Whether it has READ and/or ADMIN will depend on whether the identity of the token is in the ALLOW_READ and/or ALLOW_ADMIN list of the Startd config.
-tj
________________________________________
From: 'Carsten Aulbert' via HTCondor Users
Sent: Tuesday, July 21, 2026 12:07 PM
To: Thomas Hartmann
Cc: htcondo...@g-groups.wisc.edu
Subject: Re: [HTCondor-users] IDTOKENS and defrag daemon
Hi Thomas,
Cheers
Carsten
--
Archives for older messages are found at https://www-auth.cs.wisc.edu/lists/htcondor-users/
---
You received this message because you are subscribed to the Google Groups "HTCondor Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to htcondor-user...@g-groups.wisc.edu.
To view this discussion visit https://groups.google.com/a/g-groups.wisc.edu/d/msgid/htcondor-users/0aeaa8f0-88b2-4be6-9d65-ce1755a4cb05%40aei.mpg.de.
Try temporarily enabling this config variable on the startd. (don't forget to reconfig the startd)
STARTD_DEBUG = $(STARTD_DEBUG) D_SECURITY:2
This generates a lot of output, so you don't want to leave this debug level turned on long term, but it should be able to give some insight into why the token cannot be used to authenticate the drain command.
-tj
________________________________________
From: 'Carsten Aulbert' via HTCondor Users
Sent: Monday, July 27, 2026 3:45 AM
To: John M Knoeller
Cc: htcondo...@g-groups.wisc.edu
Subject: Re: [HTCondor-users] IDTOKENS and defrag daemon
Hi tj,
(taken from condor_config_val -sum)
"sub":"con...@atlas.local"
--
Archives for older messages are found at https://www-auth.cs.wisc.edu/lists/htcondor-users/
---
You received this message because you are subscribed to the Google Groups "HTCondor Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to htcondor-user...@g-groups.wisc.edu.
To view this discussion visit https://groups.google.com/a/g-groups.wisc.edu/d/msgid/htcondor-users/2b4683a9-0311-46f9-9ee3-6602714d7c72%40aei.mpg.de.