Uploaded image for project: 'Help-Desk'
  1. Help-Desk
  2. HELP-20051

FIWARE.Question.Tech.Unable to use JWT token generated from Fiware Keyrock.

    Details

      Description

      Created question in FIWARE Q/A platform on 09-09-2022 at 16:09
      Please, ANSWER this question AT https://stackoverflow.com/questions/73665080/unable-to-use-jwt-token-generated-from-fiware-keyrock

      Question:
      Unable to use JWT token generated from Fiware Keyrock

      Description:
      For the Fiware security layer Keyrock version 8.0.0, Wilma version 8.0.0 and Authzforce version release-10.0.0 are configured.
      Keyrock generates a Bearer token that works properly for Orion authorization. But, the problem comes if I use a JWT token instead. I generate a JWT token by adding the scope option in the request:
      POST /oauth2/token HTTP/1.1 Host: localhost:3005 Authorization: Basic MTlmMjdiZGMtMTM1My00MTY5LTkxN2ItZTI1NTVjNDYwYzUyOjU4YWIxZTFjLTBkYjktNDBmZi1hMmUyLTJjZTYyNjNlNjI1Yg== Content-Type: application/x-www-form-urlencoded grant_type=password&usernameusername1&password=password1&scope=jwt
      When I try to access Orion through Wilma using the below request, Wilma reports the error "AZF domain not created for application 19f27bdc-1353-4169-917b-e2555c460c52":
      GET /version HTTP/1.1 Host: localhost:1022 Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJvcmdhbm......uPPQk6TdAT-b-8nDEU_l8JdIkJeSIDzTQvfOHX1PYeU.
      Moreover, in Keyrock GUI for the application all Grant Types are selected. And, for Token types "JWT token" is selected.
      Also in Wilma configuration property for JWT Secret is added (PEP_TOKEN_SECRET=5e39ee34ad881b01).
      I removed a few times az_domain from authzforce table in MySQL database and recreated it by adding new roles/permissions from the Keyrock GUI, but that new domain didn't solve the problem either.
      I hope someone can help me. Thanks in advance.

        Activity

        Hide
        backlogmanager Backlog Manager added a comment -

        2022-09-10 05:31|CREATED monitor | # answers= 0, accepted answer= False

        Show
        backlogmanager Backlog Manager added a comment - 2022-09-10 05:31|CREATED monitor | # answers= 0, accepted answer= False

          People

          • Assignee:
            aalonsog Alvaro Alonso
            Reporter:
            backlogmanager Backlog Manager
          • Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: