# Acl\_groups w/wo ldap

**URL:** <https://community.openpbs.org/t/acl-groups-w-wo-ldap/426>\
**Category:** Users/Site Administrators\
**Created:** [February 1, 2017, 1:46pm UTC](https://community.openpbs.org/t/acl-groups-w-wo-ldap/426 "2017-02-01T13:46:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![einjen](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.openpbs.org/einjen/32/42_2.png) [@einjen](https://community.openpbs.org/u/einjen)\
**Post date:** [February 1, 2017, 1:46pm UTC](https://community.openpbs.org/t/acl-groups-w-wo-ldap/426/1 "2017-02-01T13:46:14Z")

</div>

Hello.

I’m having trouble setting acl\_groups on queues.

I have two queues, test and training, but I can only submit to “test” queue.  
I cannot submit to training queue, even though I have both primary and secondary group "testing"  
I want this to work with ldap.

# id einjen

tells me I’m in both groups

so what is going on? how do I set up this acl correctly?

create queue test  
set queue test queue\_type = Execution  
set queue test acl\_user\_enable = True  
set queue test acl\_users = einjen  
set queue test enabled = True  
set queue test started = True  
Qmgr: p q training

# 

# Create queues and set their attributes.

# 

# 

# Create and define queue training

# 

create queue training  
set queue training queue\_type = Execution  
set queue training acl\_group\_enable = True  
set queue training acl\_groups = training  
set queue training enabled = True  
set queue training started = True

---

<div class="post-metadata">

**Author:** ![scott](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.openpbs.org/scott/32/30_2.png) [@scott](https://community.openpbs.org/u/scott)\
**Post date:** [February 1, 2017, 2:24pm UTC](https://community.openpbs.org/t/acl-groups-w-wo-ldap/426/2 "2017-02-01T14:24:47Z")

</div>

I am assuming the secondary group for user einjen is training, correct?

If you want to the secondary group to be used in job submission, then you will need to specify this at submission time by using the -W group\_list= option. Please see below.

I have recreated your queue setup.

```
Qmgr: p q test,training
#
# Create queues and set their attributes.
#
#
# Create and define queue test
#
create queue test
set queue test queue_type = Execution
set queue test acl_user_enable = True
set queue test acl_users = scott
set queue test enabled = True
set queue test started = True
#
# Create queues and set their attributes.
#
#
# Create and define queue training
#
create queue training
set queue training queue_type = Execution
set queue training acl_group_enable = True
set queue training acl_groups = users
set queue training enabled = True
set queue training started = True

```

As the user, scott, I will attempt to submit the job to the training queue where the acl\_group=users.

My secondary group is users

```
[scott@centos7-00 ~]$ id scott
uid=1000(scott) gid=1000(scott) groups=1000(scott),100(users),993(docker)

```

First job submission, I do not specify -W group\_list, so my primary group is used at submission. And, I am rejected.

```
[scott@centos7-00 ~]$ /opt/pbs/default/bin/qsub -q training -- /bin/sleep 100
qsub: Unauthorized Request 

```

Second job submission, I specify -W group\_list=users and the job is accepted

```
[scott@centos7-00 ~]$ /opt/pbs/default/bin/qsub -q training -W group_list=users -- /bin/sleep 100
1657.centos7-00.virtualworld
```

---

<div class="post-metadata">

**Author:** ![einjen](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.openpbs.org/einjen/32/42_2.png) [@einjen](https://community.openpbs.org/u/einjen)\
**Post date:** [February 1, 2017, 2:50pm UTC](https://community.openpbs.org/t/acl-groups-w-wo-ldap/426/3 "2017-02-01T14:50:10Z")

</div>

Thanks, but no luck.  
neither primary, nor secondary group works, with or without -W group\_list.  
it doesn’t work if group is in ldap or if it is not.

acl\_user\_enable = True  
acl\_users = einjen

does work. with or without ldap

---

<div class="post-metadata">

**Author:** ![scott](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.openpbs.org/scott/32/30_2.png) [@scott](https://community.openpbs.org/u/scott)\
**Post date:** [February 1, 2017, 10:13pm UTC](https://community.openpbs.org/t/acl-groups-w-wo-ldap/426/4 "2017-02-01T22:13:36Z")

</div>

PBS does not directly interface with LDAP, it uses the standard c-library functions getpwname and getpwent.

There are sites using LDAP on clusters with PBS Professional managing the jobs.

Curious… was PBS Professional server running before you configured the system to use LDAP? I seem to recall that some sites restarted the PBS Server and it started working.

Are you submitting the job on the same host as the PBS Server?

Does your user have the same group membership on the server and the submission host?

---

<div class="post-metadata">

**Author:** ![einjen](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.openpbs.org/einjen/32/42_2.png) [@einjen](https://community.openpbs.org/u/einjen)\
**Post date:** [February 1, 2017, 11:33pm UTC](https://community.openpbs.org/t/acl-groups-w-wo-ldap/426/5 "2017-02-01T23:33:13Z")

</div>

Hey! Thanks!

Restart of PBS server was the secret sauce.  
Ldap clients on pbs server and submitting host was installed after PBS was installed.

I was really puzzled by this since it was working quite well on our PBS pro 12 production cluster
