Unfortunately, CAS doesn't support the deprecated Spring Security password 
encoders by default.

The cleanest method would be to construct a jdbcAuthenticationHandlers bean 
in deployerConfigContext.xml/.groovy with your own password encoder.

IMHO, a far easier method however would be to replace 
StandardPasswordEncoder with your own implementation that delegates to 
ShaPasswordEncoder.


Op maandag 6 februari 2017 17:10:44 UTC+1 schreef Alvaro S.:
>
> Ok, I'm pretty sure what is the error but I don't know how to solve it.
>
> We are using md5 with salt this way
>
> md5(password+salt)
>
> How can I tell CAS that the salt is before the password?
>
> Thanks
>
> On Monday, 6 February 2017 12:54:13 UTC+1, Alvaro S. wrote:
>>
>> I am currently configuring my CAS Server v5.0.2 to use Database 
>> Authentication, particularly using the Encode method, using the CAS 
>> properties file. Below are the relevant property configurations from the 
>> properties file:
>>
>> cas.server.name: https://cas.example.org:8443
>> cas.server.prefix: https://cas.example.org:8443/cas
>>
>>
>> cas.adminPagesSecurity.ip=127\.0\.0\.1
>>
>>
>> logging.config: file:/etc/cas/config/log4j2.xml
>> # cas.serviceRegistry.config.location: classpath:/services
>>
>>
>> cas.authn.accept.users=
>>
>>
>> cas.authn.jdbc.query[0].sql=SELECT password FROM UserSocial WHERE email=?
>> cas.authn.jdbc.query[0].healthQuery=SELECT 1 FROM UserSocial
>> # cas.authn.jdbc.query[0].isolateInternalQueries=false
>> cas.authn.jdbc.query[0].url=jdbc:mysql://*************.
>> amazonaws.com:3306/feisbuk
>> # cas.authn.jdbc.query[0].failFast=true
>> # cas.authn.jdbc.query[0].isolationLevelName=ISOLATION_READ_COMMITTED
>> cas.authn.jdbc.query[0].dialect=org.hibernate.dialect.MySQLDialect
>> # cas.authn.jdbc.query[0].leakThreshold=10
>> # cas.authn.jdbc.query[0].propagationBehaviorName=PROPAGATION_REQUIRED
>> # cas.authn.jdbc.query[0].batchSize=1
>> cas.authn.jdbc.query[0].user=*********
>> # cas.authn.jdbc.query[0].ddlAuto=create-drop
>> # cas.authn.jdbc.query[0].maxAgeDays=180
>> cas.authn.jdbc.query[0].password=****
>> # cas.authn.jdbc.query[0].autocommit=false
>> cas.authn.jdbc.query[0].driverClass=com.mysql.cj.jdbc.Driver
>> # cas.authn.jdbc.query[0].idleTimeout=5000
>> # cas.authn.jdbc.query[0].credentialCriteria=
>>
>>
>> cas.authn.jdbc.query[0].passwordEncoder.type=NONE
>> cas.authn.jdbc.query[0].passwordEncoder.characterEncoding=UTF-8
>> cas.authn.jdbc.query[0].passwordEncoder.encodingAlgorithm=MD5
>> cas.authn.jdbc.query[0].passwordEncoder.secret=lothlorien
>> #cas.authn.jdbc.query[0].passwordEncoder.strength=16
>>
>>
>> # cas.authn.jdbc.query[0].principalTransformation.suffix=
>> cas.authn.jdbc.query[0].principalTransformation.caseConversion=NONE
>> # cas.authn.jdbc.query[0].principalTransformation.prefix=
>>
>> The database I am connecting with is a MySQL. The passwords were 
>> previously encoded using Spring Security's MD5 and a salt-source. I have 
>> tested the CAS DB Authentication configuration by entering valid 
>> credentials in the CAS Server's default login page, but authentication 
>> always fail and return "Invalid credentials." Additionally, It throws me 
>> this error
>> *Authentication has failed. Credentials may be incorrect or CAS cannot 
>> find authentication handler that supports [[email protected] 
>> <javascript:>] of type [UsernamePasswordCredential], which suggests a 
>> configuration problem*
>>
>> This is part of spring security config:
>>
>>         <authentication-manager>
>> <authentication-provider user-service-ref="usersCrmProvider" />
>> <authentication-provider user-service-ref="userDetailsService">
>> <password-encoder hash="md5">
>> <salt-source system-wide="lothlorien" />
>> </password-encoder>
>> </authentication-provider>
>> </authentication-manager>
>>
>> Right now I am looking for any approach on resolving this issue. I am 
>> still relatively new to CAS, and I really appreciate the much needed help. 
>> Thanks!
>>
>

-- 
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/d45d0a7e-f79d-4e7f-bc0b-af9b2a274d11%40apereo.org.

Reply via email to