Äcdocutils.nodes
document
q)Åq}q(U	nametypesq}q(X���four distinct tiersqàX���investigator toolkitqNX���apache configuration detailsqNX���mnstorage.createq	àX���restq
àX���accesspolicyqàX���what is dataone?qNX%���configuration as a replication targetq
NX���dataone web siteqàX���dataone service interfaceqàX���member nodesqNX���object replication policiesqNX"���generating dataone system metadataqNX���the dataone service interfaceqNX$���configuring metacat as a member nodeqNX���coordinating nodesqNX-���configure tomcat to allow dataone identifiersqNX���cnauthorization.setaccesspolicyqàX���dataone member node supportqNX���incommonqàX���access control policiesqNX���systemmetadataqàX���dataoneqàX"���cnreplication.setreplicationpolicyqàX���mnstorage.updateqàX���cilogonqàuUsubstitution_defsq }q!Uparse_messagesq"]q#Ucurrent_sourceq$NU
decorationq%NUautofootnote_startq&KUnameidsq'}q((hUfour-distinct-tiersq)hUinvestigator-toolkitq*hUapache-configuration-detailsq+h	Umnstorage-createq,h
Urestq-hUaccesspolicyq.hUwhat-is-dataoneq/h
U%configuration-as-a-replication-targetq0hUdataone-web-siteq1hUdataone-service-interfaceq2hUmember-nodesq3hUobject-replication-policiesq4hU"generating-dataone-system-metadataq5hUthe-dataone-service-interfaceq6hU$configuring-metacat-as-a-member-nodeq7hUcoordinating-nodesq8hU-configure-tomcat-to-allow-dataone-identifiersq9hUcnauthorization-setaccesspolicyq:hUdataone-member-node-supportq;hUincommonq<hUaccess-control-policiesq=hUsystemmetadataq>hUdataoneq?hU"cnreplication-setreplicationpolicyq@hUmnstorage-updateqAhUcilogonqBuUchildrenqC]qDcdocutils.nodes
section
qE)ÅqF}qG(U	rawsourceqHU�UparentqIhUsourceqJXa���/var/lib/jenkins/jobs/Metacat_stable/workspace/METACAT_2_7_2/docs/user/metacat/source/dataone.rstqKUtagnameqLUsectionqMU
attributesqN}qO(UdupnamesqP]UclassesqQ]UbackrefsqR]UidsqS]qTh;aUnamesqU]qVhauUlineqWKUdocumentqXhhC]qY(cdocutils.nodes
title
qZ)Åq[}q\(hHX���DataONE Member Node Supportq]hIhFhJhKhLUtitleq^hN}q_(hP]hQ]hR]hS]hU]uhWKhXhhC]q`cdocutils.nodes
Text
qaX���DataONE Member Node SupportqbÖÅqc}qd(hHh]hIh[ubaubcdocutils.nodes
paragraph
qe)Åqf}qg(hHXù��DataONE_ is a federation of data repositories that aims to improve
interoperability among data repository software systems and advance the
preservation of scientific data for future use.
Metacat deployments can be configured to participate in DataONE_. This
chapter describes the DataONE_ data federation,  its architecture, and the
way in which Metacat can be used to participate as a node in the DataONE system.hIhFhJhKhLU	paragraphqhhN}qi(hP]hQ]hR]hS]hU]uhWKhXhhC]qj(cdocutils.nodes
reference
qk)Åql}qm(hHX���DataONE_UresolvedqnKhIhfhLU	referenceqohN}qp(UnameX���DataONEUrefuriqqX���http://dataone.org/qrhS]hR]hP]hQ]hU]uhC]qshaX���DataONEqtÖÅqu}qv(hHU�hIhlubaubhaXÎ��� is a federation of data repositories that aims to improve
interoperability among data repository software systems and advance the
preservation of scientific data for future use.
Metacat deployments can be configured to participate in qwÖÅqx}qy(hHXÎ��� is a federation of data repositories that aims to improve
interoperability among data repository software systems and advance the
preservation of scientific data for future use.
Metacat deployments can be configured to participate in hIhfubhk)Åqz}q{(hHX���DataONE_hnKhIhfhLhohN}q|(UnameX���DataONEhqhrhS]hR]hP]hQ]hU]uhC]q}haX���DataONEq~ÖÅq}qÄ(hHU�hIhzubaubhaX���. This
chapter describes the qÅÖÅqÇ}qÉ(hHX���. This
chapter describes the hIhfubhk)ÅqÑ}qÖ(hHX���DataONE_hnKhIhfhLhohN}qÜ(UnameX���DataONEhqhrhS]hR]hP]hQ]hU]uhC]qáhaX���DataONEqàÖÅqâ}qä(hHU�hIhÑubaubhaX}��� data federation,  its architecture, and the
way in which Metacat can be used to participate as a node in the DataONE system.qãÖÅqå}qç(hHX}��� data federation,  its architecture, and the
way in which Metacat can be used to participate as a node in the DataONE system.hIhfubeubcdocutils.nodes
target
qé)Åqè}qê(hHX ���.. _DataONE: http://dataone.org/U
referencedqëKhIhFhJhKhLUtargetqíhN}qì(hqhrhS]qîh?ahR]hP]hQ]hU]qïhauhWK
hXhhC]ubhE)Åqñ}qó(hHU�hIhFhJhKhLhMhN}qò(hP]hQ]hR]hS]qôh/ahU]qöhauhWK
hXhhC]qõ(hZ)Åqú}qù(hHX���What is DataONE?qûhIhñhJhKhLh^hN}qü(hP]hQ]hR]hS]hU]uhWK
hXhhC]q†haX���What is DataONE?q°ÖÅq¢}q£(hHhûhIhúubaubhe)Åq§}q•(hHX&��The DataONE_ project is a collaboration among scientists, technologists, librarians,
and social scientists to build a robust, interoperable, and sustainable system for
preserving and accessing Earth observational data at national and global scales.
Supported by the U.S. National Science Foundation, DataONE partners focus on
technological, financial, and organizational sustainability approaches to
building a distributed network of data repositories that are fully interoperable,
even when those repositories use divergent underlying software and support different
data and metadata content standards. DataONE defines a common web-service service
programming interface that allows the main software components of the DataONE system
to seamlessly communicate. The components of the DataONE system include:hIhñhJhKhLhhhN}q¶(hP]hQ]hR]hS]hU]uhWKhXhhC]qß(haX���The q®ÖÅq©}q™(hHX���The hIh§ubhk)Åq´}q¨(hHX���DataONE_hnKhIh§hLhohN}q≠(UnameX���DataONEhqhrhS]hR]hP]hQ]hU]uhC]qÆhaX���DataONEqØÖÅq∞}q±(hHU�hIh´ubaubhaX�� project is a collaboration among scientists, technologists, librarians,
and social scientists to build a robust, interoperable, and sustainable system for
preserving and accessing Earth observational data at national and global scales.
Supported by the U.S. National Science Foundation, DataONE partners focus on
technological, financial, and organizational sustainability approaches to
building a distributed network of data repositories that are fully interoperable,
even when those repositories use divergent underlying software and support different
data and metadata content standards. DataONE defines a common web-service service
programming interface that allows the main software components of the DataONE system
to seamlessly communicate. The components of the DataONE system include:q≤ÖÅq≥}q¥(hHX�� project is a collaboration among scientists, technologists, librarians,
and social scientists to build a robust, interoperable, and sustainable system for
preserving and accessing Earth observational data at national and global scales.
Supported by the U.S. National Science Foundation, DataONE partners focus on
technological, financial, and organizational sustainability approaches to
building a distributed network of data repositories that are fully interoperable,
even when those repositories use divergent underlying software and support different
data and metadata content standards. DataONE defines a common web-service service
programming interface that allows the main software components of the DataONE system
to seamlessly communicate. The components of the DataONE system include:hIh§ubeubcdocutils.nodes
bullet_list
qµ)Åq∂}q∑(hHU�hIhñhJhKhLUbullet_listq∏hN}qπ(Ubulletq∫X���*hS]hR]hP]hQ]hU]uhWKhXhhC]qª(cdocutils.nodes
list_item
qº)ÅqΩ}qæ(hHX���DataONE Service InterfaceqøhIh∂hJhKhLU	list_itemq¿hN}q¡(hP]hQ]hR]hS]hU]uhWNhXhhC]q¬he)Åq√}qƒ(hHhøhIhΩhJhKhLhhhN}q≈(hP]hQ]hR]hS]hU]uhWKhC]q∆haX���DataONE Service Interfaceq«ÖÅq»}q…(hHhøhIh√ubaubaubhº)Åq }qÀ(hHX���Member NodesqÃhIh∂hJhKhLh¿hN}qÕ(hP]hQ]hR]hS]hU]uhWNhXhhC]qŒhe)Åqœ}q–(hHhÃhIh hJhKhLhhhN}q—(hP]hQ]hR]hS]hU]uhWKhC]q“haX���Member Nodesq”ÖÅq‘}q’(hHhÃhIhœubaubaubhº)Åq÷}q◊(hHX���Coordinating NodesqÿhIh∂hJhKhLh¿hN}qŸ(hP]hQ]hR]hS]hU]uhWNhXhhC]q⁄he)Åq€}q‹(hHhÿhIh÷hJhKhLhhhN}q›(hP]hQ]hR]hS]hU]uhWKhC]qfihaX���Coordinating NodesqflÖÅq‡}q·(hHhÿhIh€ubaubaubhº)Åq‚}q„(hHX���Investigator Toolkit
hIh∂hJhKhLh¿hN}q‰(hP]hQ]hR]hS]hU]uhWNhXhhC]qÂhe)ÅqÊ}qÁ(hHX���Investigator ToolkitqËhIh‚hJhKhLhhhN}qÈ(hP]hQ]hR]hS]hU]uhWKhC]qÍhaX���Investigator ToolkitqÎÖÅqÏ}qÌ(hHhËhIhÊubaubaubeubhe)ÅqÓ}qÔ(hHX“��Metacat implements the services needed to operate as a DataONE Member Node,
as described below.  The service interface then allows many different scientific
software tools for data management, analysis, visualization and other parts of
the scientific lifecycle to directly communicate with Metacat without being
further specialized beyond the support needed for DataONE.  This streamlines the
process of writing scientific software both for servers and client tools.qhIhñhJhKhLhhhN}qÒ(hP]hQ]hR]hS]hU]uhWKhXhhC]qÚhaX“��Metacat implements the services needed to operate as a DataONE Member Node,
as described below.  The service interface then allows many different scientific
software tools for data management, analysis, visualization and other parts of
the scientific lifecycle to directly communicate with Metacat without being
further specialized beyond the support needed for DataONE.  This streamlines the
process of writing scientific software both for servers and client tools.qÛÖÅqÙ}qı(hHhhIhÓubaubeubhE)Åqˆ}q˜(hHU�hIhFhJhKhLhMhN}q¯(hP]hQ]hR]hS]q˘h6ahU]q˙hauhWK&hXhhC]q˚(hZ)Åq¸}q˝(hHX���The DataONE Service Interfaceq˛hIhˆhJhKhLh^hN}qˇ(hP]hQ]hR]hS]hU]uhWK&hXhhC]r���haX���The DataONE Service Interfacer��ÖÅr��}r��(hHh˛hIh¸ubaubhe)År��}r��(hHXo��DataONE acheives interoperability by defining a lightweight but powerful set of
REST_ web services that can be implemented by various data management software
systems to allow those systems to effectively communicate with one another,
exchange data, metadata, and other scientific objects.  This `DataONE Service Interface`_
is an open standard that defines the communication protocols and technical
expectations for software components that wish to participate in the DataONE
federation. This service interface is divided into `four distinct tiers`_, with the
intention that any given software system may implement only those tiers that are
relevant to their repository; for example, a data aggregator might only implement
the Tier 1 interfaces that provide anonymous access to public data sets, while
a complete data management system like Metacat can implement all four tiers:hIhˆhJhKhLhhhN}r��(hP]hQ]hR]hS]hU]uhWK'hXhhC]r��(haXP���DataONE acheives interoperability by defining a lightweight but powerful set of
r��ÖÅr	��}r
��(hHXP���DataONE acheives interoperability by defining a lightweight but powerful set of
hIj��ubhk)År��}r��(hHX���REST_hnKhIj��hLhohN}r
��(UnameX���RESThqX<���http://en.wikipedia.org/wiki/Representational_state_transferr��hS]hR]hP]hQ]hU]uhC]r��haX���RESTr��ÖÅr��}r��(hHU�hIj��ubaubhaX”��� web services that can be implemented by various data management software
systems to allow those systems to effectively communicate with one another,
exchange data, metadata, and other scientific objects.  This r��ÖÅr��}r��(hHX”��� web services that can be implemented by various data management software
systems to allow those systems to effectively communicate with one another,
exchange data, metadata, and other scientific objects.  This hIj��ubhk)År��}r��(hHX���`DataONE Service Interface`_hnKhIj��hLhohN}r��(UnameX���DataONE Service InterfacehqX8���http://releases.dataone.org/online/d1-architecture-1.0.0r��hS]hR]hP]hQ]hU]uhC]r��haX���DataONE Service Interfacer��ÖÅr��}r��(hHU�hIj��ubaubhaXÃ���
is an open standard that defines the communication protocols and technical
expectations for software components that wish to participate in the DataONE
federation. This service interface is divided into r��ÖÅr��}r ��(hHXÃ���
is an open standard that defines the communication protocols and technical
expectations for software components that wish to participate in the DataONE
federation. This service interface is divided into hIj��ubhk)År!��}r"��(hHX���`four distinct tiers`_hnKhIj��hLhohN}r#��(UnameX���four distinct tiershqXH���http://releases.dataone.org/online/d1-architecture-1.0.0/apis/index.htmlr$��hS]hR]hP]hQ]hU]uhC]r%��haX���four distinct tiersr&��ÖÅr'��}r(��(hHU�hIj!��ubaubhaXI��, with the
intention that any given software system may implement only those tiers that are
relevant to their repository; for example, a data aggregator might only implement
the Tier 1 interfaces that provide anonymous access to public data sets, while
a complete data management system like Metacat can implement all four tiers:r)��ÖÅr*��}r+��(hHXI��, with the
intention that any given software system may implement only those tiers that are
relevant to their repository; for example, a data aggregator might only implement
the Tier 1 interfaces that provide anonymous access to public data sets, while
a complete data management system like Metacat can implement all four tiers:hIj��ubeubcdocutils.nodes
enumerated_list
r,��)År-��}r.��(hHU�hIhˆhJhKhLUenumerated_listr/��hN}r0��(Usuffixr1��U.hS]hR]hP]Uprefixr2��U�hQ]hU]Uenumtyper3��Uarabicr4��uhWK3hXhhC]r5��(hº)År6��}r7��(hHX,���**Tier 1:** Read-only, anonymous data accessr8��hIj-��hJhKhLh¿hN}r9��(hP]hQ]hR]hS]hU]uhWNhXhhC]r:��he)År;��}r<��(hHj8��hIj6��hJhKhLhhhN}r=��(hP]hQ]hR]hS]hU]uhWK3hC]r>��(cdocutils.nodes
strong
r?��)År@��}rA��(hHX���**Tier 1:**hN}rB��(hP]hQ]hR]hS]hU]uhIj;��hC]rC��haX���Tier 1:rD��ÖÅrE��}rF��(hHU�hIj@��ubahLUstrongrG��ubhaX!��� Read-only, anonymous data accessrH��ÖÅrI��}rJ��(hHX!��� Read-only, anonymous data accesshIj;��ubeubaubhº)ÅrK��}rL��(hHX=���**Tier 2:** Read-only, with authentication and access controlrM��hIj-��hJhKhLh¿hN}rN��(hP]hQ]hR]hS]hU]uhWNhXhhC]rO��he)ÅrP��}rQ��(hHjM��hIjK��hJhKhLhhhN}rR��(hP]hQ]hR]hS]hU]uhWK4hC]rS��(j?��)ÅrT��}rU��(hHX���**Tier 2:**hN}rV��(hP]hQ]hR]hS]hU]uhIjP��hC]rW��haX���Tier 2:rX��ÖÅrY��}rZ��(hHU�hIjT��ubahLjG��ubhaX2��� Read-only, with authentication and access controlr[��ÖÅr\��}r]��(hHX2��� Read-only, with authentication and access controlhIjP��ubeubaubhº)År^��}r_��(hHX���**Tier 3:** Full Write accessr`��hIj-��hJhKhLh¿hN}ra��(hP]hQ]hR]hS]hU]uhWNhXhhC]rb��he)Årc��}rd��(hHj`��hIj^��hJhKhLhhhN}re��(hP]hQ]hR]hS]hU]uhWK5hC]rf��(j?��)Årg��}rh��(hHX���**Tier 3:**hN}ri��(hP]hQ]hR]hS]hU]uhIjc��hC]rj��haX���Tier 3:rk��ÖÅrl��}rm��(hHU�hIjg��ubahLjG��ubhaX��� Full Write accessrn��ÖÅro��}rp��(hHX��� Full Write accesshIjc��ubeubaubhº)Årq��}rr��(hHX(���**Tier 4:** Replication target services
hIj-��hJhKhLh¿hN}rs��(hP]hQ]hR]hS]hU]uhWNhXhhC]rt��he)Åru��}rv��(hHX'���**Tier 4:** Replication target serviceshIjq��hJhKhLhhhN}rw��(hP]hQ]hR]hS]hU]uhWK6hC]rx��(j?��)Åry��}rz��(hHX���**Tier 4:**hN}r{��(hP]hQ]hR]hS]hU]uhIju��hC]r|��haX���Tier 4:r}��ÖÅr~��}r��(hHU�hIjy��ubahLjG��ubhaX��� Replication target servicesrÄ��ÖÅrÅ��}rÇ��(hHX��� Replication target serviceshIju��ubeubaubeubhé)ÅrÉ��}rÑ��(hHXF���.. _REST: http://en.wikipedia.org/wiki/Representational_state_transferhëKhIhˆhJhKhLhíhN}rÖ��(hqj��hS]rÜ��h-ahR]hP]hQ]hU]rá��h
auhWK8hXhhC]ubhé)Årà��}râ��(hHXW���.. _DataONE Service Interface: http://releases.dataone.org/online/d1-architecture-1.0.0hëKhIhˆhJhKhLhíhN}rä��(hqj��hS]rã��h2ahR]hP]hQ]hU]rå��hauhWK:hXhhC]ubhé)Årç��}ré��(hHXa���.. _four distinct tiers: http://releases.dataone.org/online/d1-architecture-1.0.0/apis/index.htmlhëKhIhˆhJhKhLhíhN}rè��(hqj$��hS]rê��h)ahR]hP]hQ]hU]rë��hauhWK<hXhhC]ubeubhE)Årí��}rì��(hHU�hIhFhJhKhLhMhN}rî��(hP]hQ]hR]hS]rï��h3ahU]rñ��hauhWK?hXhhC]ró��(hZ)Årò��}rô��(hHX���Member Nodesrö��hIjí��hJhKhLh^hN}rõ��(hP]hQ]hR]hS]hU]uhWK?hXhhC]rú��haX���Member Nodesrù��ÖÅrû��}rü��(hHjö��hIjò��ubaubhe)År†��}r°��(hHX(��In DataONE, Member Nodes represent the core of the network, in that they represent
particular scientific communities, manage and preserve their data and metadata, and
provide tools to their community for contributing, managing, and accessing data.
DataONE provides a standard way for these individual repositories to interact, and helps
to coordinate among the Member Nodes in the federation.  This allows Member Nodes
to provide services to each other, such as replication of data for backup and failover.
To be a Member Node, a repository must implement the Member Node service interface,
and then register with DataONE.  Metacat provides this implementation automatically,
and provides an easy configuration option to register a Metacat instance as a
DataONE Member Node (see configuration section below). If you are deploying a Metacat
instance, it is relatively simple to become a Member Node, but keep in mind that
DataONE is aiming for longevity and preservation, and so is selecting for nodes
that have long-term data preservation as part of their mission.r¢��hIjí��hJhKhLhhhN}r£��(hP]hQ]hR]hS]hU]uhWK@hXhhC]r§��haX(��In DataONE, Member Nodes represent the core of the network, in that they represent
particular scientific communities, manage and preserve their data and metadata, and
provide tools to their community for contributing, managing, and accessing data.
DataONE provides a standard way for these individual repositories to interact, and helps
to coordinate among the Member Nodes in the federation.  This allows Member Nodes
to provide services to each other, such as replication of data for backup and failover.
To be a Member Node, a repository must implement the Member Node service interface,
and then register with DataONE.  Metacat provides this implementation automatically,
and provides an easy configuration option to register a Metacat instance as a
DataONE Member Node (see configuration section below). If you are deploying a Metacat
instance, it is relatively simple to become a Member Node, but keep in mind that
DataONE is aiming for longevity and preservation, and so is selecting for nodes
that have long-term data preservation as part of their mission.r•��ÖÅr¶��}rß��(hHj¢��hIj†��ubaubeubhE)År®��}r©��(hHU�hIhFhJhKhLhMhN}r™��(hP]hQ]hR]hS]r´��h8ahU]r¨��hauhWKOhXhhC]r≠��(hZ)ÅrÆ��}rØ��(hHX���Coordinating Nodesr∞��hIj®��hJhKhLh^hN}r±��(hP]hQ]hR]hS]hU]uhWKOhXhhC]r≤��haX���Coordinating Nodesr≥��ÖÅr¥��}rµ��(hHj∞��hIjÆ��ubaubhe)År∂��}r∑��(hHX˙���The DataONE Coordinating Nodes provide a set of services to Member Nodes that
allow Member Nodes to easily interact with one another and to provide a unified
view of the whole DataONE Federation.  The main services provided by Coordinating
Nodes are:r∏��hIj®��hJhKhLhhhN}rπ��(hP]hQ]hR]hS]hU]uhWKPhXhhC]r∫��haX˙���The DataONE Coordinating Nodes provide a set of services to Member Nodes that
allow Member Nodes to easily interact with one another and to provide a unified
view of the whole DataONE Federation.  The main services provided by Coordinating
Nodes are:rª��ÖÅrº��}rΩ��(hHj∏��hIj∂��ubaubhµ)Åræ��}rø��(hHU�hIj®��hJhKhLh∏hN}r¿��(h∫X���*hS]hR]hP]hQ]hU]uhWKUhXhhC]r¡��(hº)År¬��}r√��(hHXF���Global search index for all metadata and web portal for data discoveryrƒ��hIjæ��hJhKhLh¿hN}r≈��(hP]hQ]hR]hS]hU]uhWNhXhhC]r∆��he)År«��}r»��(hHjƒ��hIj¬��hJhKhLhhhN}r…��(hP]hQ]hR]hS]hU]uhWKUhC]r ��haXF���Global search index for all metadata and web portal for data discoveryrÀ��ÖÅrÃ��}rÕ��(hHjƒ��hIj«��ubaubaubhº)ÅrŒ��}rœ��(hHXO���Resolution service to map unique identifiers to the Member Nodes that hold datar–��hIjæ��hJhKhLh¿hN}r—��(hP]hQ]hR]hS]hU]uhWNhXhhC]r“��he)År”��}r‘��(hHj–��hIjŒ��hJhKhLhhhN}r’��(hP]hQ]hR]hS]hU]uhWKVhC]r÷��haXO���Resolution service to map unique identifiers to the Member Nodes that hold datar◊��ÖÅrÿ��}rŸ��(hHj–��hIj”��ubaubaubhº)År⁄��}r€��(hHXO���Authentication against a shared set of accounts based on CILogon_ and InCommon_r‹��hIjæ��hJhKhLh¿hN}r›��(hP]hQ]hR]hS]hU]uhWNhXhhC]rfi��he)Årfl��}r‡��(hHj‹��hIj⁄��hJhKhLhhhN}r·��(hP]hQ]hR]hS]hU]uhWKWhC]r‚��(haX9���Authentication against a shared set of accounts based on r„��ÖÅr‰��}rÂ��(hHX9���Authentication against a shared set of accounts based on hIjfl��ubhk)ÅrÊ��}rÁ��(hHX���CILogon_hnKhIjfl��hLhohN}rË��(UnameX���CILogonhqX���http://www.cilogon.orgrÈ��hS]hR]hP]hQ]hU]uhC]rÍ��haX���CILogonrÎ��ÖÅrÏ��}rÌ��(hHU�hIjÊ��ubaubhaX��� and rÓ��ÖÅrÔ��}r��(hHX��� and hIjfl��ubhk)ÅrÒ��}rÚ��(hHX	���InCommon_hnKhIjfl��hLhohN}rÛ��(UnameX���InCommonhqX���http://incommon.orgrÙ��hS]hR]hP]hQ]hU]uhC]rı��haX���InCommonrˆ��ÖÅr˜��}r¯��(hHU�hIjÒ��ubaubeubaubhº)År˘��}r˙��(hHXh���Replication management services to reliably replicate data according to
policies set by the Member NodeshIjæ��hJhKhLh¿hN}r˚��(hP]hQ]hR]hS]hU]uhWNhXhhC]r¸��he)År˝��}r˛��(hHXh���Replication management services to reliably replicate data according to
policies set by the Member Nodesrˇ��hIj˘��hJhKhLhhhN}r���(hP]hQ]hR]hS]hU]uhWKXhC]r��haXh���Replication management services to reliably replicate data according to
policies set by the Member Nodesr��ÖÅr��}r��(hHjˇ��hIj˝��ubaubaubhº)År��}r��(hHX=���Fixity checking to ensure that preserved objects remain validr��hIjæ��hJhKhLh¿hN}r��(hP]hQ]hR]hS]hU]uhWNhXhhC]r	��he)År
��}r��(hHj��hIj��hJhKhLhhhN}r��(hP]hQ]hR]hS]hU]uhWKZhC]r
��haX=���Fixity checking to ensure that preserved objects remain validr��ÖÅr��}r��(hHj��hIj
��ubaubaubhº)År��}r��(hHX'���Member Node registration and managementr��hIjæ��hJhKhLh¿hN}r��(hP]hQ]hR]hS]hU]uhWNhXhhC]r��he)År��}r��(hHj��hIj��hJhKhLhhhN}r��(hP]hQ]hR]hS]hU]uhWK[hC]r��haX'���Member Node registration and managementr��ÖÅr��}r��(hHj��hIj��ubaubaubhº)År��}r��(hHX?���Aggregated logging for data access across the whole federation
hIjæ��hJhKhLh¿hN}r��(hP]hQ]hR]hS]hU]uhWNhXhhC]r ��he)År!��}r"��(hHX>���Aggregated logging for data access across the whole federationr#��hIj��hJhKhLhhhN}r$��(hP]hQ]hR]hS]hU]uhWK\hC]r%��haX>���Aggregated logging for data access across the whole federationr&��ÖÅr'��}r(��(hHj#��hIj!��ubaubaubeubhe)År)��}r*��(hHX§��Three geographically distributed Coordinating Nodes replicate these coordinating
services at UC Santa Barbara, the University of New Mexico, and the Oak Ridge Campus.
Coordinating Nodes are set up in a fully redundant manner, such that any of the coordinating
nodes can be offline and the others will continue to provide availability of the services
without interruption.  The DataONE services expose their services at::hIj®��hJhKhLhhhN}r+��(hP]hQ]hR]hS]hU]uhWK^hXhhC]r,��haX£��Three geographically distributed Coordinating Nodes replicate these coordinating
services at UC Santa Barbara, the University of New Mexico, and the Oak Ridge Campus.
Coordinating Nodes are set up in a fully redundant manner, such that any of the coordinating
nodes can be offline and the others will continue to provide availability of the services
without interruption.  The DataONE services expose their services at:r-��ÖÅr.��}r/��(hHX£��Three geographically distributed Coordinating Nodes replicate these coordinating
services at UC Santa Barbara, the University of New Mexico, and the Oak Ridge Campus.
Coordinating Nodes are set up in a fully redundant manner, such that any of the coordinating
nodes can be offline and the others will continue to provide availability of the services
without interruption.  The DataONE services expose their services at:hIj)��ubaubcdocutils.nodes
literal_block
r0��)År1��}r2��(hHX���https://cn.dataone.org/cnhIj®��hJhKhLU
literal_blockr3��hN}r4��(U	xml:spacer5��Upreserver6��hS]hR]hP]hQ]hU]uhWKdhXhhC]r7��haX���https://cn.dataone.org/cnr8��ÖÅr9��}r:��(hHU�hIj1��ubaubhe)År;��}r<��(hHX.���And the DataONE search portal is available at:r=��hIj®��hJhKhLhhhN}r>��(hP]hQ]hR]hS]hU]uhWKfhXhhC]r?��haX.���And the DataONE search portal is available at:r@��ÖÅrA��}rB��(hHj=��hIj;��ubaubcdocutils.nodes
block_quote
rC��)ÅrD��}rE��(hHU�hIj®��hJhKhLUblock_quoterF��hN}rG��(hP]hQ]hR]hS]hU]uhWNhXhhC]rH��he)ÅrI��}rJ��(hHX���https://cn.dataone.org/rK��hIjD��hJhKhLhhhN}rL��(hP]hQ]hR]hS]hU]uhWKhhC]rM��hk)ÅrN��}rO��(hHjK��hN}rP��(UrefurijK��hS]hR]hP]hQ]hU]uhIjI��hC]rQ��haX���https://cn.dataone.org/rR��ÖÅrS��}rT��(hHU�hIjN��ubahLhoubaubaubhé)ÅrU��}rV��(hHX#���.. _CILogon: http://www.cilogon.orghëKhIj®��hJhKhLhíhN}rW��(hqjÈ��hS]rX��hBahR]hP]hQ]hU]rY��hauhWKjhXhhC]ubhé)ÅrZ��}r[��(hHX!���.. _InCommon: http://incommon.orghëKhIj®��hJhKhLhíhN}r\��(hqjÙ��hS]r]��h<ahR]hP]hQ]hU]r^��hauhWKlhXhhC]ubeubhE)År_��}r`��(hHU�hIhFhJhKhLhMhN}ra��(hP]hQ]hR]hS]rb��h*ahU]rc��hauhWKohXhhC]rd��(hZ)Åre��}rf��(hHX���Investigator Toolkitrg��hIj_��hJhKhLh^hN}rh��(hP]hQ]hR]hS]hU]uhWKohXhhC]ri��haX���Investigator Toolkitrj��ÖÅrk��}rl��(hHjg��hIje��ubaubhe)Årm��}rn��(hHXõ��In order to provide scientists with convenient access to the data and metadata in
DataONE, the third component represents a library of software tools that have been
adapted to work with DataONE via the service interface and can be used to
discover, manage, analyze, and visualize data in DataONE.  For example, DataONE
plans to release metadata editors (e.g., Morpho), data search tools (e.g., Mercury),
data access tools (e.g., ONEDrive), and data analysis tools (e.g., R) that all
know how to interact with DataONE Member Nodes and Coordinating Nodes.  Consequently,
scientists will be able to access data from any DataONE Member Node, such as a Metacat
node, directly from within the R environment.  In addition, software tools that
are written to work with one Member Node should also work with others, thereby
greatly increasing the efficiency of creating an entire toolkit of software that
is useful to investigators.ro��hIj_��hJhKhLhhhN}rp��(hP]hQ]hR]hS]hU]uhWKphXhhC]rq��haXõ��In order to provide scientists with convenient access to the data and metadata in
DataONE, the third component represents a library of software tools that have been
adapted to work with DataONE via the service interface and can be used to
discover, manage, analyze, and visualize data in DataONE.  For example, DataONE
plans to release metadata editors (e.g., Morpho), data search tools (e.g., Mercury),
data access tools (e.g., ONEDrive), and data analysis tools (e.g., R) that all
know how to interact with DataONE Member Nodes and Coordinating Nodes.  Consequently,
scientists will be able to access data from any DataONE Member Node, such as a Metacat
node, directly from within the R environment.  In addition, software tools that
are written to work with one Member Node should also work with others, thereby
greatly increasing the efficiency of creating an entire toolkit of software that
is useful to investigators.rr��ÖÅrs��}rt��(hHjo��hIjm��ubaubhe)Åru��}rv��(hHX†��Because DataONE services are REST web services, software written in any
programming language can be adapted to interact with DataONE.
In addition, to ease the process of adapting tools to work with DataONE, libraries
are provided for common programming languages such as Java (d1-libclient-java)
and Python (d1_libclient-python) are provided that allow simple function calls
to be used to access any DataONE service.rw��hIj_��hJhKhLhhhN}rx��(hP]hQ]hR]hS]hU]uhWK}hXhhC]ry��haX†��Because DataONE services are REST web services, software written in any
programming language can be adapted to interact with DataONE.
In addition, to ease the process of adapting tools to work with DataONE, libraries
are provided for common programming languages such as Java (d1-libclient-java)
and Python (d1_libclient-python) are provided that allow simple function calls
to be used to access any DataONE service.rz��ÖÅr{��}r|��(hHjw��hIju��ubaubeubhE)År}��}r~��(hHU�hIhFhJhKhLhMhN}r��(hP]hQ]hR]hS]rÄ��h7ahU]rÅ��hauhWKÖhXhhC]rÇ��(hZ)ÅrÉ��}rÑ��(hHX$���Configuring Metacat as a Member NoderÖ��hIj}��hJhKhLh^hN}rÜ��(hP]hQ]hR]hS]hU]uhWKÖhXhhC]rá��haX$���Configuring Metacat as a Member Noderà��ÖÅrâ��}rä��(hHjÖ��hIjÉ��ubaubhe)Årã��}rå��(hHX≠���Configuring Metacat as a DataONE Member Node is accomplished with the standard
Metacat Administrative configuration utility. To access the utility, visit the
following URL::hIj}��hJhKhLhhhN}rç��(hP]hQ]hR]hS]hU]uhWKÜhXhhC]ré��haX¨���Configuring Metacat as a DataONE Member Node is accomplished with the standard
Metacat Administrative configuration utility. To access the utility, visit the
following URL:rè��ÖÅrê��}rë��(hHX¨���Configuring Metacat as a DataONE Member Node is accomplished with the standard
Metacat Administrative configuration utility. To access the utility, visit the
following URL:hIjã��ubaubj0��)Årí��}rì��(hHX%���http://<yourhost.org>/<context>/adminhIj}��hJhKhLj3��hN}rî��(j5��j6��hS]hR]hP]hQ]hU]uhWKähXhhC]rï��haX%���http://<yourhost.org>/<context>/adminrñ��ÖÅró��}rò��(hHU�hIjí��ubaubhe)Årô��}rö��(hHX��where ``<yourhost.org>`` represents the hostname of your webserver running metacat,
and ``<context>`` is the name of the web context in which Metacat was installed.
Once at the administrative utility, click on the DataONE configuration link, which
should show the following screen:hIj}��hJhKhLhhhN}rõ��(hP]hQ]hR]hS]hU]uhWKåhXhhC]rú��(haX���where rù��ÖÅrû��}rü��(hHX���where hIjô��ubcdocutils.nodes
literal
r†��)År°��}r¢��(hHX���``<yourhost.org>``hN}r£��(hP]hQ]hR]hS]hU]uhIjô��hC]r§��haX���<yourhost.org>r•��ÖÅr¶��}rß��(hHU�hIj°��ubahLUliteralr®��ubhaX@��� represents the hostname of your webserver running metacat,
and r©��ÖÅr™��}r´��(hHX@��� represents the hostname of your webserver running metacat,
and hIjô��ubj†��)År¨��}r≠��(hHX
���``<context>``hN}rÆ��(hP]hQ]hR]hS]hU]uhIjô��hC]rØ��haX	���<context>r∞��ÖÅr±��}r≤��(hHU�hIj¨��ubahLj®��ubhaX¥��� is the name of the web context in which Metacat was installed.
Once at the administrative utility, click on the DataONE configuration link, which
should show the following screen:r≥��ÖÅr¥��}rµ��(hHX¥��� is the name of the web context in which Metacat was installed.
Once at the administrative utility, click on the DataONE configuration link, which
should show the following screen:hIjô��ubeubcdocutils.nodes
figure
r∂��)År∑��}r∏��(hHU�hIj}��hJhKhLUfigurerπ��hN}r∫��(Ualignrª��X���centerhS]rº��Uid1rΩ��ahR]hP]hQ]hU]uhWNhXhhC]ræ��(cdocutils.nodes
image
rø��)År¿��}r¡��(hHXÜ���.. figure:: images/screenshots/image068.png
   :align: center

   The configuration screen for configuring Metacat as a DataONE node.
hN}r¬��(UuriX���images/screenshots/image068.pngr√��hS]hR]hP]hQ]U
candidatesrƒ��}r≈��U*j√��shU]uhIj∑��hC]hLUimager∆��ubcdocutils.nodes
caption
r«��)År»��}r…��(hHXC���The configuration screen for configuring Metacat as a DataONE node.r ��hIj∑��hJhKhLUcaptionrÀ��hN}rÃ��(hP]hQ]hR]hS]hU]uhWKîhC]rÕ��haXC���The configuration screen for configuring Metacat as a DataONE node.rŒ��ÖÅrœ��}r–��(hHj ��hIj»��ubaubeubhe)År—��}r“��(hHXí��To configure Metacat as a node in the DataONE network, configure the properties shown
in the figure above.  The Node Name should be a short name for the node that can
be used in user interface displays that list the node.  For example, one node in
DataONE is the 'Knowledge Network for Biocomplexity'.  Also provide a brief sentence
or two describing the node, including its intended scope and purpose.r”��hIj}��hJhKhLhhhN}r‘��(hP]hQ]hR]hS]hU]uhWKñhXhhC]r’��haXí��To configure Metacat as a node in the DataONE network, configure the properties shown
in the figure above.  The Node Name should be a short name for the node that can
be used in user interface displays that list the node.  For example, one node in
DataONE is the 'Knowledge Network for Biocomplexity'.  Also provide a brief sentence
or two describing the node, including its intended scope and purpose.r÷��ÖÅr◊��}rÿ��(hHj”��hIj—��ubaubhe)ÅrŸ��}r⁄��(hHXÃ��The Node Identifier field is a unique identifier assigned by DataONE to identify
this node even when the node changes physical locations over time.  After Metacat
registers with the DataONE Coordinating Nodes (when you click 'Register' at the
bottom of this form), the Node Identifier should not be changed.  **It is critical that
you not change the Node Identifier after registration**, as that will break the connection with the
DataONE network.  Changing this field should only happen in the rare case
in which a new Metacat instance is being established to act as the provider for an
existing DataONE Member Node, in which case the field can be edited to set it to
the value of a valid, existing Node Identifier.hIj}��hJhKhLhhhN}r€��(hP]hQ]hR]hS]hU]uhWKúhXhhC]r‹��(haX5��The Node Identifier field is a unique identifier assigned by DataONE to identify
this node even when the node changes physical locations over time.  After Metacat
registers with the DataONE Coordinating Nodes (when you click 'Register' at the
bottom of this form), the Node Identifier should not be changed.  r›��ÖÅrfi��}rfl��(hHX5��The Node Identifier field is a unique identifier assigned by DataONE to identify
this node even when the node changes physical locations over time.  After Metacat
registers with the DataONE Coordinating Nodes (when you click 'Register' at the
bottom of this form), the Node Identifier should not be changed.  hIjŸ��ubj?��)År‡��}r·��(hHXM���**It is critical that
you not change the Node Identifier after registration**hN}r‚��(hP]hQ]hR]hS]hU]uhIjŸ��hC]r„��haXI���It is critical that
you not change the Node Identifier after registrationr‰��ÖÅrÂ��}rÊ��(hHU�hIj‡��ubahLjG��ubhaXJ��, as that will break the connection with the
DataONE network.  Changing this field should only happen in the rare case
in which a new Metacat instance is being established to act as the provider for an
existing DataONE Member Node, in which case the field can be edited to set it to
the value of a valid, existing Node Identifier.rÁ��ÖÅrË��}rÈ��(hHXJ��, as that will break the connection with the
DataONE network.  Changing this field should only happen in the rare case
in which a new Metacat instance is being established to act as the provider for an
existing DataONE Member Node, in which case the field can be edited to set it to
the value of a valid, existing Node Identifier.hIjŸ��ubeubhe)ÅrÍ��}rÎ��(hHX"��The Node Subject and Node Certificate Path are linked fields that are critical for
proper operation of the node.  To act as a Member Node in DataONE, you must obtain
an X.509 certificate that can be used to identify this node and allow it to securely
communicate using SSL with other nodes and client applications.  This certificate can
be obtained from the DataONE Certificate Authority.
Once you have the certificate in hand, use a tool such
as ``openssl`` to determine the exact subject distinguished name in the
certificate, and use that to set the Node Subject field.  Set the Node
Certificate Path to the location on the system in which you stored the
certificate file. Be sure to protect the certificate file, as it contains the
private key that is used to authenticate this node within DataONE.hIj}��hJhKhLhhhN}rÏ��(hP]hQ]hR]hS]hU]uhWK¶hXhhC]rÌ��(haXø��The Node Subject and Node Certificate Path are linked fields that are critical for
proper operation of the node.  To act as a Member Node in DataONE, you must obtain
an X.509 certificate that can be used to identify this node and allow it to securely
communicate using SSL with other nodes and client applications.  This certificate can
be obtained from the DataONE Certificate Authority.
Once you have the certificate in hand, use a tool such
as rÓ��ÖÅrÔ��}r��(hHXø��The Node Subject and Node Certificate Path are linked fields that are critical for
proper operation of the node.  To act as a Member Node in DataONE, you must obtain
an X.509 certificate that can be used to identify this node and allow it to securely
communicate using SSL with other nodes and client applications.  This certificate can
be obtained from the DataONE Certificate Authority.
Once you have the certificate in hand, use a tool such
as hIjÍ��ubj†��)ÅrÒ��}rÚ��(hHX���``openssl``hN}rÛ��(hP]hQ]hR]hS]hU]uhIjÍ��hC]rÙ��haX���opensslrı��ÖÅrˆ��}r˜��(hHU�hIjÒ��ubahLj®��ubhaXX�� to determine the exact subject distinguished name in the
certificate, and use that to set the Node Subject field.  Set the Node
Certificate Path to the location on the system in which you stored the
certificate file. Be sure to protect the certificate file, as it contains the
private key that is used to authenticate this node within DataONE.r¯��ÖÅr˘��}r˙��(hHXX�� to determine the exact subject distinguished name in the
certificate, and use that to set the Node Subject field.  Set the Node
Certificate Path to the location on the system in which you stored the
certificate file. Be sure to protect the certificate file, as it contains the
private key that is used to authenticate this node within DataONE.hIj��ubeubcdocutils.nodes
note
r˚��)År¸��}r˝��(hHX¥���For Tier 2 deployments and above, the Metacat Member Node must have Apache configured to request
client certificates. Detailed instructions are included at the end of this chapter.hIj}��hJhKhLUnoter˛��hN}rˇ��(hP]hQ]hR]hS]hU]uhWNhXhhC]r���he)År��}r��(hHX¥���For Tier 2 deployments and above, the Metacat Member Node must have Apache configured to request
client certificates. Detailed instructions are included at the end of this chapter.r��hIj¸��hJhKhLhhhN}r��(hP]hQ]hR]hS]hU]uhWK¥hC]r��haX¥���For Tier 2 deployments and above, the Metacat Member Node must have Apache configured to request
client certificates. Detailed instructions are included at the end of this chapter.r��ÖÅr��}r��(hHj��hIj��ubaubaubhe)År	��}r
��(hHX+��The ``Enable DataONE Services`` checkbox allows the administrator to decide whether to
turn on synchronization with the DataONE network.  When this box is unchecked, the
DataONE Coordinating Nodes will not attempt to synchronize at all, but when checked,
then DataONE will periodically contact the node to synchronize all metadata content.
To be part of the DataONE network, this box must be checked as that allows
DataONE to receive a copy of the metadata associated with each object in the Metacat
system.  The switch is provided for those rare cases when a node needs to be disconnected
from DataONE for maintenance or service outages.  When the box is checked, DataONE
contacts the node using the schedule provided in the ``Synchronization Schedule``
fields.  The example in the dialog above has synchronization occurring once every third
minutes at the 10 second mark of those minutes.  The syntax for these schedules
follows the Quartz Crontab Entry syntax, which provides for many flexible schedule
configurations.  If the administrator desires a less frequent schedule, such as daily,
that can be configured by changing the ``*`` in the ``Hours`` field to be a concrete
hour (such as ``11``) and the ``Minutes`` field to a concrete value like``15``,
which would change the schedule to synchronize at 11:15 am daily.hIj}��hJhKhLhhhN}r��(hP]hQ]hR]hS]hU]uhWK∑hXhhC]r��(haX���The r
��ÖÅr��}r��(hHX���The hIj	��ubj†��)År��}r��(hHX���``Enable DataONE Services``hN}r��(hP]hQ]hR]hS]hU]uhIj	��hC]r��haX���Enable DataONE Servicesr��ÖÅr��}r��(hHU�hIj��ubahLj®��ubhaX∑�� checkbox allows the administrator to decide whether to
turn on synchronization with the DataONE network.  When this box is unchecked, the
DataONE Coordinating Nodes will not attempt to synchronize at all, but when checked,
then DataONE will periodically contact the node to synchronize all metadata content.
To be part of the DataONE network, this box must be checked as that allows
DataONE to receive a copy of the metadata associated with each object in the Metacat
system.  The switch is provided for those rare cases when a node needs to be disconnected
from DataONE for maintenance or service outages.  When the box is checked, DataONE
contacts the node using the schedule provided in the r��ÖÅr��}r��(hHX∑�� checkbox allows the administrator to decide whether to
turn on synchronization with the DataONE network.  When this box is unchecked, the
DataONE Coordinating Nodes will not attempt to synchronize at all, but when checked,
then DataONE will periodically contact the node to synchronize all metadata content.
To be part of the DataONE network, this box must be checked as that allows
DataONE to receive a copy of the metadata associated with each object in the Metacat
system.  The switch is provided for those rare cases when a node needs to be disconnected
from DataONE for maintenance or service outages.  When the box is checked, DataONE
contacts the node using the schedule provided in the hIj	��ubj†��)År��}r��(hHX���``Synchronization Schedule``hN}r��(hP]hQ]hR]hS]hU]uhIj	��hC]r��haX���Synchronization Scheduler��ÖÅr��}r ��(hHU�hIj��ubahLj®��ubhaXz��
fields.  The example in the dialog above has synchronization occurring once every third
minutes at the 10 second mark of those minutes.  The syntax for these schedules
follows the Quartz Crontab Entry syntax, which provides for many flexible schedule
configurations.  If the administrator desires a less frequent schedule, such as daily,
that can be configured by changing the r!��ÖÅr"��}r#��(hHXz��
fields.  The example in the dialog above has synchronization occurring once every third
minutes at the 10 second mark of those minutes.  The syntax for these schedules
follows the Quartz Crontab Entry syntax, which provides for many flexible schedule
configurations.  If the administrator desires a less frequent schedule, such as daily,
that can be configured by changing the hIj	��ubj†��)År$��}r%��(hHX���``*``hN}r&��(hP]hQ]hR]hS]hU]uhIj	��hC]r'��haX���*ÖÅr(��}r)��(hHU�hIj$��ubahLj®��ubhaX��� in the r*��ÖÅr+��}r,��(hHX��� in the hIj	��ubj†��)År-��}r.��(hHX	���``Hours``hN}r/��(hP]hQ]hR]hS]hU]uhIj	��hC]r0��haX���Hoursr1��ÖÅr2��}r3��(hHU�hIj-��ubahLj®��ubhaX&��� field to be a concrete
hour (such as r4��ÖÅr5��}r6��(hHX&��� field to be a concrete
hour (such as hIj	��ubj†��)År7��}r8��(hHX���``11``hN}r9��(hP]hQ]hR]hS]hU]uhIj	��hC]r:��haX���11r;��ÖÅr<��}r=��(hHU�hIj7��ubahLj®��ubhaX
���) and the r>��ÖÅr?��}r@��(hHX
���) and the hIj	��ubj†��)ÅrA��}rB��(hHX���``Minutes``hN}rC��(hP]hQ]hR]hS]hU]uhIj	��hC]rD��haX���MinutesrE��ÖÅrF��}rG��(hHU�hIjA��ubahLj®��ubhaXh��� field to a concrete value like``15``,
which would change the schedule to synchronize at 11:15 am daily.rH��ÖÅrI��}rJ��(hHXh��� field to a concrete value like``15``,
which would change the schedule to synchronize at 11:15 am daily.hIj	��ubeubhe)ÅrK��}rL��(hHXN��The Replication section is used to configure replication options for the node
overall and for objects stored in Metacat.  The ``Accept and Store Replicas``
checkbox is used to indicate that the administrator of this node is willing to allow
replica data and metadata from other Member Nodes to be stored on this node.  We
encourage people to allow replication to their nodes, as this increases the
scalability and flexibility of the network overall.  The three "Default" fields set
the default values for the replication policies for data and metadata on this node
that are generated when System Metadata is not available for an object (such as when
it originates from a client that is not DataONE compliant).  The ``Default Number of
Replicas`` determines how many replica copies of the object should be stored on
other Member Nodes.  A value of 0 or less indicates that no replicas should be
stored.  In addition, you can specify a list of nodes that are either preferred for
use when choosing replica nodes, or that are blocked from use as replica nodes.
This allows Member Nodes to set up bidirectional agreements with partner nodes to
replicate data across their sites. The values for both ``Default Preferred Nodes``
and ``Default Blocked Nodes`` is a comma-separated list of NodeReference identifiers
that were assigned to the target nodes by DataONE.hIj}��hJhKhLhhhN}rM��(hP]hQ]hR]hS]hU]uhWK»hXhhC]rN��(haX~���The Replication section is used to configure replication options for the node
overall and for objects stored in Metacat.  The rO��ÖÅrP��}rQ��(hHX~���The Replication section is used to configure replication options for the node
overall and for objects stored in Metacat.  The hIjK��ubj†��)ÅrR��}rS��(hHX���``Accept and Store Replicas``hN}rT��(hP]hQ]hR]hS]hU]uhIjK��hC]rU��haX���Accept and Store ReplicasrV��ÖÅrW��}rX��(hHU�hIjR��ubahLj®��ubhaX0��
checkbox is used to indicate that the administrator of this node is willing to allow
replica data and metadata from other Member Nodes to be stored on this node.  We
encourage people to allow replication to their nodes, as this increases the
scalability and flexibility of the network overall.  The three "Default" fields set
the default values for the replication policies for data and metadata on this node
that are generated when System Metadata is not available for an object (such as when
it originates from a client that is not DataONE compliant).  The rY��ÖÅrZ��}r[��(hHX0��
checkbox is used to indicate that the administrator of this node is willing to allow
replica data and metadata from other Member Nodes to be stored on this node.  We
encourage people to allow replication to their nodes, as this increases the
scalability and flexibility of the network overall.  The three "Default" fields set
the default values for the replication policies for data and metadata on this node
that are generated when System Metadata is not available for an object (such as when
it originates from a client that is not DataONE compliant).  The hIjK��ubj†��)År\��}r]��(hHX���``Default Number of
Replicas``hN}r^��(hP]hQ]hR]hS]hU]uhIjK��hC]r_��haX���Default Number of
Replicasr`��ÖÅra��}rb��(hHU�hIj\��ubahLj®��ubhaX¬�� determines how many replica copies of the object should be stored on
other Member Nodes.  A value of 0 or less indicates that no replicas should be
stored.  In addition, you can specify a list of nodes that are either preferred for
use when choosing replica nodes, or that are blocked from use as replica nodes.
This allows Member Nodes to set up bidirectional agreements with partner nodes to
replicate data across their sites. The values for both rc��ÖÅrd��}re��(hHX¬�� determines how many replica copies of the object should be stored on
other Member Nodes.  A value of 0 or less indicates that no replicas should be
stored.  In addition, you can specify a list of nodes that are either preferred for
use when choosing replica nodes, or that are blocked from use as replica nodes.
This allows Member Nodes to set up bidirectional agreements with partner nodes to
replicate data across their sites. The values for both hIjK��ubj†��)Årf��}rg��(hHX���``Default Preferred Nodes``hN}rh��(hP]hQ]hR]hS]hU]uhIjK��hC]ri��haX���Default Preferred Nodesrj��ÖÅrk��}rl��(hHU�hIjf��ubahLj®��ubhaX���
and rm��ÖÅrn��}ro��(hHX���
and hIjK��ubj†��)Årp��}rq��(hHX���``Default Blocked Nodes``hN}rr��(hP]hQ]hR]hS]hU]uhIjK��hC]rs��haX���Default Blocked Nodesrt��ÖÅru��}rv��(hHU�hIjp��ubahLj®��ubhaXj��� is a comma-separated list of NodeReference identifiers
that were assigned to the target nodes by DataONE.rw��ÖÅrx��}ry��(hHXj��� is a comma-separated list of NodeReference identifiers
that were assigned to the target nodes by DataONE.hIjK��ubeubhe)Årz��}r{��(hHX¬��Once these parameters have been properly set, us the ``Register`` button to
request to register with the DataONE Coordinating Node.  This will generate a
registration document describing this Metacat instance and send it to the
Coordinating Node registration service.  At that point, all that remains is to wait for
the DataONE administrators to approve the node registration.  Details of the approval
process can be found on the `DataONE web site`_.hIj}��hJhKhLhhhN}r|��(hP]hQ]hR]hS]hU]uhWK⁄hXhhC]r}��(haX5���Once these parameters have been properly set, us the r~��ÖÅr��}rÄ��(hHX5���Once these parameters have been properly set, us the hIjz��ubj†��)ÅrÅ��}rÇ��(hHX���``Register``hN}rÉ��(hP]hQ]hR]hS]hU]uhIjz��hC]rÑ��haX���RegisterrÖ��ÖÅrÜ��}rá��(hHU�hIjÅ��ubahLj®��ubhaXm�� button to
request to register with the DataONE Coordinating Node.  This will generate a
registration document describing this Metacat instance and send it to the
Coordinating Node registration service.  At that point, all that remains is to wait for
the DataONE administrators to approve the node registration.  Details of the approval
process can be found on the rà��ÖÅrâ��}rä��(hHXm�� button to
request to register with the DataONE Coordinating Node.  This will generate a
registration document describing this Metacat instance and send it to the
Coordinating Node registration service.  At that point, all that remains is to wait for
the DataONE administrators to approve the node registration.  Details of the approval
process can be found on the hIjz��ubhk)Årã��}rå��(hHX���`DataONE web site`_hnKhIjz��hLhohN}rç��(UnameX���DataONE web sitehqX���http://www.dataone.orgré��hS]hR]hP]hQ]hU]uhC]rè��haX���DataONE web siterê��ÖÅrë��}rí��(hHU�hIjã��ubaubhaX���.ÖÅrì��}rî��(hHX���.hIjz��ubeubhé)Årï��}rñ��(hHX,���.. _DataONE web site: http://www.dataone.orghëKhIj}��hJhKhLhíhN}ró��(hqjé��hS]rò��h1ahR]hP]hQ]hU]rô��hauhWK·hXhhC]ubeubhE)Årö��}rõ��(hHU�hIhFhJhKhLhMhN}rú��(hP]hQ]hR]hS]rù��h=ahU]rû��hauhWK‰hXhhC]rü��(hZ)År†��}r°��(hHX���Access Control Policiesr¢��hIjö��hJhKhLh^hN}r£��(hP]hQ]hR]hS]hU]uhWK‰hXhhC]r§��haX���Access Control Policiesr•��ÖÅr¶��}rß��(hHj¢��hIj†��ubaubhe)År®��}r©��(hHX}��Metacat has supported fine grained access control for objects in the system since
its inception.  DataONE has devised a simple but effective access control system
that is compatible with the prior system in Metacat.  For each object in the DataONE
system (including data objects, scientific metadata objects, and resource maps),
a SystemMetadata_ document describes the critical metadata needed to manage that
object in the system.  This metadata includes a ``RightsHolder`` field and an
``AuthoritativeMemberNode`` field that are used to list the people and node that
have ultimate control over the disposition of the object.  In addition, a separate
AccessPolicy_ can be included in the ``SystemMetadata`` for the object.  This ``AccessPolicy``
consists of a set of rules that grant additional permissions to other people,
groups, and systems in DataONE.  For example, for one data file, two users
(Alice and Bob) may be able make changes to the object, and the general public may
be allowed to read the object.  In the absence of explicit rules extending these permissions,
Metacat enforces the rule that only the ``RightsHolder`` and ``AuthoritativeMemberNode`` have
rights to the object, and that the Coordinating Node can manage ``SystemMetadata``
for the object.  An example AccessPolicy that might be submitted with a dataset
(giving Alice and Bob permission to read and write the object) follows:hIjö��hJhKhLhhhN}r™��(hP]hQ]hR]hS]hU]uhWKÂhXhhC]r´��(haXK��Metacat has supported fine grained access control for objects in the system since
its inception.  DataONE has devised a simple but effective access control system
that is compatible with the prior system in Metacat.  For each object in the DataONE
system (including data objects, scientific metadata objects, and resource maps),
a r¨��ÖÅr≠��}rÆ��(hHXK��Metacat has supported fine grained access control for objects in the system since
its inception.  DataONE has devised a simple but effective access control system
that is compatible with the prior system in Metacat.  For each object in the DataONE
system (including data objects, scientific metadata objects, and resource maps),
a hIj®��ubhk)ÅrØ��}r∞��(hHX���SystemMetadata_hnKhIj®��hLhohN}r±��(UnameX���SystemMetadatahqX[���http://releases.dataone.org/online/d1-architecture-1.0.0/apis/Types.html#Types.AccessPolicyr≤��hS]hR]hP]hQ]hU]uhC]r≥��haX���SystemMetadatar¥��ÖÅrµ��}r∂��(hHU�hIjØ��ubaubhaXp��� document describes the critical metadata needed to manage that
object in the system.  This metadata includes a r∑��ÖÅr∏��}rπ��(hHXp��� document describes the critical metadata needed to manage that
object in the system.  This metadata includes a hIj®��ubj†��)År∫��}rª��(hHX���``RightsHolder``hN}rº��(hP]hQ]hR]hS]hU]uhIj®��hC]rΩ��haX���RightsHolderræ��ÖÅrø��}r¿��(hHU�hIj∫��ubahLj®��ubhaX��� field and an
r¡��ÖÅr¬��}r√��(hHX��� field and an
hIj®��ubj†��)Årƒ��}r≈��(hHX���``AuthoritativeMemberNode``hN}r∆��(hP]hQ]hR]hS]hU]uhIj®��hC]r«��haX���AuthoritativeMemberNoder»��ÖÅr…��}r ��(hHU�hIjƒ��ubahLj®��ubhaXâ��� field that are used to list the people and node that
have ultimate control over the disposition of the object.  In addition, a separate
rÀ��ÖÅrÃ��}rÕ��(hHXâ��� field that are used to list the people and node that
have ultimate control over the disposition of the object.  In addition, a separate
hIj®��ubhk)ÅrŒ��}rœ��(hHX
���AccessPolicy_hnKhIj®��hLhohN}r–��(UnameX���AccessPolicyhqX[���http://releases.dataone.org/online/d1-architecture-1.0.0/apis/Types.html#Types.AccessPolicyr—��hS]hR]hP]hQ]hU]uhC]r“��haX���AccessPolicyr”��ÖÅr‘��}r’��(hHU�hIjŒ��ubaubhaX��� can be included in the r÷��ÖÅr◊��}rÿ��(hHX��� can be included in the hIj®��ubj†��)ÅrŸ��}r⁄��(hHX���``SystemMetadata``hN}r€��(hP]hQ]hR]hS]hU]uhIj®��hC]r‹��haX���SystemMetadatar›��ÖÅrfi��}rfl��(hHU�hIjŸ��ubahLj®��ubhaX��� for the object.  This r‡��ÖÅr·��}r‚��(hHX��� for the object.  This hIj®��ubj†��)År„��}r‰��(hHX���``AccessPolicy``hN}rÂ��(hP]hQ]hR]hS]hU]uhIj®��hC]rÊ��haX���AccessPolicyrÁ��ÖÅrË��}rÈ��(hHU�hIj„��ubahLj®��ubhaXs��
consists of a set of rules that grant additional permissions to other people,
groups, and systems in DataONE.  For example, for one data file, two users
(Alice and Bob) may be able make changes to the object, and the general public may
be allowed to read the object.  In the absence of explicit rules extending these permissions,
Metacat enforces the rule that only the rÍ��ÖÅrÎ��}rÏ��(hHXs��
consists of a set of rules that grant additional permissions to other people,
groups, and systems in DataONE.  For example, for one data file, two users
(Alice and Bob) may be able make changes to the object, and the general public may
be allowed to read the object.  In the absence of explicit rules extending these permissions,
Metacat enforces the rule that only the hIj®��ubj†��)ÅrÌ��}rÓ��(hHX���``RightsHolder``hN}rÔ��(hP]hQ]hR]hS]hU]uhIj®��hC]r��haX���RightsHolderrÒ��ÖÅrÚ��}rÛ��(hHU�hIjÌ��ubahLj®��ubhaX��� and rÙ��ÖÅrı��}rˆ��(hHX��� and hIj®��ubj†��)År˜��}r¯��(hHX���``AuthoritativeMemberNode``hN}r˘��(hP]hQ]hR]hS]hU]uhIj®��hC]r˙��haX���AuthoritativeMemberNoder˚��ÖÅr¸��}r˝��(hHU�hIj˜��ubahLj®��ubhaXF��� have
rights to the object, and that the Coordinating Node can manage r˛��ÖÅrˇ��}r���(hHXF��� have
rights to the object, and that the Coordinating Node can manage hIj®��ubj†��)År��}r��(hHX���``SystemMetadata``hN}r��(hP]hQ]hR]hS]hU]uhIj®��hC]r��haX���SystemMetadatar��ÖÅr��}r��(hHU�hIj��ubahLj®��ubhaXò���
for the object.  An example AccessPolicy that might be submitted with a dataset
(giving Alice and Bob permission to read and write the object) follows:r��ÖÅr	��}r
��(hHX�
for the object.  An example AccessPolicy that might be submitted with a dataset
(giving Alice and Bob permission to read and write the object) follows:hIj®��ubeubj0��)År��}r��(hHXÍ���...
<accessPolicy>
    <allow>
      <subject>/C=US/O=SomeIdP/CN=Alice</subject>
      <subject>/C=US/O=SomeIdP/CN=Bob</subject>
      <permission>read</permission>
      <permission>write</permission>
    </allow>
</accessPolicy>
...hIjö��hJhKhLj3��hN}r
��(j5��j6��hS]hR]hP]hQ]hU]uhWK˘hXhhC]r��haXÍ���...
<accessPolicy>
    <allow>
      <subject>/C=US/O=SomeIdP/CN=Alice</subject>
      <subject>/C=US/O=SomeIdP/CN=Bob</subject>
      <permission>read</permission>
      <permission>write</permission>
    </allow>
</accessPolicy>
...r��ÖÅr��}r��(hHU�hIj��ubaubhe)År��}r��(hHXÚ���These AccessPolicies can be embedded inside of the ``SystemMetadata`` that accompany
submission of an object through the `MNStorage.create`_ and `MNStorage.update`_ services,
or can be set using the `CNAuthorization.setAccessPolicy`_ service.hIjö��hJhKhLhhhN}r��(hP]hQ]hR]hS]hU]uhWMhXhhC]r��(haX3���These AccessPolicies can be embedded inside of the r��ÖÅr��}r��(hHX3���These AccessPolicies can be embedded inside of the hIj��ubj†��)År��}r��(hHX���``SystemMetadata``hN}r��(hP]hQ]hR]hS]hU]uhIj��hC]r��haX���SystemMetadatar��ÖÅr��}r��(hHU�hIj��ubahLj®��ubhaX4��� that accompany
submission of an object through the r ��ÖÅr!��}r"��(hHX4��� that accompany
submission of an object through the hIj��ubhk)År#��}r$��(hHX���`MNStorage.create`_hnKhIj��hLhohN}r%��(UnameX���MNStorage.createhqX[���http://releases.dataone.org/online/d1-architecture-1.0.0/apis/MN_APIs.html#MNStorage.creater&��hS]hR]hP]hQ]hU]uhC]r'��haX���MNStorage.creater(��ÖÅr)��}r*��(hHU�hIj#��ubaubhaX��� and r+��ÖÅr,��}r-��(hHX��� and hIj��ubhk)År.��}r/��(hHX���`MNStorage.update`_hnKhIj��hLhohN}r0��(UnameX���MNStorage.updatehqX[���http://releases.dataone.org/online/d1-architecture-1.0.0/apis/MN_APIs.html#MNStorage.updater1��hS]hR]hP]hQ]hU]uhC]r2��haX���MNStorage.updater3��ÖÅr4��}r5��(hHU�hIj.��ubaubhaX#��� services,
or can be set using the r6��ÖÅr7��}r8��(hHX#��� services,
or can be set using the hIj��ubhk)År9��}r:��(hHX"���`CNAuthorization.setAccessPolicy`_hnKhIj��hLhohN}r;��(UnameX���CNAuthorization.setAccessPolicyhqXj���http://releases.dataone.org/online/d1-architecture-1.0.0/apis/CN_APIs.html#CNAuthorization.setAccessPolicyr<��hS]hR]hP]hQ]hU]uhC]r=��haX���CNAuthorization.setAccessPolicyr>��ÖÅr?��}r@��(hHU�hIj9��ubaubhaX	��� service.rA��ÖÅrB��}rC��(hHX	��� service.hIj��ubeubhé)ÅrD��}rE��(hHXo���.. _SystemMetadata: http://releases.dataone.org/online/d1-architecture-1.0.0/apis/Types.html#Types.AccessPolicyhëKhIjö��hJhKhLhíhN}rF��(hqj≤��hS]rG��h>ahR]hP]hQ]hU]rH��hauhWMhXhhC]ubhé)ÅrI��}rJ��(hHXm���.. _AccessPolicy: http://releases.dataone.org/online/d1-architecture-1.0.0/apis/Types.html#Types.AccessPolicyhëKhIjö��hJhKhLhíhN}rK��(hqj—��hS]rL��h.ahR]hP]hQ]hU]rM��hauhWM
hXhhC]ubhé)ÅrN��}rO��(hHXq���.. _MNStorage.create: http://releases.dataone.org/online/d1-architecture-1.0.0/apis/MN_APIs.html#MNStorage.createhëKhIjö��hJhKhLhíhN}rP��(hqj&��hS]rQ��h,ahR]hP]hQ]hU]rR��h	auhWMhXhhC]ubhé)ÅrS��}rT��(hHXq���.. _MNStorage.update: http://releases.dataone.org/online/d1-architecture-1.0.0/apis/MN_APIs.html#MNStorage.updatehëKhIjö��hJhKhLhíhN}rU��(hqj1��hS]rV��hAahR]hP]hQ]hU]rW��hauhWMhXhhC]ubhé)ÅrX��}rY��(hHXè���.. _CNAuthorization.setAccessPolicy: http://releases.dataone.org/online/d1-architecture-1.0.0/apis/CN_APIs.html#CNAuthorization.setAccessPolicyhëKhIjö��hJhKhLhíhN}rZ��(hqj<��hS]r[��h:ahR]hP]hQ]hU]r\��hauhWMhXhhC]ubeubhE)År]��}r^��(hHU�hIhFhJhKhLhMhN}r_��(hP]hQ]hR]hS]r`��h0ahU]ra��h
auhWMhXhhC]rb��(hZ)Årc��}rd��(hHX%���Configuration as a replication targetre��hIj]��hJhKhLh^hN}rf��(hP]hQ]hR]hS]hU]uhWMhXhhC]rg��haX%���Configuration as a replication targetrh��ÖÅri��}rj��(hHje��hIjc��ubaubhe)Årk��}rl��(hHX⁄��DataONE is designed to enable a robust preservation environment through replication
of digital objects at multiple Member Nodes.  Any Member Node in DataONE that implements
the Tier 4 Service interface can offer to act as a target for object replication.
Currently, Metacat configuration supports turning this replication function on or off.
When the 'Act as a replication target' checkbox is checked, then Metacat will notify
the Coordinating Nodes in DataONE that it is available to house replicas of objects
from other nodes.  Shortly thereafter, the Coordinating Nodes may notify Metacat to
replicate objects from throughout the system, which it will start to do.  There objects
will begin to be listed in the Metacat catalog.rm��hIj]��hJhKhLhhhN}rn��(hP]hQ]hR]hS]hU]uhWMhXhhC]ro��haX⁄��DataONE is designed to enable a robust preservation environment through replication
of digital objects at multiple Member Nodes.  Any Member Node in DataONE that implements
the Tier 4 Service interface can offer to act as a target for object replication.
Currently, Metacat configuration supports turning this replication function on or off.
When the 'Act as a replication target' checkbox is checked, then Metacat will notify
the Coordinating Nodes in DataONE that it is available to house replicas of objects
from other nodes.  Shortly thereafter, the Coordinating Nodes may notify Metacat to
replicate objects from throughout the system, which it will start to do.  There objects
will begin to be listed in the Metacat catalog.rp��ÖÅrq��}rr��(hHjm��hIjk��ubaubj˚��)Års��}rt��(hHXˆ���Future versions of Metacat will allow finer specification of the Node
Replication Policy, which determines the set of objects
that it is willing to replicate, using constraints on object size, total objects,
source nodes, and object format types.hIj]��hJhKhLj˛��hN}ru��(hP]hQ]hR]hS]hU]uhWNhXhhC]rv��he)Årw��}rx��(hHXˆ���Future versions of Metacat will allow finer specification of the Node
Replication Policy, which determines the set of objects
that it is willing to replicate, using constraints on object size, total objects,
source nodes, and object format types.ry��hIjs��hJhKhLhhhN}rz��(hP]hQ]hR]hS]hU]uhWM hC]r{��haXˆ���Future versions of Metacat will allow finer specification of the Node
Replication Policy, which determines the set of objects
that it is willing to replicate, using constraints on object size, total objects,
source nodes, and object format types.r|��ÖÅr}��}r~��(hHjy��hIjw��ubaubaubeubhE)År��}rÄ��(hHU�hIhFhJhKhLhMhN}rÅ��(hP]hQ]hR]hS]rÇ��h4ahU]rÉ��hauhWM&hXhhC]rÑ��(hZ)ÅrÖ��}rÜ��(hHX���Object Replication Policiesrá��hIj��hJhKhLh^hN}rà��(hP]hQ]hR]hS]hU]uhWM&hXhhC]râ��haX���Object Replication Policiesrä��ÖÅrã��}rå��(hHjá��hIjÖ��ubaubhe)Årç��}ré��(hHX��In addition to access control, each object also can have a ``ReplicationPolicy``
associated with it that determines whether DataONE should attempt to replicate the
object for failover and backup purposes to other Member Nodes in the federation.
Both the ``RightsHolder`` and ``AuthoritativeMemberNode`` for an object can set the
``ReplicationPolicy``, which consists of fields that describe how many replicas
should be maintained, and any nodes that are preferred for housing those replicas, or
that should be blocked from housing replicas.hIj��hJhKhLhhhN}rè��(hP]hQ]hR]hS]hU]uhWM'hXhhC]rê��(haX;���In addition to access control, each object also can have a rë��ÖÅrí��}rì��(hHX;���In addition to access control, each object also can have a hIjç��ubj†��)Årî��}rï��(hHX���``ReplicationPolicy``hN}rñ��(hP]hQ]hR]hS]hU]uhIjç��hC]ró��haX���ReplicationPolicyrò��ÖÅrô��}rö��(hHU�hIjî��ubahLj®��ubhaXÆ���
associated with it that determines whether DataONE should attempt to replicate the
object for failover and backup purposes to other Member Nodes in the federation.
Both the rõ��ÖÅrú��}rù��(hHXÆ���
associated with it that determines whether DataONE should attempt to replicate the
object for failover and backup purposes to other Member Nodes in the federation.
Both the hIjç��ubj†��)Årû��}rü��(hHX���``RightsHolder``hN}r†��(hP]hQ]hR]hS]hU]uhIjç��hC]r°��haX���RightsHolderr¢��ÖÅr£��}r§��(hHU�hIjû��ubahLj®��ubhaX��� and r•��ÖÅr¶��}rß��(hHX��� and hIjç��ubj†��)År®��}r©��(hHX���``AuthoritativeMemberNode``hN}r™��(hP]hQ]hR]hS]hU]uhIjç��hC]r´��haX���AuthoritativeMemberNoder¨��ÖÅr≠��}rÆ��(hHU�hIj®��ubahLj®��ubhaX��� for an object can set the
rØ��ÖÅr∞��}r±��(hHX��� for an object can set the
hIjç��ubj†��)År≤��}r≥��(hHX���``ReplicationPolicy``hN}r¥��(hP]hQ]hR]hS]hU]uhIjç��hC]rµ��haX���ReplicationPolicyr∂��ÖÅr∑��}r∏��(hHU�hIj≤��ubahLj®��ubhaXæ���, which consists of fields that describe how many replicas
should be maintained, and any nodes that are preferred for housing those replicas, or
that should be blocked from housing replicas.rπ��ÖÅr∫��}rª��(hHXæ���, which consists of fields that describe how many replicas
should be maintained, and any nodes that are preferred for housing those replicas, or
that should be blocked from housing replicas.hIjç��ubeubhe)Årº��}rΩ��(hHX˙���These ReplicationPolicies can be embedded inside of the ``SystemMetadata`` that accompany
submission of an object through the `MNStorage.create`_ and `MNStorage.update`_ services,
or can be set using the `CNReplication.setReplicationPolicy`_ service.hIj��hJhKhLhhhN}ræ��(hP]hQ]hR]hS]hU]uhWM/hXhhC]rø��(haX8���These ReplicationPolicies can be embedded inside of the r¿��ÖÅr¡��}r¬��(hHX8���These ReplicationPolicies can be embedded inside of the hIjº��ubj†��)År√��}rƒ��(hHX���``SystemMetadata``hN}r≈��(hP]hQ]hR]hS]hU]uhIjº��hC]r∆��haX���SystemMetadatar«��ÖÅr»��}r…��(hHU�hIj√��ubahLj®��ubhaX4��� that accompany
submission of an object through the r ��ÖÅrÀ��}rÃ��(hHX4��� that accompany
submission of an object through the hIjº��ubhk)ÅrÕ��}rŒ��(hHX���`MNStorage.create`_hnKhIjº��hLhohN}rœ��(UnameX���MNStorage.createhqj&��hS]hR]hP]hQ]hU]uhC]r–��haX���MNStorage.creater—��ÖÅr“��}r”��(hHU�hIjÕ��ubaubhaX��� and r‘��ÖÅr’��}r÷��(hHX��� and hIjº��ubhk)År◊��}rÿ��(hHX���`MNStorage.update`_hnKhIjº��hLhohN}rŸ��(UnameX���MNStorage.updatehqj1��hS]hR]hP]hQ]hU]uhC]r⁄��haX���MNStorage.updater€��ÖÅr‹��}r›��(hHU�hIj◊��ubaubhaX#��� services,
or can be set using the rfi��ÖÅrfl��}r‡��(hHX#��� services,
or can be set using the hIjº��ubhk)År·��}r‚��(hHX%���`CNReplication.setReplicationPolicy`_hnKhIjº��hLhohN}r„��(UnameX"���CNReplication.setReplicationPolicyhqXm���http://releases.dataone.org/online/d1-architecture-1.0.0/apis/CN_APIs.html#CNReplication.setReplicationPolicyr‰��hS]hR]hP]hQ]hU]uhC]rÂ��haX"���CNReplication.setReplicationPolicyrÊ��ÖÅrÁ��}rË��(hHU�hIj·��ubaubhaX	��� service.rÈ��ÖÅrÍ��}rÎ��(hHX	��� service.hIjº��ubeubhé)ÅrÏ��}rÌ��(hHXï���.. _CNReplication.setReplicationPolicy: http://releases.dataone.org/online/d1-architecture-1.0.0/apis/CN_APIs.html#CNReplication.setReplicationPolicyhëKhIj��hJhKhLhíhN}rÓ��(hqj‰��hS]rÔ��h@ahR]hP]hQ]hU]r��hauhWM3hXhhC]ubeubhE)ÅrÒ��}rÚ��(hHU�hIhFhJhKhLhMhN}rÛ��(hP]hQ]hR]hS]rÙ��h5ahU]rı��hauhWM7hXhhC]rˆ��(hZ)År˜��}r¯��(hHX"���Generating DataONE System Metadatar˘��hIjÒ��hJhKhLh^hN}r˙��(hP]hQ]hR]hS]hU]uhWM7hXhhC]r˚��haX"���Generating DataONE System Metadatar¸��ÖÅr˝��}r˛��(hHj˘��hIj˜��ubaubhe)Årˇ��}r���(hHX��When a Metacat instance becomes a Member Node, System Metadata must be generated for the existing content.
This can be invoked in the Replication configuration screen of the Metacat administration interface. Initially,
Metacat instances will only need to generate System Metadata for their local content (the ``localhost`` entry).
In cases where Metacat has participated in replication with other Metacat servers, it may be useful to generate System Metadata
for those replica records as well. Please consult both the replication partner's administrator and the DataONE administrators before
generating System Metadata for replica content.hIj��hJhKhLhhhN}r��(hP]hQ]hR]hS]hU]uhWM8hXhhC]r��(haX5��When a Metacat instance becomes a Member Node, System Metadata must be generated for the existing content.
This can be invoked in the Replication configuration screen of the Metacat administration interface. Initially,
Metacat instances will only need to generate System Metadata for their local content (the r��ÖÅr��}r��(hHX5��When a Metacat instance becomes a Member Node, System Metadata must be generated for the existing content.
This can be invoked in the Replication configuration screen of the Metacat administration interface. Initially,
Metacat instances will only need to generate System Metadata for their local content (the hIjˇ��ubj†��)År��}r��(hHX
���``localhost``hN}r��(hP]hQ]hR]hS]hU]uhIjˇ��hC]r	��haX	���localhostr
��ÖÅr��}r��(hHU�hIj��ubahLj®��ubhaX=�� entry).
In cases where Metacat has participated in replication with other Metacat servers, it may be useful to generate System Metadata
for those replica records as well. Please consult both the replication partner's administrator and the DataONE administrators before
generating System Metadata for replica content.r
��ÖÅr��}r��(hHX=�� entry).
In cases where Metacat has participated in replication with other Metacat servers, it may be useful to generate System Metadata
for those replica records as well. Please consult both the replication partner's administrator and the DataONE administrators before
generating System Metadata for replica content.hIjˇ��ubeubj∂��)År��}r��(hHU�hIjÒ��hJhKhLjπ��hN}r��(jª��X���centerhS]r��Uid2r��ahR]hP]hQ]hU]uhWNhXhhC]r��(jø��)År��}r��(hHXá���.. figure:: images/screenshots/image069.png
   :align: center

   The replication configuration screen for generating System Metadata.
hN}r��(UuriX���images/screenshots/image069.pngr��hS]hR]hP]hQ]jƒ��}r��U*j��shU]uhIj��hC]hLj∆��ubj«��)År��}r��(hHXD���The replication configuration screen for generating System Metadata.r��hIj��hJhKhLjÀ��hN}r��(hP]hQ]hR]hS]hU]uhWMBhC]r��haXD���The replication configuration screen for generating System Metadata.r ��ÖÅr!��}r"��(hHj��hIj��ubaubeubeubhE)År#��}r$��(hHU�hIhFhJhKhLhMhN}r%��(hP]hQ]hR]hS]r&��h+ahU]r'��hauhWMEhXhhC]r(��(hZ)År)��}r*��(hHX���Apache configuration detailsr+��hIj#��hJhKhLh^hN}r,��(hP]hQ]hR]hS]hU]uhWMEhXhhC]r-��haX���Apache configuration detailsr.��ÖÅr/��}r0��(hHj+��hIj)��ubaubhe)År1��}r2��(hHXT���These Apache directives are crucial for Metacat to function as a Tier 2+ Member Noder3��hIj#��hJhKhLhhhN}r4��(hP]hQ]hR]hS]hU]uhWMFhXhhC]r5��haXT���These Apache directives are crucial for Metacat to function as a Tier 2+ Member Noder6��ÖÅr7��}r8��(hHj3��hIj1��ubaubj0��)År9��}r:��(hHXú��...
AllowEncodedSlashes On
AcceptPathInfo      On
JkOptions +ForwardURICompatUnparsed
SSLEngine on
SSLOptions +StrictRequire +StdEnvVars +ExportCertData
SSLVerifyClient optional
SSLVerifyDepth 10
SSLCertificateFile /etc/ssl/certs/<your_server_certificate>
SSLCertificateKeyFile /etc/ssl/private/<your_server_key>
SSLCertificateChainFile /etc/ssl/certs/<CA_chain_file>.crt
SSLCACertificatePath /etc/ssl/certs/
...hIj#��hJhKhLj3��hN}r;��(j5��j6��hS]hR]hP]hQ]hU]uhWMJhXhhC]r<��haXú��...
AllowEncodedSlashes On
AcceptPathInfo      On
JkOptions +ForwardURICompatUnparsed
SSLEngine on
SSLOptions +StrictRequire +StdEnvVars +ExportCertData
SSLVerifyClient optional
SSLVerifyDepth 10
SSLCertificateFile /etc/ssl/certs/<your_server_certificate>
SSLCertificateKeyFile /etc/ssl/private/<your_server_key>
SSLCertificateChainFile /etc/ssl/certs/<CA_chain_file>.crt
SSLCACertificatePath /etc/ssl/certs/
...r=��ÖÅr>��}r?��(hHU�hIj9��ubaubhe)År@��}rA��(hHXô��Where ``<your_server_certificate>`` and ``<your_server_key>`` are the certificate/key pair used by Apache
to identify the server to clients. The DataONE Certiciate Authority certificate - available from the DataONE administrators -
will also need to be added to the directory specified by ``SSLCACertificatePath``
in order to validate client certificates signed by that authority. DataONE has also provided a CA chain file that may be used in lieu of directory-based CA
confinguration. The `SSLCACertificateFile`` directive should be used when configuring your member node with the DataONE CA chain.
When these changes have been applied, Apache should be restarted:hIj#��hJhKhLhhhN}rB��(hP]hQ]hR]hS]hU]uhWMXhXhhC]rC��(haX���Where rD��ÖÅrE��}rF��(hHX���Where hIj@��ubj†��)ÅrG��}rH��(hHX���``<your_server_certificate>``hN}rI��(hP]hQ]hR]hS]hU]uhIj@��hC]rJ��haX���<your_server_certificate>rK��ÖÅrL��}rM��(hHU�hIjG��ubahLj®��ubhaX��� and rN��ÖÅrO��}rP��(hHX��� and hIj@��ubj†��)ÅrQ��}rR��(hHX���``<your_server_key>``hN}rS��(hP]hQ]hR]hS]hU]uhIj@��hC]rT��haX���<your_server_key>rU��ÖÅrV��}rW��(hHU�hIjQ��ubahLj®��ubhaX‰��� are the certificate/key pair used by Apache
to identify the server to clients. The DataONE Certiciate Authority certificate - available from the DataONE administrators -
will also need to be added to the directory specified by rX��ÖÅrY��}rZ��(hHX‰��� are the certificate/key pair used by Apache
to identify the server to clients. The DataONE Certiciate Authority certificate - available from the DataONE administrators -
will also need to be added to the directory specified by hIj@��ubj†��)År[��}r\��(hHX���``SSLCACertificatePath``hN}r]��(hP]hQ]hR]hS]hU]uhIj@��hC]r^��haX���SSLCACertificatePathr_��ÖÅr`��}ra��(hHU�hIj[��ubahLj®��ubhaX±���
in order to validate client certificates signed by that authority. DataONE has also provided a CA chain file that may be used in lieu of directory-based CA
confinguration. The rb��ÖÅrc��}rd��(hHX±���
in order to validate client certificates signed by that authority. DataONE has also provided a CA chain file that may be used in lieu of directory-based CA
confinguration. The hIj@��ubcdocutils.nodes
title_reference
re��)Årf��}rg��(hHX���`SSLCACertificateFile``hN}rh��(hP]hQ]hR]hS]hU]uhIj@��hC]ri��haX���SSLCACertificateFile`rj��ÖÅrk��}rl��(hHU�hIjf��ubahLUtitle_referencerm��ubhaXò��� directive should be used when configuring your member node with the DataONE CA chain.
When these changes have been applied, Apache should be restarted:rn��ÖÅro��}rp��(hHXò��� directive should be used when configuring your member node with the DataONE CA chain.
When these changes have been applied, Apache should be restarted:hIj@��ubeubj0��)Årq��}rr��(hHX@���cd /etc/ssl/certs
sudo c_rehash
sudo /etc/init.d/apache2 restarthIj#��hJhKhLj3��hN}rs��(j5��j6��hS]hR]hP]hQ]hU]uhWMahXhhC]rt��haX@���cd /etc/ssl/certs
sudo c_rehash
sudo /etc/init.d/apache2 restartru��ÖÅrv��}rw��(hHU�hIjq��ubaubeubhE)Årx��}ry��(hHU�hIhFhJhKhLhMhN}rz��(hP]hQ]hR]hS]r{��h9ahU]r|��hauhWMghXhhC]r}��(hZ)År~��}r��(hHX-���Configure Tomcat to allow DataONE identifiersrÄ��hIjx��hJhKhLh^hN}rÅ��(hP]hQ]hR]hS]hU]uhWMghXhhC]rÇ��haX-���Configure Tomcat to allow DataONE identifiersrÉ��ÖÅrÑ��}rÖ��(hHjÄ��hIj~��ubaubhe)ÅrÜ��}rá��(hHX4���Edit ``/etc/tomcat/catalina.properties`` to include:rà��hIjx��hJhKhLhhhN}râ��(hP]hQ]hR]hS]hU]uhWMhhXhhC]rä��(haX���Edit rã��ÖÅrå��}rç��(hHX���Edit hIjÜ��ubj†��)Åré��}rè��(hHX#���``/etc/tomcat/catalina.properties``hN}rê��(hP]hQ]hR]hS]hU]uhIjÜ��hC]rë��haX���/etc/tomcat/catalina.propertiesrí��ÖÅrì��}rî��(hHU�hIjé��ubahLj®��ubhaX��� to include:rï��ÖÅrñ��}ró��(hHX��� to include:hIjÜ��ubeubj0��)Årò��}rô��(hHX}���org.apache.tomcat.util.buf.UDecoder.ALLOW_ENCODED_SLASH=true
org.apache.catalina.connector.CoyoteAdapter.ALLOW_BACKSLASH=truehIjx��hJhKhLj3��hN}rö��(j5��j6��hS]hR]hP]hQ]hU]uhWMlhXhhC]rõ��haX}���org.apache.tomcat.util.buf.UDecoder.ALLOW_ENCODED_SLASH=true
org.apache.catalina.connector.CoyoteAdapter.ALLOW_BACKSLASH=truerú��ÖÅrù��}rû��(hHU�hIjò��ubaubeubeubahHU�Utransformerrü��NU
footnote_refsr†��}r°��Urefnamesr¢��}r£��(X���four distinct tiers]r§��j!��aX���mnstorage.create]r•��(j#��jÕ��eX���cnauthorization.setaccesspolicy]r¶��j9��aX���dataone web site]rß��jã��aX���dataone service interface]r®��j��aX���incommon]r©��jÒ��aX���rest]r™��j��aX���accesspolicy]r´��jŒ��aX���systemmetadata]r¨��jØ��aX���dataone]r≠��(hlhzhÑh´eX"���cnreplication.setreplicationpolicy]rÆ��j·��aX���mnstorage.update]rØ��(j.��j◊��eX���cilogon]r∞��jÊ��auUsymbol_footnotesr±��]r≤��Uautofootnote_refsr≥��]r¥��Usymbol_footnote_refsrµ��]r∂��U	citationsr∑��]r∏��hXhUcurrent_linerπ��NUtransform_messagesr∫��]rª��Ureporterrº��NUid_startrΩ��KU
autofootnotesræ��]rø��U
citation_refsr¿��}r¡��Uindirect_targetsr¬��]r√��Usettingsrƒ��(cdocutils.frontend
Values
r≈��or∆��}r«��(Ufootnote_backlinksr»��KUrecord_dependenciesr…��NUrfc_base_urlr ��Uhttps://tools.ietf.org/html/rÀ��U	tracebackrÃ��àUpep_referencesrÕ��NUstrip_commentsrŒ��NU
toc_backlinksrœ��Uentryr–��U
language_coder—��Uenr“��U	datestampr”��NUreport_levelr‘��KU_destinationr’��NU
halt_levelr÷��KU
strip_classesr◊��Nh^NUerror_encoding_error_handlerrÿ��UbackslashreplacerŸ��Udebugr⁄��NUembed_stylesheetr€��âUoutput_encoding_error_handlerr‹��Ustrictr›��U
sectnum_xformrfi��KUdump_transformsrfl��NU
docinfo_xformr‡��KUwarning_streamr·��NUpep_file_url_templater‚��Upep-%04dr„��Uexit_status_levelr‰��KUconfigrÂ��NUstrict_visitorrÊ��NUcloak_email_addressesrÁ��àUtrim_footnote_reference_spacerË��âUenvrÈ��NUdump_pseudo_xmlrÍ��NUexpose_internalsrÎ��NUsectsubtitle_xformrÏ��âUsource_linkrÌ��NUrfc_referencesrÓ��NUoutput_encodingrÔ��Uutf-8r��U
source_urlrÒ��NUinput_encodingrÚ��U	utf-8-sigrÛ��U_disable_configrÙ��NU	id_prefixrı��U�U	tab_widthrˆ��KUerror_encodingr˜��UUTF-8r¯��U_sourcer˘��hKUgettext_compactr˙��àU	generatorr˚��NUdump_internalsr¸��NUsmart_quotesr˝��âUpep_base_urlr˛��U https://www.python.org/dev/peps/rˇ��Usyntax_highlightr���Ulongr��Uinput_encoding_error_handlerr��j›��Uauto_id_prefixr��Uidr��Udoctitle_xformr��âUstrip_elements_with_classesr��NU
_config_filesr��]Ufile_insertion_enabledr��àUraw_enabledr	��KU
dump_settingsr
��NubUsymbol_footnote_startr��K�Uidsr��}r
��(h+j#��h2jà��h-jÉ��h.jI��h0j]��h>jD��h/hñh@jÏ��h5jÒ��h4j��h7j}��j��j��h*j_��h=jö��jΩ��j∑��h8j®��h3jí��h6hˆh)jç��hAjS��h1jï��h9jx��h,jN��h<jZ��h;hFh:jX��h?hèhBjU��uUsubstitution_namesr��}r��hLhXhN}r��(hP]hS]hR]UsourcehKhQ]hU]uU	footnotesr��]r��Urefidsr��}r��ub.