After upgraded to 12.9, policy server shows error
[mm/dd/yyyy][hh:mm:ss.133][hh:mm:ss][1266948][140359296333568][BaseAccessTokenTunnel.java][formClientObject][Unable to fetch JWT Client Authentication Verification Alias. Exception: com.ca.siteminder.sdk.adminapi.XPSException: attribute CA.FED::OIDCClient JWTSecVerificationAliasLink at com.ca.siteminder.sdk.adminapi.ca.xps.Class.getAttribute(Unknown Source) at com.ca.siteminder.sdk.adminapi.XPSObjectImpl.getAttr(Unknown Source) at com.ca.siteminder.sdk.adminapi.XPSObjectImpl.resolve(Unknown Source) at com.ca.siteminder.sdk.adminapi.XPSObjectImpl.getProperty(Unknown Source) at com.ca.siteminder.sdk.adminapi.XPSObjectImpl.getLink(Unknown Source) at com.ca.siteminder.sdk.adminapi.XPSObjectImpl.getLink(Unknown Source) at com.ca.siteminder.sdk.adminapi.ca.fed.OIDCClient.getJWTSecVerificationAlias(Unknown Source) at com.ca.fedserver.common.tunnel.BaseAccessTokenTunnel.lambda$formClientObject$6(BaseAccessTokenTunnel.java:672) at com.ca.fedserver.common.tunnel.BaseAccessTokenTunnel.formClientObject(BaseAccessTokenTunnel.java:684) at com.ca.federation.openidconnect.tunnel.AccessTokenTunnelService.tunnel(Unknown Source) at com.netegrity.policyserver.smapi.TunnelServiceContext.tunnel(TunnelServiceContext.java:245)
OS: Red Hat Enterprise Linux Server release 8
Policy server version : 12.9; Update: 0.00; Build: 3079
12.9 code is checking verification cert alias linked to an oidc client, despite check box option for "JWT Bearer" is NOT selected in admin UI.
When "JWT Bearer" is NOT selected in admin UI, verification cert does not apply to oidc client authentication.
Code fix is required from Broadcom engineering or upgrade to latest patch of 12.9.