CAS Oauth2 and JHipster app

I am testing CAS Oauth2 with JHipster so I have created this repository to keep track what I have done.

Building steps

Here is summary of steps

  1. Create JHipster application
    • Add entity CITY and configure sample data
    • Start docker container as postgres development database
    • Run initial application with development profile
  2. CASifying application
    • Enable SSL for JHipster application
    • Configure CAS OAuth2 docker container
    • Adjust JHipster to use CAS for authentication
  3. Frontend proxy
    • Configure reverse proxy
    • Add security via mod_auth_cas

1. Create JHipster application

mkdir casoauth2
cd casoauth2
yo jhipster
  • Monolithic application
  • Type of authentication - select OAuth2 Authentication
  • PostgreSQL as production and development database
  • Maven

Add entity CITY and configure sample data

yo jhipster:entity city

2 attributes:

  • name
  • country

Modify liquibase script to prepare initial sample data. Create file src/main/resources/config/liquibase/cities.csv with sample data. Create new changeset in src/main/resources/config/liquibase/changelog/*added_entity_City.xml to load data.

Start docker container as postgres development database

As I ma using few docker postgres containers I am running this one with port 5232

docker run --name pgdev2 -p 5232:5432 -e POSTGRES_USER=casoauth2 -d postgres:9.5.4

in order to work with application there is need to change src/main/resources/config/application-dev.yml


    type: com.zaxxer.hikari.HikariDataSource
    url: jdbc:postgresql://localhost:5432/casoauth2
    username: casoauth2


    type: com.zaxxer.hikari.HikariDataSource
    url: jdbc:postgresql://localhost:5232/casoauth2
    username: casoauth2
    password: casoauth2

2. CASifying application

Here we modify application from step 1. to use CAS as OAuth2 SSO. This part I have done based on various examples from Github and Spring. For development purpose we will use docker container for CAS server and modify JHipster to use it.

Enable SSL for JHipster application

keytool -genkey -noprompt\
 -alias jhoauth2\
 -keyalg RSA\
 -validity 999\
 -dname ", OU=Test, O=Test, L=Test, S=Test, C=SK"\
 -keystore src/main/docker/keystore\
 -storepass changeit\
 -keypass changeit
  • change port in config file. I will set it to 8825. In addition I will set context path to demo for JHipster application.

Modify server section in src/main/resources/config/application-dev.yml


    port: 8080


    contextPath: /demo
    port: 8825
        key-store: src/main/docker/keystore
        key-password: changeit
        key-store-password: changeit
        enabled: true

Configure CAS OAuth2 docker container

For demo purpose CAS server will be modified to use JHipster database as user repository so we can keep using JHipster for user management and CAS for authentication. As I want to use database authentication I need to change pom.xml in overlay project and build it. As it take time I am creating src/main/docker-cas where I will prebuild image for this demo.

Build docker image locally for cas (as of 5.0.1 there is still bug using BCrypt and database authentication so fix is done localy)

cd src/main/docker-cas
docker build -t rohajda/cas-oauth2:v5.0.1 .
cd ../../..

Create thekeystore for CAS

keytool -genkey -noprompt\
    -alias cas\
    -keyalg RSA\
    -validity 999\
    -dname ", OU=Test, O=Test, L=Test, S=Test, C=SK"\
    -keystore src/main/docker/thekeystore \
    -storepass changeit\
    -keypass changeit

Register certificate as trusted in java

keytool -export -alias cas -storepass changeit -file src/main/docker/cas2.cer -keystore  src/main/docker/thekeystore
sudo keytool -import -alias cas2 -keystore $JAVA_HOME/jre/lib/security/cacerts -file src/main/docker/cas2.cer

Add alias for localhost to hosts file


Run development CAS server

docker run --name cas2 -p 8843:8843 --link pgdev2:pgdev2\
 -v $(pwd)/src/main/docker/thekeystore:/etc/cas/thekeystore \
 -v $(pwd)/src/main/docker/dev/cas/config/\
 -v $(pwd)/src/main/docker/dev/cas/config/log4j2.xml:/cas-overlay/etc/cas/config/log4j2.xml\
 -v $(pwd)/src/main/docker/dev/cas/services:/etc/cas/services\

Adjust JHipster to use CAS OAuth2 for authentication

        clientId: clientid
        clientSecret: clientSecret
        tokenName: access_token
        authenticationScheme: query
        clientAuthenticationScheme: form

Remove unused classess

  • AjaxLogoutSuccessHandler
  • OAuth2ServerConfiguration

Remove from liquibase initial change log oauth2 related objects

Modify classes and java script files

  • auth.service.js

Add new logout controller (workaround as I did not manage to go around CORS related issues with redirect to CAS)


Run initial application with development profile

Use IntelliJ run option or use command line from terminal ./mvnw

Run production setup

  • build first (i am skipping test as i did not have time to fix karma test)

              mvn clean
      ./mvnw package -Pprod -DskipTests docker:build
  • start docker compose

    docker-compose -f src/main/docker/app.yml up

  • connect to application as admin/admin

3. Frontend proxy

In production like environmnet DMZ will have reverse proxy server routing request to internal network where is CAS and JHipster application. In addition as per some customer they requesting extra security that will ensure that all requests reaching internal JHipster application are authenticated and if needed extra 2fa authentication can be configured. To simulate my customer requirement OS used will be Centos 7.

Configure reverse proxy

In this step we will build docker image with httpd 2.4 , mod ssl and proxy. In addition I have build rpm for mod_auth_cas using git project (i have fixed some small issue of original project so it generates artifact as I needed). As httpd will redirect to cas2 server i need cas2 certificate to be registered to trusted one.

Build image with httpd and other parts needed for docker-compose

cd src/main/docker-httpd
docker build -t rohajda/casoauth2-httpd:v1.0 .
cd ../../..

Register new alias for localhost in /etc/hosts

Generate server certificate for SSL mode

keytool -genkey -noprompt -alias fr -keyalg RSA -validity 999 -dname ", OU=Test, O=Test, L=Test, S=Test, C=SK" -keystore src/main/docker/httpd/frkeystore -storepass changeit -keypass changeit;

openssl req -new -x509 -nodes -subj "/C=SK/ST=Test/L=Test/O=Dis/" -out src/main/docker/httpd/ -keyout src/main/docker/httpd/

Configure simple reverse proxy by adding below text to ssl.conf file at the end of file before </VirtualHost> Setup is for demo only so real securing should be done on reverese proxy and it is outside of this demo scope.


SSLCertificateFile /etc/pki/tls/certs/
SSLCertificateKeyFile /etc/pki/tls/private/

ServerAdmin webmaster@localhost
ProxyPreserveHost On
SSLProxyEngine on
SSLProxyVerify none
SSLProxyCheckPeerCN off
SSLProxyCheckPeerName off
SSLProxyCheckPeerExpire off


ProxyRequests off
ProxyPass "/demo/" ""
ProxyPassReverse "/demo/" ""
ProxyPass "/cas/" ""
ProxyPassReverse "/cas/" ""

Start docker compose and test direct access as well as access via reverse proxy

docker-compose -f src/main/docker/app.yml up

Add extra authentication on reverse proxy using mod_cas_auth module

  • configure auth_cas.conf on httpd server

auth_cas.conf file

<IfModule !mod_ssl.c>
    LoadModule ssl_module modules/

LoadModule auth_cas_module modules/

CASCookiePath /var/cache/httpd/cas/




CASCertificatePath /etc/ssl/certs/
  • setup authentication for /demo/ location in ssl.conf

ssl.conf file (add lines after ProxyPassReverse "/cas/" ""

<Location "/demo/">
   Authtype CAS
   AuthName 'CAS'
   Require valid-user
  • Add new service in CAS configuration for reverse proxy FRONT-102.json
  • start environment via docker-compose -f src/main/docker/app.yml up

We are ready to test direct access and reverese proxy

Direct Access

Reverse Proxy

Important to add is that user need to provide username/password only once at reverese proxy. Rest is taken care by SSO CAS feauture. Having 2 services on CAS enabling easily control who can access from outside as well allowing to add additional authentication factors that are not required if user is in internal network without changing JHipster application.

