nordic-institute/misp2-web-app

Problems with the Estonian mobileID implementation

Closed this issue · 0 comments

raits commented

Currently, it appears that the Estonian MobileID implementation has some issues:

  • If the "mobileID.rest.trustStore.password" parameter is not set, the service fails to start even if mobileID is not used
  • The "mobileID.rest.trustStore.path" variable is used to search inside the classpath only, which means that the store must be located in the "/var/lib/tomcat8/webapps/misp2/WEB-INF/classes" folder - the user should be able to specify an absolute path in the filesystem instead
  • If the trust store is not found or can not be accessed (file doesn't exist, incorrect file permissions, incorrect password), it just fails silently and the first error is received when the user tries to log in with the mobileID