globus-connect-server collection create error: “The following domains cannot be found:”

186 views
Skip to first unread message

Weatherby,Gerard

unread,
Feb 18, 2021, 9:04:30 AM2/18/21
to dis...@globus.org
I am setting up a new Globus v5 Connect server.

I have gotten as far as creating the gateway:

Display Name: NMRbox Gateway
ID: xxxx
Connector: POSIX
High Assurance: False
Authentication Timeout: 15840
Allowed Domains: ['bioscience-ct.net']

The server it is running on (Ubuntu 18.04.5 LTS) is domain joined to an Active Directory server, bioscience-ct.net.

When I go to create the collection:

globus-connect-server collection create xxxx \
 $HOME "POSIX nmrbox.org home directories" \
 --organization 'NMRbox' \
 --contact-email sup...@nmrbox.org \
 --info-link https://example.org/storage/info \
 --description "NMRbox home directories" \
 --keywords nmrbox.org,home,nmr,'UConn Health','University of Connecticut' \
 --enable-https

I’m getting the following error:

An API Error Occurred
HTTP status: 400
code: bad_request
message: Storage Gateway xxxx is misconfigured: Invalid value for 'required_domains' parameter: ['bioscience-ct.net'.... The following domains cannot be found: bioscience-ct.net

Any suggestions on how to resolve and/or troubleshoot?

-- 
Gerard Weatherby | Application Architect
NMRbox | Department of Molecular Biology and Biophysics | UConn Health
263 Farmington Avenue, Farmington, CT 06030-6406
uchc.edu

Sam Claassens

unread,
Feb 19, 2021, 6:33:12 PM2/19/21
to Weatherby,Gerard, dis...@globus.org
Hi Gerard,

We're following up on this in a ticket but we just wanted to inform other users in case they come across this issue.

This error is shown because Globus Auth domain bioscience-rt.net isn't registered with Globus Auth. If you use the --domain flag when registering your storage gateway, you should only provide domains associated with identity providers listed by Globus Auth. In this case, Globus Auth did not recognize the domain, and it returned an error indicating that the domain can't be found. The error message is shown when you attempt to create a collection using the storage gateway.

If you want to use a domain that is not part of the Globus Auth identity providers, one alternative is to install the GCS OIDC server.

Hope this helps!

Best,
Sam
--
 
Sam Claassens
Senior Software Engineer
Reply all
Reply to author
Forward
0 new messages