CAS 6.0.X breaks JWT Signing

40 views
Skip to first unread message

Alessandro Moscatelli

unread,
Mar 19, 2019, 6:41:45 AM3/19/19
to CAS Community
Upgrading CAS from 5.3.X to 6.0.X seems to break JWT Signing (and maybe Encryption? I cannot tell).

I am actually using nimbus library to verify/decrypt JWT produces by CAS.

What I have already tried :

1) Using jose4j instead of nimbus using the same code as described in https://apereo.github.io/cas/6.0.x/installation/Configure-ServiceTicket-JWT.html
2) Regenerating the AES keys produced by the CAS (I use the keys automatically used by CAS and then I put them into config, I do NOT generate keys by myself)

I upgraded to CAS 5.3.9 and everything works as usual.

Best regards

Alessandro Moscatelli

unread,
Jun 4, 2019, 12:58:17 PM6/4/19
to CAS Community
This seems to be fixed in 6.0.4

Thank you
Reply all
Reply to author
Forward
0 new messages