AWS Security ChangesHomeSearch

AWS pcs: Slurm REST API username claim moves to id.name, top-level claims deprecated

Service: pcs · 2026-09-27 · Documentation high

File: pcs/latest/userguide/slurm-rest-api-authenticate.md · Type: auth

Summary

Updates authentication documentation to specify the JWT username in the name field inside the id claim, documents that top-level claims (sun, custom userclaimfield) are deprecated from Slurm 26.05, explains claim precedence per cluster version, and updates the Python token example to use the id/name structure.

Security assessment

The change governs which JWT claim is used to derive the authenticated Slurm username, so ambiguity or version-dependent precedence could map a token to the wrong identity. It is authentication configuration guidance rather than a fix for a specific reported vulnerability.

Evidence

Provide the username in only one location. If a token sets both the `name` field within the `id` claim and a top-level claim, the claim that takes precedence depends on the Slurm version of your cluster: on Slurm 26.05 and later, the `name` field within the `id` claim takes precedence. On earlier versions, the top-level claim takes precedence.

Diff

diff --git a/pcs/latest/userguide/slurm-rest-api-authenticate.md b/pcs/latest/userguide/slurm-rest-api-authenticate.md
index ac9727ad9..1a4656572 100644
--- a//pcs/latest/userguide/slurm-rest-api-authenticate.md
+++ b//pcs/latest/userguide/slurm-rest-api-authenticate.md
@@ -96,2 +95,0 @@ AWS CLI
-     * `sun` – The username for authentication
-
@@ -102 +100,3 @@ AWS CLI
-     * `id` – Additional POSIX identity properties
+     * `id` – POSIX identity properties
+
+       * `name` – The username for authentication
@@ -121 +121,5 @@ AWS CLI
-As an alternative to the `sun` claim, you can provide any of the following:
+Provide the username in the `name` field within the `id` claim. AWS PCS accepts this claim on every supported Slurm version.
+
+You can also set the username in one of the following top-level claims:
+
+  * `sun`
@@ -125 +129,2 @@ As an alternative to the `sun` claim, you can provide any of the following:
-  * A custom field name that you define via the `userclaimfield` in the `AuthAltParameters Slurm custom settings`
+  * A custom claim name that you define with `userclaimfield` in the `AuthAltParameters` Slurm custom setting
+
@@ -127 +131,0 @@ As an alternative to the `sun` claim, you can provide any of the following:
-  * A `name` field within the `id` claim
@@ -129,0 +134 @@ As an alternative to the `sun` claim, you can provide any of the following:
+Slurm 26.05 reads the username from the `name` field within the `id` claim. The top-level claims are deprecated from Slurm 26.05, and AWS PCS might stop accepting them in a future Slurm version. Existing tokens that use a top-level claim continue to authenticate on all supported versions. If your tokens use one, update the code that generates them to provide the username in the `name` field within the `id` claim.
@@ -130,0 +136 @@ As an alternative to the `sun` claim, you can provide any of the following:
+Provide the username in only one location. If a token sets both the `name` field within the `id` claim and a top-level claim, the claim that takes precedence depends on the Slurm version of your cluster: on Slurm 26.05 and later, the `name` field within the `id` claim takes precedence. On earlier versions, the top-level claim takes precedence.
@@ -192 +197,0 @@ This Python example illustrates how to use the signing key to generate a JWT tok
-        "sun": "ec2-user",
@@ -195,0 +201 @@ This Python example illustrates how to use the signing key to generate a JWT tok
+            "name": "ec2-user",