SAP Knowledge Base Article - Preview

3767731 - sso jwt login fails after jdk 21 migration with invalidbearertokenexception; jwtdecoder must be defined in web context, SAP commerce cloud

Symptom

  • After migrating from JDK 17 to JDK 21, all SSO logins fail.
  • Error: org.springframework.security.oauth2.server.resource.InvalidBearerTokenException: An error occurred while attempting to decode the Jwt: Signed JWT rejected: Another algorithm expected, or no matching key(s) found.
  • Affects tokens from multiple identity providers (with and without the typ header).
  • Worked on JDK 17 and fails only after migrating to JDK 21.


Read more...

Environment

  • Product: SAP Commerce Cloud 2211
  • Platform: JDK 21, Spring Security 6.5.5, nimbus-jose-jwt 10.3.1, resourceserverserver.jar

Product

SAP Commerce Cloud all versions

Keywords

sso, jwt, jdk 21, invalidbearertokenexception, nimbus-jose-jwt, defaultjwtprocessor, rs256, jwks, algorithm expected, no matching keys found, spring security, jwtdecoder, web context, resourceserverserver.jar, 2211 , KBA , CEC-SCC-PLA-PL , Platform , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.