OpenID state cookies, then this error is likely a symptom of another issue. For more information on this issue, see: https://github.com/zmartzone/mod_auth_openidc/wiki/Cookies&lt;br /&gt;
&lt;br /&gt;
A workaround would be to increase the client header request size from the default 8k to something higher. To do this:&lt;br /&gt;
&lt;br /&gt;
#&lt;br /&gt;
# Create an additional config file at &amp;lt;code&amp;gt;/var/lib/ondemand-nginx/config/apps/sys/large-header.conf&amp;lt;/code&amp;gt; with &amp;lt;code&amp;gt;large_client_header_buffers 8 64k;&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
==Implementations==&lt;br /&gt;
&lt;br /&gt;
*https://arc-ts.umich.edu/open-ondemand/  University of Michigan&lt;br /&gt;
*https://www.hpc.caltech.edu/documentation/open-ondemand Caltech&lt;br /&gt;
*https://www.ou.edu/oscer/support/openondemand#start University of Oklahoma&lt;br /&gt;
*https://its.unc.edu/research-computing/ondemand/ North Carolina&lt;br /&gt;
*https://chpc.utah.edu/presentations/images-and-pdfs/IntroOOD20s.pdf&lt;br /&gt;
*https://rc-docs.northeastern.edu/en/latest/using-ood/introduction.html  North Eastern (pam auth)&lt;br /&gt;
*https://wiki.ncsa.illinois.edu/display/ISL20/Getting+started+with+HAL+OnDemand (pam)&lt;br /&gt;
*https://www.sherlock.stanford.edu/docs/user-guide/ondemand/ Stanford&lt;br /&gt;
*https://hcc.unl.edu/documents/kickstart_2020/HCC_OOD.pdf Nebraska&lt;br /&gt;
*https://dashboard.hpc.unimelb.edu.au/web_environments/ (pam, https://spartan-ood.hpc.unimelb.edu.au/pun/sys/dashboard/batch_connect/sessions)&lt;br /&gt;
*https://wiki.hpc.odu.edu/en/open-ondemand  Old Dominion (sso, https://ondemand.wahab.hpc.odu.edu/)&lt;br /&gt;
*https://docs.ycrc.yale.edu/clusters-at-yale/access/ood/ Yale&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
&lt;br /&gt;
*Documentation: https://osc.github.io/ood-documentation/latest/index.html&lt;br /&gt;
&lt;br /&gt;
{{Navbox Linux}}&lt;br /&gt;
[[Category:Linux]]&lt;br /&gt;
[[Category:HPC]]&lt;/div&gt;</summary>
		<author><name>174.241.28.194</name></author>
	</entry>
</feed>