Yes, you're right. I have also found out that it was caused by the password mismatch, since the password in the database was encoded using Spring Security's ShaPasswordEncoder with SHA-1 and the salt value which was also saved in the database, compared to CAS which uses Apache Shiro's DefaultHashService. Right now I was thinking of modifying the custom authentication handler so I can use the ShaPasswordEncoder in place of the default implementation, but I am still not quite sure how to do that. Do you guys have any idea how to do that? Or are there other alternative implementations?
On Monday, February 6, 2017 at 7:28:34 PM UTC+8, Menno en Erla Avegaart wrote: > > It looks like a simple password mismatch. > > Are you sure the password is salted, hashed and encoded exactly the same? > 1. The salt is prepended. > 2. SHA-1 hashed > 3. Converted to hex > > > Op vrijdag 3 februari 2017 15:15:46 UTC+1 schreef Jihad Talic: >> >> >> >> Hey dkopy..., thank you for replying. I am using the Maven overlay, and >> yes, I have included the dependency in pom.xml, as stated from the site ( >> https://apereo.github.io/cas/5.0.x/installation/Database-Authentication.html). >> >> I have also added the JDBC driver dependency, and checked if the jar files >> of the aforementioned dependencies are present in the WAR file, and yes, >> they are there. >> > -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/ecdec9a1-83d6-428b-88bf-d1ea86324bf7%40apereo.org.
