{"id":121,"date":"2021-02-19T13:57:51","date_gmt":"2021-02-19T19:57:51","guid":{"rendered":"http:\/\/computing.fnal.gov\/lqcd\/?page_id=121"},"modified":"2025-08-07T14:22:41","modified_gmt":"2025-08-07T19:22:41","slug":"user-accounts","status":"publish","type":"page","link":"https:\/\/computing.fnal.gov\/lqcd\/user-accounts\/","title":{"rendered":"New User Accounts"},"content":{"rendered":"\n<p>To access USQCD computing resources at Fermilab users require the following three items:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Visitor ID<\/li>\n\n\n\n<li>Kerberos account<\/li>\n\n\n\n<li>Unix accounts on the LQCD cluster machines<\/li>\n<\/ul>\n\n\n\n<p><span style=\"text-decoration: underline;\">Visitor ID and Kerberos account<\/span><\/p>\n\n\n\n<p>Submit an online application form for a Affiliate ID and Kerberos account&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/get-connected.fnal.gov\/accessandbadging\/access\/\" target=\"_blank\">using this link<\/a>. Follow the instructions for applying for a computing account as a Fermilab affiliate. You do not need to apply for on-site access or a physical id badge. You will need to enter the following information:&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>For your affiliation&nbsp;<em>select<\/em>&nbsp;Lattice QCD&nbsp;<\/li>\n\n\n\n<li>Fermilab contact name\u00a0<em>list<\/em>\u00a0Lisa Goodenough (primary Site Manager)<\/li>\n\n\n\n<li>Fermilab contact phone&nbsp;<em>list<\/em>&nbsp;x6783 (Ken Herner, secondary Site Manager)<\/li>\n\n\n\n<li>Fermilab contact email\u00a0<em>list<\/em>\u00a0goodenou@fnal.gov (primary Site Manager)<\/li>\n<\/ol>\n\n\n\n<p><span style=\"text-decoration: underline;\">Unix accounts on the LQCD cluster machines<\/span><\/p>\n\n\n\n<p>After you have received an email with information about your Kerberos account, We need an email from the PI of the project verifying your affiliation to the project. We ask that the PI send an email to&nbsp;<a href=\"mailto:hpc-admin@fnal.gov\">hpc-admin@fnal.gov<\/a> to request the user be added to the project on the LQCD cluster machines. In the email, mention the Kerberos account name, the email address to be added to our lqcd-userss@fnal.gov announcements list, and identify your project name. Type A projects are listed in the <a href=\"https:\/\/computing.fnal.gov\/lqcd\/allocations\/\" data-type=\"page\" data-id=\"178\">allocations table<\/a>. <\/p>\n\n\n\n<h5 class=\"wp-block-heading\">Existing Allocation \/ Projects<\/h5>\n\n\n\n<p>In order to add you to an existing project allocation, we need an email from the project&#8217;s PI or POC asking that we add your account and associate it with the project. We ask that the user who is requesting the account contact the PI or POC to have them send an email to&nbsp;<a href=\"mailto:hpc-admin@fnal.gov\">hpc-admin@fnal.gov<\/a>. This email should include the user&#8217;s Kerberos principal and the project name. We can not set up an account unless the request comes from or through the project PI or POC.<\/p>\n\n\n\n<p>The current&nbsp;<a href=\"https:\/\/computing.fnal.gov\/lqcd\/allocations\/\" data-type=\"page\" data-id=\"178\">list of allocated projects<\/a>&nbsp;lists the PI or POC contact person.<\/p>\n\n\n\n<p>Once we have that request, we will create a Request ticket to track the work. Our goal is to have the new account ready within two business days.<\/p>\n\n\n\n<p>You are now all set to start using the Fermilab LQCD clusters. If you get stuck at any of the above steps please send us an email to&nbsp;<a href=\"mailto:lqcd-admin@fnal.gov\">lqcd-admin@fnal.gov<\/a>&nbsp;with a detailed explanation of the issue you are facing.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"RenewingyourVisitorIDandKerberosaccount\">Renewing your Visitor ID and Kerberos account<\/h3>\n\n\n\n<p>Your Visitor ID and computer privileges expire at different intervals depending on your classification (employee, contractor, on-site or off-site visitor). Please note that even when your ID or computer privileges expire&nbsp;<span style=\"text-decoration: underline;\">we do not erase any user data&nbsp;stored on the Fermilab LQCD clusters<\/span>.<\/p>\n\n\n\n<p>If you need to look up your Vistor ID number then use the&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/tele.fnal.gov\/\" target=\"_blank\">Fermilab telephone directory<\/a>&nbsp;search pages to look for your name. If an entry exists for you and that entry lists a Visitor ID number, record that number for filling out the account renewal application.<\/p>\n\n\n\n<p>Details regarding the account renewal process for a&nbsp;<span style=\"text-decoration: underline;\">visitor<\/span>&nbsp;can be found&nbsp;<a href=\"https:\/\/fermi.servicenowservices.com\/kb_view.do?sys_kb_id=8188a4c91b2e2c109581ece0f54bcb88&amp;sysparm_rank=1&amp;sysparm_tsqueryId=5e954cb91b957c10818d4000f54bcb2a\" target=\"_blank\" rel=\"noreferrer noopener\">at this link<\/a>.<\/p>\n\n\n\n<p>If you still need further assistance please email us at&nbsp;<a href=\"mailto:hpc-admin@fnal.gov\" data-type=\"mailto\" data-id=\"mailto:hpc-admin@fnal.gov\">hpc-admin@fnal.gov<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"ChangingyourKerberosaccountpassword\">Changing your Kerberos account password<\/h3>\n\n\n\n<p>A month before your Kerberos password is set to expire you will receive a reminder email from the Fermilab Service Desk requesting you to change your password as soon as you can. Please&nbsp;<span style=\"text-decoration: underline;\">do not ignore this reminder<\/span>&nbsp;email and act upon it as soon as possible. You will lose remote login privileges to the USQCD cluster resources at Fermilab once your Kerberos password has expired.<\/p>\n\n\n\n<p>Follow the instructions for changing your Kerberos password as listed in&nbsp;<a href=\"https:\/\/fermi.servicenowservices.com\/kb_view_customer.do?sysparm_article=KB0010628\" target=\"_blank\" rel=\"noreferrer noopener\">this knowledge base article<\/a>.<\/p>\n\n\n\n<p>&nbsp;If your password expires before you change it, you can still change it as long as you remember what it is. If you don&#8217;t remember it, please call the&nbsp;Service Desk at (630) 840-2345 to have it reset.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Kerberossoftwareinstallation\">Kerberos software installation<\/h3>\n\n\n\n<p>Many UNIX systems already have Kerberos installed. Use&nbsp;<code>which kinit&nbsp;<\/code>to see whether this software is already in your path. If not, check if&nbsp;<code>\/usr\/krb5<\/code>&nbsp;or&nbsp;<code>\/usr\/kerberos<\/code>&nbsp;directories exist on your workstation &#8211; if so, add&nbsp;<code>\/usr\/kerberos\/bin<\/code>&nbsp;(or the equivalent for&nbsp;krb5) to the&nbsp;<strong>front<\/strong>&nbsp;of your path. Generally, if you have <code>\/usr\/bin\/kinit <\/code>installed, you should use that.<\/p>\n\n\n\n<p>On RedHat Linux systems (<a href=\"https:\/\/fermi.servicenowservices.com\/kb_view.do?sysparm_article=KB0011294\" target=\"_blank\" rel=\"noreferrer noopener\">MAC read this<\/a>), you will need to install the following RPM&#8217;s (versions will vary):<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">krb5-libs\nkrb5-workstation\npam_krb5\n<\/pre>\n\n\n\n<p>If Kerberos software is already installed on your system, you will need to modify the configuration file so that your machine knows how to contact the Fermilab key authentication servers. Copy your OS-specific&nbsp;krb5.conf&nbsp;file in&nbsp;\/etc. If you are already using Kerberos to access another site, for example, NCSA, you will need to modify your existing&nbsp;<code>\/etc\/krb5.conf<\/code>&nbsp;file as follows:<\/p>\n\n\n\n<p>In the&nbsp;<strong>[realms]<\/strong>&nbsp;section, add<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">FNAL.GOV = {\n            kdc = krb-fnal-1.fnal.gov:88\n            kdc = krb-fnal-2.fnal.gov:88\n            kdc = krb-fnal-3.fnal.gov:88\n            kdc = krb-fnal-4.fnal.gov:88\n            kdc = krb-fnal-5.fnal.gov:88\n            kdc = krb-fnal-6.fnal.gov:8\n            admin_server = krb-fnal-admin.fnal.gov\n            master_kdc = krb-fnal-admin.fnal.gov:88\n            default_domain = fnal.gov\n}\n\nWIN.FNAL.GOV = {\n            kdc = littlebird.win.fnal.gov:88\n            kdc = bigbird.win.fnal.gov:88\n            default_domain = fnal.gov\n}&nbsp;<\/pre>\n\n\n\n<p>In the&nbsp;<strong>[domain_realm<\/strong>] section, add<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">        .fnal.gov = FNAL.GOV\n        .dhcp.fnal.gov = FNAL.GOV<\/pre>\n\n\n\n<p>A user must have a valid Kerberos ticket before they can log in to a Fermilab machine. Here is a sample session showing a typical Kerberos dialog to obtain a Kerberos ticket. johndoe@FNAL.GOV is the Kerberos principal. You must use Secure SHell (SSH) that supports Kerberos to remote login.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">login.somemachine:~$ kinit -r 7d johndoe@FNAL.GOV<br>Password for johndoe@FNAL.GOV:<br><br>somemachine:~$ ssh lq.fnal.gov<br><br><br>NOTICE TO USERS<br><br>This is a Federal computer (and\/or it is directly connected to a Fermilab local network system) that is the property of the UnitedStates Government. It is for . . . .&nbsp;<br>&lt;---snip---&gt;<br><br>lq:~$<\/pre>\n\n\n\n<p>Please note:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>You should only&nbsp;kinit&nbsp;on your local machine, from its console.&nbsp;<span style=\"text-decoration: underline;\">Do not execute&nbsp;<\/span><code>kinit<\/code>&nbsp;over a network connection (e.g. public wireless access point), since this can expose your kerberos password.<\/li>\n\n\n\n<li>You will probably want to request renewable tickets since tickets by default expire 24 hours after they are issued unless renewed with&nbsp;<code>kinit -R<\/code>. Tickets can be renewed for up to 7 days if you request a ticket using&nbsp;<code>kinit -r 7d<\/code>. The maximum renewable period is 7 days.<\/li>\n\n\n\n<li>Use&nbsp;<code>klist<\/code>&nbsp;to check whether you hold a valid ticket.<\/li>\n\n\n\n<li>If you are connecting from home behind a firewall which uses NAT (Network Address Translation), you&#8217;ll need to use address-less tickets. Most versions of kerberos will give you address-less tickets if you use the&nbsp;-n&nbsp;switch. Other versions of kerberos may use the&nbsp;-A&nbsp;switch. Check your man page for&nbsp;<code>kinit<\/code>&nbsp;or use&nbsp;<code>kinit --help<\/code>&nbsp;to see which switch is supported.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>To access USQCD computing resources at Fermilab users require the following three items: Visitor ID and Kerberos account Submit an online application form for a Affiliate ID and Kerberos account&nbsp;using this link. Follow the instructions for applying for a computing account as a Fermilab affiliate. You do not need to apply for on-site access or&#8230; <a class=\"more-link\" href=\"https:\/\/computing.fnal.gov\/lqcd\/user-accounts\/\"> More &#187;<\/a><\/p>\n","protected":false},"author":16,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-121","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/computing.fnal.gov\/lqcd\/wp-json\/wp\/v2\/pages\/121","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/computing.fnal.gov\/lqcd\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/computing.fnal.gov\/lqcd\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/computing.fnal.gov\/lqcd\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/computing.fnal.gov\/lqcd\/wp-json\/wp\/v2\/comments?post=121"}],"version-history":[{"count":36,"href":"https:\/\/computing.fnal.gov\/lqcd\/wp-json\/wp\/v2\/pages\/121\/revisions"}],"predecessor-version":[{"id":7648,"href":"https:\/\/computing.fnal.gov\/lqcd\/wp-json\/wp\/v2\/pages\/121\/revisions\/7648"}],"wp:attachment":[{"href":"https:\/\/computing.fnal.gov\/lqcd\/wp-json\/wp\/v2\/media?parent=121"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}