Skip to content
Connect2id
Connect2id server

Connect2id server 20.0

Connect2id server 20.0 moves to Java 21, introduces per-authorisation signing algorithms for JWT access tokens, updates Native SSO session handling and adds TLS support for Redis connections. The release also upgrades the underlying Infinispan and AWS SDK dependencies.

Java 21 and 25

Version 20.0 targets Java 21 and supports running on Java 21 and 25. Deployments running an earlier Java version must update their runtime before upgrading the server.

The c2id/c2id-server-min:20.0 Docker image uses Java 25, which offers reduced heap memory usage through compact object headers. Enable this feature with the following JVM option:

-XX:+UseCompactObjectHeaders

Per-authorisation signing algorithms for access tokens

Deployments issuing self-contained (JWT-encoded) access tokens can now select the JWS signing algorithm for each authorisation. This enables deployments to accommodate APIs with different signing requirements and introduce a new algorithm selectively.

Algorithm selection can address compatibility, security policy, token size and performance requirements. For a comparison of signing and verification speeds, see our 2018 Nimbus JOSE+JWT benchmarks. Results vary with the runtime, cryptographic provider and hardware.

The consent, direct authorisation and CIBA web APIs accept an optional access_token.jws_alg parameter. The integration can use the requested scope, client ID or other criteria to decide which algorithm to apply.

Example consent that sets a specific JWS algorithm for the access token:

{
  "scope"        : [ "urn:c2id:scope:accounts:read",
                     "urn:c2id:scope:accounts:transfer" ],
  "access_token" : { "jws_alg" : "ES256" }
}

Custom OAuth 2.0 grant handlers can make the same choice through the updated AccessTokenSpec in Connect2id server SDK 6.0.

The authzStore.accessToken.jwsAlg configuration property specifies the default algorithm. It continues to apply whenever an authorisation does not specify an override.

The built-in client credentials, self-issued JWT bearer and device SSO grant handlers also receive optional configuration properties for choosing their access token signing algorithm.

Native SSO session claims and data

OpenID Connect Native SSO enables applications from the same vendor to share a device session linked to a device_secret.

When the server creates a native client group (NCG) session, it now copies the claims and data from the web session used to authenticate the end-user. These fields are updated again whenever an application in the group completes a new successful OAuth 2.0 authorisation request, using the web session associated with that authentication.

This makes the web session’s claims and application-specific data available in the shared native session, and refreshes them as users complete subsequent authorisations.

TLS connections to Redis

Redis-backed deployments can now enable TLS by setting the redis.tls Java system property to true.

By default, the server uses the JVM’s trust store to verify the Redis server certificate. Deployments using a private certificate authority can configure a custom trust store with redis.tls.trustStore and its accompanying password property.

For Redis installations that require mutual TLS, the optional redis.tls.keyStore and password properties provide the client private key and certificate chain.

Infinispan and AWS SDK updates

The release upgrades Infinispan from 14.0 to 16.2 and migrates from AWS SDK for Java 1.x to 2.x. The supplied Infinispan XML configurations use the 16.2 schema.

Upgrading to 20.0

Alongside the Java runtime requirement, deployments should account for the following changes:

  • SQL schema update. The long_lived_authorizations table gains an ata (access token JWS algorithm) column. The server adds it automatically on startup, with an appropriate default value. If automatic schema changes are disabled through dataSource.createTableIfMissing=false, arrange for the column to be added before starting the upgraded server.

  • Infinispan XML customisations. If you have modified an Infinispan XML file directly, review your changes against the supplied 16.2 configurations. This review is not required if you use the supplied XML files and configure them through Java system properties.

  • Asynchronous session purges. The session store /purge endpoint now returns HTTP 202 Accepted for asynchronous requests.

  • Legacy session identifiers. Support for sessionStore.acceptLegacySIDs and the Legacy-SID request header is removed. These deprecated options, originally added in March 2017, enabled import of sessions from Connect2id server 5.x and older, whose identifiers lacked HMAC protection.

The release also includes fixes to client authentication error reporting, access token certificate-chain handling and session store maintenance. See the release notes for the complete list of changes.

New login pages designed for secure AI-assisted customisation

We have started a new project to develop sample login and logout pages for the Connect2id server. Planned scenarios include common two-factor authentication methods, third-party identity providers (social logins) and SAML logins.

New Connect2id server login page

The pages are rendered entirely on the server, with no client-side JavaScript required. Avoiding a client-side framework keeps the implementation simpler and reduces exposure to third-party script risks and the dependency risks documented in npm ecosystem research.

Our aim is to provide strong software foundations for customisation with coding agents and LLMs: clear code and templates, documented security practices, and tests that help catch unsafe changes. We will develop this guidance and validation alongside the sample pages, helping teams benefit from AI-assisted development while preserving the security of their authentication flows.

Download 20.0

For the signature validation: Public GPG key

Standard Connect2id server edition

Apache Tomcat package with Connect2id server 20.0: Connect2id-server.zip

GPG signature: Connect2id-server.zip.asc

SHA-256: ec3ec71940645398dc53d1b667835b2953c19e12824d0966be2573e9bcd8873c

Connect2id server 20.0 WAR package: c2id.war

GPG signature: c2id.war.asc

SHA-256: 9c2a45f17f96ccb1d663dd51526a64588ecbf21ae4e2b27fc75f91367bfbfc9b

Multi-tenant edition

Apache Tomcat package with Connect2id server 20.0: Connect2id-server-mt.zip

GPG signature: Connect2id-server-mt.zip.asc

SHA-256: 561366e1abe47e444b7b1f5a5962127e0153ab20a4cad501414575a513bf94b7

Connect2id server 20.0 WAR package: c2id-mt.war

GPG signature: c2id-mt.war.asc

SHA-256: 9bc7d6d5b993e55be7b0cf227a934066c5f0f5080fb14d6b609e80b21cadd432

Questions?

For technical questions about this new release contact Connect2id support. To purchase a production license for the Connect2id server, renew or upgrade your support and updates subscription, email our sales.


Release notes

20.0 (2026-10-07)

Summary

  • Targets Java 21 and supports running on Java 21 and 25.

  • Adds support for overriding the JWS algorithm for self-contained (JWT-encoded) access tokens per authorisation, through the consent web APIs or the grant handler SPIs. The authzStore.accessToken.jwsAlg configuration property now specifies the default algorithm, used when no algorithm is specified for an authorisation.

  • Updates OpenID Connect Native SSO. When the Connect2id server creates a new native client group (NCG) session linked to a device_secret, the session inherits the claims and data of the web session where the end-user was authenticated. The NCG session claims and data are also updated whenever a native client participating in the group makes a new successful OAuth 2.0 authorisation request, from the web session used to authenticate the end-user.

  • Adds support for TLS connections to Redis, with optional custom trust and key stores.

  • Upgrades Infinispan from version 14.0 to 16.2.

  • Migrates from AWS SDK for Java 1.x to 2.x.

Configuration

  • /WEB-INF/autzStore.properties

    • authzStore.accessToken.jwsAlg – Now specifies the default JWS algorithm for self-contained (JWT-encoded) access tokens, used when no algorithm is specified for an individual authorisation. In previous releases, this property determined the algorithm for all self-contained access tokens.
  • /WEB-INF/sessionStore.properties

    • sessionStore.acceptLegacySIDs – Removes support for the deprecated configuration property. It enabled import of sessions from Connect2id server versions 5.x and older. When true it allowed acceptance of legacy session identifiers (SID) without HMAC protection.
  • /WEB-INF/clientGrantHandler.properties

    • op.grantHandler.clientCredentials.simpleHandler.accessToken.jwsAlg – New optional configuration property to specify the JWS algorithm for self-contained (JWT-encoded) access tokens. If blank or omitted the default algorithm configured by authzStore.accessToken.jwsAlg applies.
  • /WEB-INF/selfIssuedJWTBearerHandler.properties

    • op.grantHandler.selfIssuedJWTBearer.accessToken.jwsAlg – New optional configuration property to specify the JWS algorithm for self-contained (JWT-encoded) access tokens. If blank or omitted the default algorithm configured by authzStore.accessToken.jwsAlg applies.
  • /WEB-INF/deviceSSOHandler.properties

    • op.deviceSSOHandler.accessToken.jwsAlg – New optional configuration property to specify the JWS algorithm for self-contained (JWT-encoded) access tokens. If blank or omitted the default algorithm configured by authzStore.accessToken.jwsAlg applies.
  • /WEB-INF/infinispan-*.xml

    • Upgrades the XML schema to Infinispan 16.2.
  • /WEB-INF/infinispan-*-{mysql|postgres95|sqlserver|oracle|h2}.xml

    • Adds a new ata column to the long_lived_authorizations table. In existing Connect2id server deployments with an SQL RDBMS the server will automatically add the new column (with an appropriate default value) on startup. For SQL databases the automatic column addition is enabled by default and can be turned off by setting the dataSource.createTableIfMissing Java system property to false.
  • /WEB-INF/infinispan--redis-.xml

    • redis.tls – New optional Java system property to enable TLS for Redis connections. Set to true to enable TLS. Defaults to false.

    • redis.tls.trustStore – New optional Java system property to specify
      the path to a custom trust store containing trusted X.509 certificates for verifying the Redis server certificate. If TLS is enabled and this property is not set, the JVM’s default trust store, typically ${java.home}/lib/security/cacerts is used. No default value.

    • redis.tls.trustStore.password – New optional Java system property to specify the password for the custom trust store. No default value.

    • redis.tls.keyStore – New optional Java system property to specify the path to a custom key store containing the client private key and certificate chain for TLS client authentication to Redis. If not set, no client certificate is presented. Required when Redis is configured to require TLS client authentication. No default value.

    • redis.tls.keyStore.password – New optional Java system property to specify the password for the custom key store. No default value.

Web API

  • /authz-sessions/rest/v3/

    • The consent prompt receives a new optional access_token.jws_alg parameter, to enable deployments to override the default authzStore.accessToken.jwsAlg configuration property for specific OAuth 2.0 authorisation requests, based on the scope, client_id or another criteria.
  • /direct-authz/rest/v2

    • The direct authorisation request receives a new optional access_token.jws_alg parameter, to enable deployments to override the default authzStore.accessToken.jwsAlg configuration property for specific requests, based on the scope, client_id or another criteria.
  • /ciba-sessions/rest/v1

    • The CIBA authorisation receives a new optional access_token.jws_alg parameter, to enable deployments to override the default authzStore.accessToken.jwsAlg configuration property for specific requests, based on the scope, client_id or another criteria.
  • /session-store/rest/v2

    • The purge resource now returns HTTP 202 Accepted for asynchronous purges.

    • Removes support for the deprecated Legacy-SID HTTP request header,
      alongside removal of the sessionStore.acceptLegacySIDs configuration property.

SPI

  • Upgrades the Connect2id server SDK to com.nimbusds:c2id-server-sdk:6.0

    • AccessTokenSpec – Enables OAuth 2.0 grant handler SPIs to set a specific JWS algorithm for self-contained (JWT) access tokens, overriding the default algorithm configured in authzStore.accessToken.jwsAlg.

    • JWTSigner – Enables SPI implementations that issue signed JSON Web Tokens (JWT) to set a specific JWS algorithm. Previously the Connect2id server signed the JWTs using the algorithm configured in authzStore.accessToken.jwsAlg, which remains the default setting in the updated JWTSigner.

Resolved issues

  • Token requests with missing required client authentication must log and return client_auth_id (issue server / 1224).

  • Removes obsolete DynamoDB item sanitisation as no longer required for current DynamoDB and AWS SDK 2.x (issue dynamodb / 33).

  • The LDAP claims source must not treat a missing configuration file (/WEB-INF/ldapClaimsSource.properties) as an error (issue claims-source-ldap / 5).

  • Prevents configuration of non-positive DynamoDB read-capacity,
    write-capacity and purge-max-read-capacity values (issue server / 963).

  • The authzStore.accessToken.includeX5C configuration property must be applied to ECDSA (ES256, ES384, ES512) signed access tokens, instead of always including the X.509 certificate chain (issue authz-store / 255).

  • Defines the SQL pending_codes.acl table column as NOT NULL for new deployments (issue authz-store / 261).

  • Adds extra protections to retrieve pending authorisation SQL records with an undefined acl field as expired (issue authz-store / 260).

  • The authorisation session web API must reject submitted subject sessions with a ctx (context) value that is not web or unspecified (implies the default web). This is to prevent login pages from creating subject sessions with inappropriate ctx, such as NCG (native client group), in browser-based OAuth 2.0 flows (issue server / 1230).

  • Prevents the purge of orphaned subject keys in the session store from running concurrently with itself (issue session-store / 112).

  • Bounds the session store async web API /purge requests to a single worker with no queue (issue session-store / 111).

  • The session store /purge endpoint should return HTTP 202 Accepted for asynchronous purges (issue session-store / 116).

  • Improves the OP7112 log info message native client group (native) SSO (issue server / 1228).

  • Fixes /index.jsp HTML markup issues (issue server / 1234).