Connecting

Connecting for the first time

All connections to the NOAA RDHPCS enclave are done via Secure Shell (SSH) in a terminal session to a Bastion, or via a web browser to ParallelWorks. See our ParallelWorks guide.

Note

For access to the MSU HPC systems Orion and Hercules, please review the MSU-HPC user guide.

Authentication is via a CAC/PIV card or YubiKey Multi-Factor Authentication.

Internal to the enclave, X509 certificates are used to authenticate between resources. At first login, and at yearly intervals, a master certificate valid for one year is created (SSH Bastion login required) with a user-defined pass-phrase. At each successive log in, a thirty-day proxy certificate is created and used for resource access and data transfers.

Attention

You must have access to an RDHPCS resource (system) in order to log into it! Visit the Account Information Management website to view your RDHPCS profile and system access.

Access to most RDHPCS systems require a signed x.509 certificate. The first login attempt will generate a master certificate request. You will experience a short (less than 5 minute) delay while the request is signed. Users cannot fully log on to a system until that certificate is signed.

The prompt will ask you to create a passphrase. Create a passphrase with a minimum of three words.

Note

Do not worry if you forget your passphrase – just continue to try. On the 4th attempt the system will prompt you to recreate your master certificate.

Secure Shell (SSH) Access

Access to on premise RDHPCS compute resources is done using the Secure Shell (SSH) protocol to one of the system’s bastions, or via ParallelWorks.

MSU systems (Orion, Hercules) are accessed via SSH or OpenOnDemand. See MSU-HPC Logging In for instructions.

SSH terminal clients are part of the standard Operating Systems (O/S) in use today across Linux, MacOS, and Windows. Windows 10 and Windows 11 have added built-in support for SSH. If it is not installed on your version of Windows, please refer to Microsoft’s documentation on OpenSSH.

Graphical SSH clients for Windows systems are available; users have reported success with applications such as PuTTY-CAC, SecureCRT, or MobaXterm.

Bastion Hostnames

As of mid 2026, there is only one type of Bastion used for both CAC or Yubikey access.

RDHPCS System

MFA Bastion hostnames

Gaea

gaea-mfa.princeton.rdhpcs.noaa.gov

gaea-mfa.fairmont.rdhpcs.noaa.gov

Hera

hera-mfa.princeton.rdhpcs.noaa.gov

hera-mfa.fairmont.rdhpcs.noaa.gov

PPAN

analysis-mfa.princeton.rdhpcs.noaa.gov

analysis-mfa.fairmont.rdhpcs.noaa.gov

Mercury

mercury-mfa.princeton.rdhpcs.noaa.gov

mercury-mfa.fairmont.rdhpcs.noaa.gov

Ursa

ursa-mfa.princeton.rdhpcs.noaa.gov

ursa-mfa.fairmont.rdhpcs.noaa.gov

In addition to the NOAA systems, RDHPCS users have access to computational capacity on the Orion and Hercules systems, hosted by Mississippi State University. See the MSU-HPC user guide. for detailed information.

Computational capacity is also available on the RDHPCS Cloud Platform, which allows NOAA users to create custom HPC clusters on an as-needed basis, through the Parallel Works platform. The Cloud User Guide provides more information.

Common Access Card (CAC) SSH Login

RDHPCS users with a CAC who are logging in from a Windows, Mac, or Linux system are recommended to use a CAC login. This requires a CAC reader and a modern OpenSSH client, or PUTTY-CAC for Windows.

Attention

If you recently were issued a new or renewed CAC, please log into the Account Information Management website to update the CAC information.

  1. Reference the table above for the appropriate Bastion to use.

  2. When prompted, enter your CAC PIN.

See also the ssh port tunnels section to create an OpenSSH configuration for easy RDHPCS access.

Always start by inserting your CAC/PIV card before using ssh. If the CAC/PIV is not available, authentication will fall through to Yubikey, and the password prompt will be different.

Linux

ssh -oPKCS11Provider=/usr/lib64/pkcs11/opensc-pkcs11.so First.Last@BASTION

Mac OS

ssh -oPKCS11Provider=/usr/lib/ssh-keychain.dylib First.Last@BASTION

Windows

Open PuTTY-CAC. Select the desired profile (Bastion / HPCS) and click Connect or something like that.

  1. Open PuTTY-CAC and load or create a saved session profile.

  2. Navigate to Connection → SSH → Certificate and confirm your PIV authentication certificate is shown under Selected thumbprint. If not, repeat the Set CAPI Cert… step from Step 2.

  3. Return to Session, select your profile, and click Save.

  4. Click Open to initiate the connection.

  5. Verify the server key fingerprint when prompted and click Yes.

  6. Enter your RDHPCS username (First.Last format).

  7. When the certificate confirmation dialog appears, click OK and enter your CAC/PIV PIN.

    Note

    Your card reader may flash during login. Do not remove your card until you are fully logged in.

Yubikey SSH Login

RDHPCS users who do not have a CAC, or lack the required hardware or software, are welcome to use their NOAA issued Yubikey to login. You must have configured and registered your Yubikey for NOAA RDHPCS access.

$ ssh First.Last@BASTION
  1. All bastions are available for both CAC and Yubikey logins.

  2. When prompted, enter your Yubikey PIN then press and hold your Yubikey (long press).

Selecting a Node

RDHPCS systems accessed via SSH allow users to select a specific head node at login. After successful authentication at the bastion host, a list of available nodes will be displayed with a 5 second delay to choose a specific destination. To select a specific host, press Control+C (^C) and enter the desired node.

Here is an example of what the display looks like for the Gaea system mid 2024:

Welcome to the NOAA RDHPCS.

Attempting to renew your proxy certificate...Proxy certificate has 720:00:00  (30.0 days) left.

        Welcome to gaea.rdhpcs.noaa.gov
Gateway to gaea-c5.ncrc.gov and other points beyond

!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!! RDHPCS Policy states that all user login sessions shall be terminated     !!
!! after a maximum duration of seven (7) days. ALL user login sessions will  !!
!! be dropped from the Princeton Bastions at 4AM ET / 2AM MT each Monday     !!
!! morning, regardless of the duration. Please note: This will NOT impact    !!
!! batch jobs, cron scripts, screen sessions, remote desktop, or data        !!
!! transfers.                                                                !!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

Hostname            Description
gaea                C5 head nodes
gaea51              C5 head node
gaea52              C5 head node
gaea53              C5 head node
gaea54              C5 head node
gaea55              C5 head node
gaea56              C5 head node
gaea57              C5 head node
gaea58              C5 head node
gaea60              T6 Test access only
gaea61              C6 head node
gaea62              C6 head node
gaea63              C6 head node
gaea64              C6 head node
gaea65              C6 head node
gaea66              C6 head node
gaea67              C6 head node
gaea68              C6 head node

You will now be connected to NOAA RDHPCS: Gaea (CMRS/NCRC) C5 system.
To select a specific host, hit ^C within 5 seconds.

Note

After the 5 second wait, the bastion node will use a load balancer to select a lightly loaded node.

X11 Graphics

Users can use SSH X11 forwarding to open GUI-based applications (e.g., xterm, ARM Forge). This is typically done using an SSH option. For OpenSSH-based clients, use the -X option:

$ ssh -X host.url

Other clients, like PuTTY-CAC, will have an option when configuring the host.

The base SSH X11 forwarding is typically slow. A different option is to use ParallelWorks with a graphical desktop accessible via web browser.

Note

Microsoft Windows users can use any of the X11 servers available for Windows. The SSH client will need to be configured to use the X11 server for forwarding X11.

SSH Port Tunnels

To allow users to easily transfer small files to and from the RDHPCS systems, the bastion configures SSH port-forwarding tunnels. To use these tunnels, the user must configure their local SSH client to create tunnels to/from the bastion.

You can use this OpenSSH configuration generation form to create a sample SSH configuration for OpenSSH-based clients.

Windows users will need to configure port tunnels in their SSH application of choice.

Web based ParallelWorks Access

See the RDHPCS Cloud Computing for details on using ParallelWorks in a web browser to access on-premise and cloud HPCS.