<html><head><meta http-equiv="Content-Type" content="text/html charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">Check the server’s JWK Set endpoint (at <issuer>/jwk) and see if it’s publishing the keys you want it to publish there. If it is, then your keystore is getting loaded and something else is the problem. If not, then you can trace it down to a keystore issue. <div class=""><br class=""></div><div class="">Can you replicate the bug on a pristine copy of the server using the same base version? <br class=""><div class=""><br class=""></div><div class=""> — Justin</div><div class=""><br class=""><div><blockquote type="cite" class=""><div class="">On Dec 12, 2016, at 5:53 PM, William Hadden1 <<a href="mailto:WilHadden@uk.ibm.com" class="">WilHadden@uk.ibm.com</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div class="socmaildefaultfont" dir="ltr" style="font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; font-family: Arial, Helvetica, sans-serif; font-size: 10.5pt;"><div dir="ltr" class="">That was a suspicion I had, but my setup looks ok to me,</div><div dir="ltr" class=""> </div><div dir="ltr" class="">In my overlay under src/main/webapp/WEB-INF I have crypto-config.xml which points to </div><div dir="ltr" class=""> </div><div dir="ltr" class=""><bean id="defaultKeyStore" class="org.mitre.jose.keystore.JWKSetKeyStore"><br class=""> <property name="location" value="file:/etc/mitreid-connect/keystore.jwks" /><br class=""> </div><div dir="ltr" class="">In /etc/mitreid-connect/keystore.jwks I have the standard cloned keystore. So this looks OK to me.</div><div dir="ltr" class=""> </div><div dir="ltr" class="">Now, I've switched on all debug in log4j but I don't see any mention of that keystore getting loaded. Is it possible my crpyto-config isn'y getting loaded? The other files in there seem to be getting loaded.</div><div dir="ltr" class=""> </div><div dir="ltr" class="">Wil</div><div dir="ltr" class=""> </div><blockquote data-history-content-modified="1" dir="ltr" style="border-left-style: solid; border-left-color: rgb(170, 170, 170); border-left-width: 2px; margin-left: 5px; padding-left: 5px; direction: ltr; margin-right: 0px;" class="">----- Original message -----<br class="">From: Justin Richer <<a href="mailto:jricher@mit.edu" class="">jricher@mit.edu</a>><br class="">To: William Hadden1/UK/IBM@IBMGB<br class="">Cc: <a href="mailto:mitreid-connect@mit.edu" class="">mitreid-connect@mit.edu</a><br class="">Subject: Re: [mitreid-connect] I seem to have a problem with an empty keystore<br class="">Date: Mon, Dec 12, 2016 10:48 PM<br class=""> <br class="">Yes, the server will still issue a JWT formatted token for client credentials clients. The “claims” here are the claims inside the JWT, not the “claims” of user information or authentication event information in an OpenID Connect transaction. (Since you’re doing client credentials, you’re not using OpenID Connect functionality anyway, you’re doing plain OAuth, so none of that comes into play.) All of those claims should already be set in when the token is created.<div class=""> </div><div class="">If your keystore is empty, though, the server won’t be able to sign *any* tokens. Which means it won’t be able to issue any tokens. Is that the case? If so, why is your keystore empty?<div class=""> </div><div class=""> — Justin</div><div class=""> </div><div class=""> <div class=""><blockquote type="cite" class=""><div class="">On Dec 12, 2016, at 5:40 PM, William Hadden1 <<a href="mailto:WilHadden@uk.ibm.com" target="_blank" class="">WilHadden@uk.ibm.com</a>> wrote:</div> <div class=""><div dir="ltr" style="font-family: Arial, Helvetica, sans-serif; font-size: 10.5pt;" class=""><div dir="ltr" class="">Hi,</div><div dir="ltr" class=""> </div><div dir="ltr" class="">I have been writing my own overlay and at this point I can call the API and create clients. However when I try to create a client_credentials token I get a null pointer. Now bear in mind I have been changing the spring config files, so that would be a prime candidate for where I have done something wrong.</div><div dir="ltr" class=""> </div><div dir="ltr" class="">The NP ultimately is:</div><div dir="ltr" class="">2016-12-12 20:58:39 DEBUG DispatcherServlet:988 - Could not complete request<br class="">java.lang.NullPointerException<br class=""> at com.nimbusds.jose.JWSObject.ensureJWSSignerSupport(JWSObject.java:268)<br class=""> at com.nimbusds.jose.JWSObject.sign(JWSObject.java:291)<br class=""> at org.mitre.jwt.signer.service.impl.DefaultJWTSigningAndValidationService.signJwt(DefaultJWTSigningAndValidationService.java:225)</div><div dir="ltr" class=""> at org.mitre.openid.connect.token.ConnectTokenEnhancer.enhance(ConnectTokenEnhancer.java:114)</div><div dir="ltr" class=""> </div><div dir="ltr" class="">This seems to come down to this line not creating a proper object</div><div dir="ltr" class=""> </div><div dir="ltr" class="">SignedJWT signed = new SignedJWT(header, claims);</div><div dir="ltr" class=""> </div><div dir="ltr" class="">My question is, for client_credentials, should the code be trying to create / use a JWT? If so then is it likely that my claims are wrong, as in I have setup my client to use it's own scope but do I also have to setup a claim to go along with it?</div><div dir="ltr" class=""> </div><div dir="ltr" class="">Thanks for any help</div><div dir="ltr" class="">Wil</div><div dir="ltr" class=""> </div><div dir="ltr" class=""> </div><div dir="ltr" class=""> </div></div>Unless stated otherwise above:<br class="">IBM United Kingdom Limited - Registered in England and Wales with number 741598.<br class="">Registered office: PO Box 41, North Harbour, Portsmouth, Hampshire PO6 3AU<br class=""><br class="">_______________________________________________<br class="">mitreid-connect mailing list<br class=""><a href="mailto:mitreid-connect@mit.edu" target="_blank" class="">mitreid-connect@mit.edu</a><br class=""><span class=""><a href="http://mailman.mit.edu/mailman/listinfo/mitreid-connect" target="_blank" class="">http://mailman.mit.edu/mailman/listinfo/mitreid-connect</a></span></div></blockquote></div></div></div></blockquote><div dir="ltr" class=""> </div></div><span style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: inline !important;" class="">Unless stated otherwise above:</span><br style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=""><span style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: inline !important;" class="">IBM United Kingdom Limited - Registered in England and Wales with number 741598.<span class="Apple-converted-space"> </span></span><br style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=""><span style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: inline !important;" class="">Registered office: PO Box 41, North Harbour, Portsmouth, Hampshire PO6 3AU</span></div></blockquote></div><br class=""></div></div></body></html>