Symptom
- After migrating from JDK 17 to JDK 21, all SSO logins fail.
- Error: org.springframework.security.oauth2.server.resource.InvalidBearerTokenException: An error occurred while attempting to decode the Jwt: Signed JWT rejected: Another algorithm expected, or no matching key(s) found.
- Affects tokens from multiple identity providers (with and without the typ header).
- Worked on JDK 17 and fails only after migrating to JDK 21.
Read more...
Environment
- Product: SAP Commerce Cloud 2211
- Platform: JDK 21, Spring Security 6.5.5, nimbus-jose-jwt 10.3.1, resourceserverserver.jar
Product
SAP Commerce Cloud all versions
Keywords
sso, jwt, jdk 21, invalidbearertokenexception, nimbus-jose-jwt, defaultjwtprocessor, rs256, jwks, algorithm expected, no matching keys found, spring security, jwtdecoder, web context, resourceserverserver.jar, 2211 , KBA , CEC-SCC-PLA-PL , Platform , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview