AWS pcs: Slurm REST API username claim moves to id.name, top-level claims deprecated
Summary
Updates authentication documentation to specify the JWT username in the name field inside the id claim, documents that top-level claims (sun, custom userclaimfield) are deprecated from Slurm 26.05, explains claim precedence per cluster version, and updates the Python token example to use the id/name structure.
Security assessment
The change governs which JWT claim is used to derive the authenticated Slurm username, so ambiguity or version-dependent precedence could map a token to the wrong identity. It is authentication configuration guidance rather than a fix for a specific reported vulnerability.
Evidence
Provide the username in only one location. If a token sets both the `name` field within the `id` claim and a top-level claim, the claim that takes precedence depends on the Slurm version of your cluster: on Slurm 26.05 and later, the `name` field within the `id` claim takes precedence. On earlier versions, the top-level claim takes precedence.
Diff
diff --git a/pcs/latest/userguide/slurm-rest-api-authenticate.md b/pcs/latest/userguide/slurm-rest-api-authenticate.md index ac9727ad9..1a4656572 100644 --- a//pcs/latest/userguide/slurm-rest-api-authenticate.md +++ b//pcs/latest/userguide/slurm-rest-api-authenticate.md @@ -96,2 +95,0 @@ AWS CLI - * `sun` – The username for authentication - @@ -102 +100,3 @@ AWS CLI - * `id` – Additional POSIX identity properties + * `id` – POSIX identity properties + + * `name` – The username for authentication @@ -121 +121,5 @@ AWS CLI -As an alternative to the `sun` claim, you can provide any of the following: +Provide the username in the `name` field within the `id` claim. AWS PCS accepts this claim on every supported Slurm version. + +You can also set the username in one of the following top-level claims: + + * `sun` @@ -125 +129,2 @@ As an alternative to the `sun` claim, you can provide any of the following: - * A custom field name that you define via the `userclaimfield` in the `AuthAltParameters Slurm custom settings` + * A custom claim name that you define with `userclaimfield` in the `AuthAltParameters` Slurm custom setting + @@ -127 +131,0 @@ As an alternative to the `sun` claim, you can provide any of the following: - * A `name` field within the `id` claim @@ -129,0 +134 @@ As an alternative to the `sun` claim, you can provide any of the following: +Slurm 26.05 reads the username from the `name` field within the `id` claim. The top-level claims are deprecated from Slurm 26.05, and AWS PCS might stop accepting them in a future Slurm version. Existing tokens that use a top-level claim continue to authenticate on all supported versions. If your tokens use one, update the code that generates them to provide the username in the `name` field within the `id` claim. @@ -130,0 +136 @@ As an alternative to the `sun` claim, you can provide any of the following: +Provide the username in only one location. If a token sets both the `name` field within the `id` claim and a top-level claim, the claim that takes precedence depends on the Slurm version of your cluster: on Slurm 26.05 and later, the `name` field within the `id` claim takes precedence. On earlier versions, the top-level claim takes precedence. @@ -192 +197,0 @@ This Python example illustrates how to use the signing key to generate a JWT tok - "sun": "ec2-user", @@ -195,0 +201 @@ This Python example illustrates how to use the signing key to generate a JWT tok + "name": "ec2-user",