ATLAS HTCondor-CE ping with SCITOKEN

host: 
port: 

HTCondor basic info

Name: grid-72065.ijclab.in2p3.fr
CE Version: 23.9.1
Version: $CondorVersion: 23.10.1 2024-10-03 BuildID: 759508 PackageID: 23.10.1-1 GitSHA: acedc362 $
Platform: $CondorPlatform: x86_64_AlmaLinux9 $
Identity: condor@family

Test condor_ping with SCITOKEN credentials

11/24/24 02:14:28 recognized WRITE as authorization level, using command 60021.
Destination:                 schedd grid-72065.ijclab.in2p3.fr
Remote Version:              $CondorVersion: 23.10.1 2024-10-03 BuildID: 759508 PackageID: 23.10.1-1 GitSHA: acedc362 $
Local  Version:              $CondorVersion: 23.9.6 2024-08-08 BuildID: 748275 PackageID: 23.9.6-1 GitSHA: dfdd9eaa $
Session ID:                  grid-72065:92224:1732410868:238860
Instruction:                 WRITE
Command:                     60021
Encryption:                  AES
Integrity:                   AES
Authenticated using:         SCITOKENS
All authentication methods:  SCITOKENS
Remote Mapping:              atlp000@users.htcondor.org
Authorized:                  TRUE

Test condor_ping with GSI credentials

This can't work with recent HTCondor-CEs that no longer support GSI

condor_ping result:
11/24/24 02:14:28 recognized WRITE as authorization level, using command 60021.
WARNING: GSI authentication is enabled by your security configuration! GSI is no longer supported.
For details, see https://htcondor.org/news/plan-to-replace-gst-in-htcss/
11/24/24 02:14:28 SECMAN: no classad from server, failing
WRITE failed!
SECMAN:2011:Connection closed during command authorization. Probably due to an unknown command.

Test condor_ping with SSL credentials

This could work only with recent HTCondor-CEs, but only with special individual SSL mapping for certificate subject:

SSL "/DC=ch/DC=cern/OU=Organic Units/OU=Users/CN=vokac/CN=610071/CN=Petr Vokac" unix_account
condor_ping result:
11/24/24 02:14:29 recognized WRITE as authorization level, using command 60021.
Destination:                 schedd grid-72065.ijclab.in2p3.fr
Remote Version:              $CondorVersion: 23.10.1 2024-10-03 BuildID: 759508 PackageID: 23.10.1-1 GitSHA: acedc362 $
Local  Version:              $CondorVersion: 23.9.6 2024-08-08 BuildID: 748275 PackageID: 23.9.6-1 GitSHA: dfdd9eaa $
Session ID:                  grid-72065:92224:1732410869:238861
Instruction:                 WRITE
Command:                     60021
Encryption:                  AES
Integrity:                   AES
Authenticated using:         SSL
All authentication methods:  SSL
Remote Mapping:              alt074@users.htcondor.org
Authorized:                  TRUE

Client credentials

Token:
{
  "wlcg.ver": "1.0",
  "sub": "7dee38a3-6ab8-4fe2-9e4c-58039c21d817",
  "aud": [
    "grid-72065.ijclab.in2p3.fr:9619",
    "condor://grid-72065.ijclab.in2p3.fr:9619",
    "https://wlcg.cern.ch/jwt/v1/any"
  ],
  "nbf": 1732410867,
  "scope": "compute.read compute.cancel compute.modify compute.create",
  "iss": "https://atlas-auth.cern.ch/",
  "exp": 1732756467,
  "iat": 1732410867,
  "jti": "9611dfdf-b4a2-4aa0-9826-1cc3df276c23",
  "client_id": "7dee38a3-6ab8-4fe2-9e4c-58039c21d817"
}

Proxy:
subject   : /DC=ch/DC=cern/OU=Organic Units/OU=Users/CN=vokac/CN=610071/CN=Petr Vokac/CN=1887078256/CN=1497194377
issuer    : /DC=ch/DC=cern/OU=Organic Units/OU=Users/CN=vokac/CN=610071/CN=Petr Vokac/CN=1887078256
identity  : /DC=ch/DC=cern/OU=Organic Units/OU=Users/CN=vokac/CN=610071/CN=Petr Vokac
type      : RFC3820 compliant impersonation proxy
strength  : 2048
path      : /tmp/x509up_u48.prd.htcondor.20873
timeleft  : 11:59:55
key usage : Digital Signature, Key Encipherment
=== VO atlas extension information ===
VO        : atlas
subject   : /DC=ch/DC=cern/OU=Organic Units/OU=Users/CN=vokac/CN=610071/CN=Petr Vokac
issuer    : /DC=ch/DC=cern/OU=computers/CN=atlas-auth.web.cern.ch
attribute : /atlas/Role=production/Capability=NULL
attribute : /atlas/Role=NULL/Capability=NULL
attribute : /atlas/alarm/Role=NULL/Capability=NULL
attribute : /atlas/cz/Role=NULL/Capability=NULL
attribute : /atlas/team/Role=NULL/Capability=NULL
attribute : testattr = testvalue (atlas)
attribute : nickname = vokac (atlas)
timeleft  : 11:59:55
uri       : voms-atlas-auth.app.cern.ch:443