IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only

Token identification in RunTime Database

  • 1.  Token identification in RunTime Database

    Posted 10/30/18 10:49 PM

    Hi Community,

     

    We are on ISAM 9.0.5

     

    In the AAC's Advanced Configuration, we have

    runtime.hashAlgorithm = SHA-512

    oauth20.hashedTokenStorageEnabled = true

     

    (0ur refresh tokens have a length of 500)

     

    I went trough the oauth workflow & obtained the following tokens:

     

    {

                    "access_token": "hzty0Q6QzUNJUXkG1oUZ",

                    "refresh_token": "bvIHo5pacEeeF2QeI3jLl5XMa0pnW8cr05ka2ZPIBGQAFKT4obeIDasn57HJ7fF3td9NODuwfRtzQBRTGw4aRGDTi5lUEwcNUDMKiX9JwOZ1y1PwAfNgdICYuo7vv8IdLBDb2QzgP8zY1cCNE0i7TUHLpoZmwGs1uAzKo5TKJy2K8pwNJ4XtCZfeQB1l1peap1IbvbC2f1zQVcentUSDjb8lzwXKggQM7CKQkrYuiLQCaQVMcNovo2tT4wxTX7cH1J9p4vUd3eDPQ2chWZLLRS0WGSwkScwBxky7TdZCJMotNfZV6220UjiAs0qywUyUIvIp7kfrKMfLF04hDqJZfBkjnFRhORKiSxdFvfKKBr95yUtGbCkwxNaLAPjc5GFsaa7G4JqkdaZzAxZ6MVI2dpNWPf2GCtqPbID0hgOdZ3P40AyZaDMGhY60OWsIsRAg2WsVWdl9Dr5LNPE8JeaMKPUwceTpbjq3DkhvdTeum3v7J26HfHKA",

                    "token_type": "bearer",

                    "expires_in": 14

    }

     

     

    when I look in the runtime database in the OAUTH20_TOKEN_CACHE table I see the following two entries that correspond to the access & refresh token just obtained.

     

    SUB_TYPE=refresh_token

    TOKEN_ID={SHA-512}1rQqgCc+g3/jZ1VYnnO5A4UsPNtpNQp45ZrLm3bKBxRTTyaAgLAKirG9cd6rZW34vpBsMwNvzBnkIHRA8BaAmg==

     

    SUB_TYPE=bearer

    TOKEN_ID={SHA-512}FfQIQmBG1VK0654Wl/iRANzQ1/2ya3IDOkCNUV0HNG6hScfxiicjxDLfTeN62LPsR6tYat3R4KxqkF86siZTSw==

     

     

    But I cannot seem to recreate the procedure used to go from Refresh_Token (RT) to TOKEN_ID

     

    if I try:

    RT -> SHA-512 -> Base64 -> the length is too long (*)

     

    I tried:

    RT -> SHA-256 -> Base64 -> I get the good length but the values don't match (**)

     

     

    Could someone help me? I need this because I am tracing in production some refresh_token that are being rejected & I would like to look in the Database to get a clue as to why this is happening.

     

    Many thanks,

    Louis

     

     

    (*)

    for the RT shown previously (starting with bvIHo5p... )

    SHA-512 gives:

    D6B42A80273E837FE36755589E73B903852C3CDB69350A78E59ACB9B76CA0714534F268080B00A8AB1BD71DEAB656DF8BE906C33036FCC19E4207440F016809A

    Base64 gives:

    RDZCNDJBODAyNzNFODM3RkUzNjc1NTU4OUU3M0I5MDM4NTJDM0NEQjY5MzUwQTc4RTU5QUNCOUI3NkNBMDcxNDUzNEYyNjgwODBCMDBBOEFCMUJENzFERUFCNjU2REY4QkU5MDZDMzMwMzZGQ0MxOUU0MjA3NDQwRjAxNjgwOUE=

    which is way longer than the value in the DB:

    1rQqgCc+g3/jZ1VYnnO5A4UsPNtpNQp45ZrLm3bKBxRTTyaAgLAKirG9cd6rZW34vpBsMwNvzBnkIHRA8BaAmg==

     

    (**)

    for the RT shown previously (starting with bvIHo5p... )

    SHA-256 gives:

    D77CD4AEA9F4F33DFFA854F6791F41000A08FD37250C9C42626578DB75737588

    Base64 gives:

    RDc3Q0Q0QUVBOUY0RjMzREZGQTg1NEY2NzkxRjQxMDAwQTA4RkQzNzI1MEM5QzQyNjI2NTc4REI3NTczNzU4OA==

    which is the same length as the value in the DB, but different:

    1rQqgCc+g3/jZ1VYnnO5A4UsPNtpNQp45ZrLm3bKBxRTTyaAgLAKirG9cd6rZW34vpBsMwNvzBnkIHRA8BaAmg==

    (the length seem to imply that the hash is a SHA-256 even though our setting state SHA-512 )



    ------------------------------
    Louis Beaudry
    Access Management
    Intact Financial Corporation
    ------------------------------