I have gotten past this error, but now it fails with a Unable to accept the id token with an invalid [sub] claim
This is strange, because the code looks like ANY sub claim is an invalid sub claim. I don't believe this is the proper behavior for this adaptor. On Monday, June 10, 2019 at 1:17:40 PM UTC-4, Jimmy Springles wrote: > > I am setting up a CAS server and attempting to use AWS Cognito as the > authorization handler. The Cognito requests return 200, showing me that CAS > has attempted to log in to Cognito and has succeeded. However, I receive an > Authentication error in the CAS logs even when the AWS request is > successful. > > This is my configuration file > > cas.server.name=https://localhost:8443 > cas.server.prefix=${cas.server.name}/cas > > logging.config: file:/etc/cas/config/log4j2.xml > > cas.serviceRegistry.json.location: file:/etc/cas/services-repo > cas.serviceRegistry.initFromJson: true > > cas.authn.accept.users= > cas.authn.cognito.name=COGNITO > cas.authn.cognito.order=1 > > cas.authn.cognito.clientId=<client id> > cas.authn.cognito.userPoolId=<user pool id> > cas.authn.cognito.credentialAccessKey=<access key> > cas.authn.cognito.credentialSecretKey=<secret key> > cas.authn.policy.req.tryAll=false > cas.authn.policy.req.handlerName=COGNITO > cas.authn.policy.req.enabled=true > > It seems that the AWS Cognito request is successful, but CAS still > displays the following error: > > 15:37:29.605 [QUIET] [system.out] 2019-06-10 15:37:29,605 DEBUG > [com.amazonaws.request] - <Received successful response: 200, AWS Request ID: > a7cdc8b9-8b95-11e9-a25d-0db9186f3709> > 15:37:29.605 [QUIET] [system.out] 2019-06-10 15:37:29,606 DEBUG > [com.amazonaws.requestId] - <x-amzn-RequestId: > a7cdc8b9-8b95-11e9-a25d-0db9186f3709> > 15:37:29.610 [QUIET] [system.out] 2019-06-10 15:37:29,609 ERROR > [org.apereo.cas.authentication.PolicyBasedAuthenticationManager] - > <Authentication has failed. Credentials may be incorrect or CAS cannot find > authentication handler that supports > [UsernamePasswordCredential(username=<username>, source=null)] of type > [UsernamePasswordCredential]. Examine the configuration to ensure a method of > authentication is defined and analyze CAS logs at DEBUG level to trace the > authentication event.> > > -- - Website: https://apereo.github.io/cas - Gitter Chatroom: https://gitter.im/apereo/cas - List Guidelines: https://goo.gl/1VRrw7 - Contributions: https://goo.gl/mh7qDG --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/fea6bca5-0a3c-4371-9b72-49a49b79e4fa%40apereo.org.
