Error "Unable to fetch JWT Client Authentication Verification Alias" in 12.9
search cancel

Error "Unable to fetch JWT Client Authentication Verification Alias" in 12.9

book

Article ID: 421081

calendar_today

Updated On:

Products

SITEMINDER

Issue/Introduction

After upgraded to 12.9, policy server shows error

[mm/dd/yyyy][hh:mm:ss.133][hh:mm:ss][1266948][140359296333568][BaseAccessTokenTunnel.java][formClientObject][Unable to fetch JWT Client Authentication Verification Alias. Exception: com.ca.siteminder.sdk.adminapi.XPSException: attribute CA.FED::OIDCClient JWTSecVerificationAliasLink at com.ca.siteminder.sdk.adminapi.ca.xps.Class.getAttribute(Unknown Source) at com.ca.siteminder.sdk.adminapi.XPSObjectImpl.getAttr(Unknown Source) at com.ca.siteminder.sdk.adminapi.XPSObjectImpl.resolve(Unknown Source) at com.ca.siteminder.sdk.adminapi.XPSObjectImpl.getProperty(Unknown Source) at com.ca.siteminder.sdk.adminapi.XPSObjectImpl.getLink(Unknown Source) at com.ca.siteminder.sdk.adminapi.XPSObjectImpl.getLink(Unknown Source) at com.ca.siteminder.sdk.adminapi.ca.fed.OIDCClient.getJWTSecVerificationAlias(Unknown Source) at com.ca.fedserver.common.tunnel.BaseAccessTokenTunnel.lambda$formClientObject$6(BaseAccessTokenTunnel.java:672) at com.ca.fedserver.common.tunnel.BaseAccessTokenTunnel.formClientObject(BaseAccessTokenTunnel.java:684) at com.ca.federation.openidconnect.tunnel.AccessTokenTunnelService.tunnel(Unknown Source) at com.netegrity.policyserver.smapi.TunnelServiceContext.tunnel(TunnelServiceContext.java:245)

 

Environment

OS: Red Hat Enterprise Linux Server release 8
Policy server version : 12.9; Update: 0.00; Build: 3079

Cause

12.9 code is checking verification cert alias linked to an oidc client, despite check box option for "JWT Bearer" is NOT selected in admin UI. 

 When "JWT Bearer" is NOT selected in admin UI, verification cert does not apply to oidc client authentication.

Resolution

Code fix is required from Broadcom engineering or upgrade to latest patch of 12.9.