All posts by Kostas Koumantaros

Working at GRNET ( as the NGI_GRNET manager and HellasGrid coordinator

Access to HellasGrid

In order to get access to HellasGrid infrastructure, you have to:
1.Obtain a Digital Certificate from the HellasGrid Certification Authority.
2.Get an account at a HellasGrid User Interface.
3.Join a Virtual Organization.
4.Import your Digital Certificate to your User Interface.

Obtain a Digital Certificate from the HellasGrid Certification Authority

In order to acquire a Digital Certificate you have to visit the following web page: By clicking at the first choice, you can request a personal Digital Certificate. You have first to complete a form with your personal information (first name, last name, organization, department, etc). Once you have completed this form an informative e-mail will be sent at your personal e-mail account informing you that your personal information has been registered at HellasGrid data base and request to confirm the reception of the e-mail. In case you do not confirm the e-mail reception in seven days, your registration will be removed from the HellasGrid data base.

Once you confirmed the reception of the e-mail you can proceed with the certification request procedure. Initially you will be asked to install at your web browser the certificate of the HellasGrid Certification Authority. For the Greek users the responsible authority is the HellasGrid -CA ( ).

Consequently you must generate your private key and certificate signing request at the web browser. The private key and certificate signing request will be automatically sent at HellasGrid -CA.
Once your certificate signing request has been sent at the HellasGrid -CA an informative email will be sent to you. With this email you will be requested to visit in person your appropriate Registration Authority and present the following documents:

  • Your identification card or your passport.
  • One document which will confirm your affiliation with your organization.
  • A print out of the received e-mail.

list of the existing Registration Authorities for the Greek Users can be found at the site: In the case you can not be served by an existing Registration Authority you must contact the Catch-all Registration Authority, operated by GridAUTH (
You can regularly check the status of your certificate signing request. Once the status of your request changes to “signed” you have to install the certificate at your web browser (the same used for the procedure obtaining the certificate).

Get an account at a HellasGrid User Interface

A User Interface is nothing more and nothing less than a Linux box having installed all the required client software, APIs and tools for developing and running applications in the Grid. In practice everyone can install and setup a UI with the required EGEE tools following the instructions in the GLITE-3 Installation Guide.
Also the Italian SA1 EGEE Activity has made available a package called UIPnP which can be installed in any Linux machine and turn it into a User Interface (you can even install it as a regular non-root user). Note though that it is preconfigured for accessing the Italian EGEE sites and some manual configuration steps are required at the moment in order to be useful for EGEE-SEE users (including Hellasrid users).
There is also a chance that your institute may already have setup a UI machine so you can ask from your local administrator to create an account for you there.
Till now, six User Interfaces has been installed to serve the HellasGrid users:

• three in Athens (,,,
• one in Thessaloniki (,

You can request access to the appropiate UI according to the location of your organization by following the second choice at the web page If you do not have access to a User Interface or you cannot (or do not want to) install your own UI, you may request via the web page for an account at the Isabella catch-all UI hosted in the GRNET site, which is located at Athens; provided of course that you have already obtained a digital certificate issued by the HellasGrid -CA. In order to connect at the User Interface at which you have an account you must use an ssh client program, for example putty, a free program which can be downloaded from the link

Join a Virtual Organization

To be authorized to use the Grid and do useful work with it you have to belong to a Virtual Organization (VO); A Virtual Organization (VO) is a group of grid users with similar interests and requirements who are able to work collaboratively with other members of the group and/or share resources (data, software, expertise, CPU, storage space, etc.) regardless of geographical location. A list of existing EGEE VOs is available at

Enroll into an existing VO

If you are an experienced Grid user you are already familiar with the concept of VO and you may already belong to one of them. If you participate in one of the LHC experiments (like Atlas, CMS etc) there are already respective established VOs. If you want to join you should contact the appropriate VO manager.


In order to make life easier for the South Eastern Europe users (including the HellasGrid users), speed up and simplify the process of new application induction, EGEE-SEE has established its own VO called SEE-VO. This VO will be the most adequate for SEE users that do not fit in any of the existing EGEE VOs or are not able to create their own EGEE-wide VO. To join the SEE-VO as a HellasGrid user you have to request it via the web page: Please note that this page has to be visited using the browser on which you have already loaded your digital certificate otherwise the process cannot be completed.

Import your Digital Certificate to your User Interface

Till now, you have a Digital Certificate installed at your web browser. In order to use the HellasGrid infrastructure, for example to submit a job for execution, check the status of the job; get the output of the job, you have to install also your certificate to the User Interface you have an account. First you have to export your Digital Certificate from your web browser at which it is installed. To do this at Internet Explorer you must follow the path: Tools->Internet Options->Content->Certificates->Personal->Export while to do this at Mozilla Firefox you must follow the path: Edit->Preferences->Advanced->Encryption->View Certificates->Your Certificates->Backup or Tools->Options->Advanced->Encryption->View Certificates->Your Certificates->Backup. In both cases your personal certificate must be saved with .p12 extension (PKCS#12 format). So, by following the instructions of the above links you have succesfully backed up your security certificate and private key at your machine. Now you have to copy your Digital Certificate from your machine to your home directory at the User Inteface you gained an account. Then you must create your Digital Certificate and private key in .pem format. In order to do this you must execute the following two openssl commands:

openssl pkcs12 -nocerts \
 -in mycertificate.p12 \
 -out ~user/.globus/userkey.pem

openssl pkcs12 -clcerts -nokeys \
 -in mycertificate.p12 \
 -out ~user/.globus/usercert.pem

The first openssl command gets as input your certificate in .p12 format (mycertificate.p12) and creates your private key in .pem format (userkey.perm).The second openssl command gets as input your certificate in .p12 format (mycertificate.p12) and creates your certificate in .pem format (usercert.pem). We must mention that the ~ user should be replaced by the path to your home area. Both your private key and certificate are stored in the .globus directory.
Finally you must give the appropiate read privileges at your private key and certificate.

chmod 444 ~/.globus/usercert.pem 
chmod 400 ~/.globus/userkey.pem

δημιουργία υπολογιστικού συστήματος υψηλών επιδόσεων (High Performance Computer – HPC)

Το Εθνικό Δίκτυο Έρευνας και Τεχνολογίας (ΕΔΕΤ) πρωτοστατεί στον χώρο των υπερυπολογιστικών υποδομών, με τη δημιουργία του πρώτου εθνικού υπολογιστικού συστήματος υψηλών επιδόσεων (High Performance Computer – HPC) για την υποστήριξη επιστημονικών εφαρμογών μεγάλης κλίμακας. Την προμήθεια και εγκατάσταση του νέου συστήματος ανέλαβε η COSMOS Business Systems Α.Ε.Β.Ε. σε συνεργασία με την ΙΒΜ, έπειτα από ανοικτό διεθνή διαγωνισμό που διενήργησε η ΕΔΕΤ Α.Ε. Η νέα υποδομή αναμένεται να παίξει σημαντικό ρόλο στην ανάπτυξη και προαγωγή της επιστημονικής έρευνας στη χώρα και στη Νοτιανατολική Ευρώπη.

Continue reading δημιουργία υπολογιστικού συστήματος υψηλών επιδόσεων (High Performance Computer – HPC)

The EGI Platform Architecture

Gergely Sipos discusses how technology support will work from May 2013, after the end of the European Middleware Initiative and the Initiative for Globus in Europe

In April 2013, with the end of the EMI and IGE projects, the EGI community lost its two largest technology providers and contri- butors to the Unified Middleware Distribution.

This is a milestone for EGI and grid computing in Europe: for the first time since 2001, we will have no dedicated project for grid middleware development. But just because EMI and IGE are over, development is not finished. Most of the teams involved in EMI and in IGE are still active, fixing bugs for the communities who depend on their products. Some teams even implement new functiona- lities in their software, but the coordination and integration provided by EMI and IGE are gone. For EGI, the answer is the EGI Platform Architecture – a new software integration and provisioning process.

A platform-based EGI

EGI started developing its platform architecture in early 2012 and refined it over the last 14 months. The platform-based EGI is capable of supporting a broad customer base with a very diverse set of requirements, and with a much smaller central coordination effort.
The platform-based EGI consists of:

  1. EGI Core Infrastructure Platform, to operate and manage a distributed infrastructure (e.g. accounting);
  2. EGI Cloud Infrastructure Platform, to operate a federated cloud based infrastructure;
  3. EGI Collaboration Platform, for information exchange and community coordination (e.g. AppDB), and
  4. Community Platforms, service portfolios customised for scientific communities.

The Platform Architecture allows any type and any number of community platform to co-exist on the physical infrastructure. Some can provide a grid functio- nality – similar to EMI’s and IGE’s services. Others can include completely unique services that run, for example, in Virtual Machines.

A flexible system

EMI’s and IGE’s distributions included a large number of services that very few commu- ities required in bulk. In practice, most user groups require a relatively simple, but variable set (e.g. a service for job execution and a file storage service, plus some services for security and access control). The flexibility of the new system allows the ‘long tail of scientists’ to be better represented in the platform-based EGI.

More choice for developers will support the develop- ment of community platforms integrated and operated by scientific communities in collaboration with the NGIs.

will facilitate the interaction of software developers, scientific communities and platform integrators within EGI. Software developers will be able to choose from three levels of involvement in this process.

  • Integrated providers’ have the strongest ties with EGI and scientific communities, via MoUs and SLAs, and support is provided by the EGI Helpdesk. They are represented in the Technical Coordination Board and can influence EGI’s evolution.
  • Community providers’ simply make their software available via AppDB, now extended to incorporate a Community Software Repository.
  • Contributing providers’ are in between – they will offer guarantees on the quality of their software and user support, but not as regimented as for integrated providers.

EGI will move to the platform- based model gradually. The focus will now be on establishing new links between software developers, software integrators and operators across the community.

The conceptual change is big but what scientists will notice is the added freedom and options offered by the EGI Platform Architecture. 

Inspired // Issue #11 April 2013