Yes, you're right. I have also found out that it was caused by the password 
mismatch, since the password in the database was encoded using Spring 
Security's ShaPasswordEncoder with SHA-1 and the salt value which was also 
saved in the database, compared to CAS which uses Apache Shiro's 
DefaultHashService. Right now I was thinking of modifying the custom 
authentication handler so I can use the ShaPasswordEncoder in place of the 
default implementation, but I am still not quite sure how to do that. Do 
you guys have any idea how to do that? Or are there other alternative 
implementations?

On Monday, February 6, 2017 at 7:28:34 PM UTC+8, Menno en Erla Avegaart 
wrote:
>
> It looks like a simple password mismatch.
>
> Are you sure the password is salted, hashed and encoded exactly the same?
> 1. The salt is prepended.
> 2. SHA-1 hashed
> 3. Converted to hex
>
>
> Op vrijdag 3 februari 2017 15:15:46 UTC+1 schreef Jihad Talic:
>>
>>
>>
>> Hey dkopy..., thank you for replying. I am using the Maven overlay, and 
>> yes, I have included the dependency in pom.xml, as stated from the site (
>> https://apereo.github.io/cas/5.0.x/installation/Database-Authentication.html).
>>  
>> I have also added the JDBC driver dependency, and checked if the jar files 
>> of the aforementioned dependencies are present in the WAR file, and yes, 
>> they are there. 
>>
>

-- 
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/ecdec9a1-83d6-428b-88bf-d1ea86324bf7%40apereo.org.

Reply via email to