It was due to my configuration, /etc/xrootd/scitokens.cfg , where I used the parameter, map_subject = True . After changing it to False, the json group mapping seems to map accounts correctly. Bockjoo On 3/24/23 13:52, Bockjoo Kim wrote: > Hi, > > I am seeing the file read error with the IAM token: > > 230324 11:00:02 722982 multiuser_UserSentry: XRootD mapped request to > username that does not exist: _token_subject_ > 230324 11:00:02 722982 ofs_stat: unknown.102415:[log in to unmask] > Unable to locate > /store/mc/SAM/GenericTTbar/AODSIM/CMSSW_9_2_6_91X_mcRun1_realistic_v2-v1/00000/A64CCCF2-5C76-E711-B359-0CC47A78A3F8.root; > permission denied > > I am wondering why the token subject is showing as the username > instead of mapping specified in the token-map json file. > > Thanks, > > Bockjoo > ######################################################################## Use REPLY-ALL to reply to list To unsubscribe from the XROOTD-L list, click the following link: https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-L&A=1