【问题标题】:In Spring-WS, while using WS-SecurityPolicy, how do I specify strict layout?在 Spring-WS 中,使用 WS-SecurityPolicy 时,如何指定严格的布局?
【发布时间】:2014-10-06 13:57:14
【问题描述】:

我正在尝试使用 Websphere 公开的具有 WS-SecurityPolicy 和严格布局的 Web 服务。由于布局排序,Spring-WS 客户端生成的 SOAP 失败。

确切的错误是这样的(我使用的是时间戳,带有加密和签名):

Signature for timestamp found ahead of timestamp. Strict Layout not followed in incoming message.

我正在使用 Wss4jSecurityInterceptor。但我找不到 WSS4J 属性来强制执行严格的布局。

更新:我在 Spring 论坛 here 中发现了一个类似的查询。没有对该查询的回应。

【问题讨论】:

    标签: spring-ws ws-security wss4j


    【解决方案1】:

    您可能需要升级到更新版本的 WSS4J。见:

    https://issues.apache.org/jira/browse/WSS-424

    科尔姆。

    【讨论】:

    • 最新的 Spring-WS 使用 WSS4J 1.6.5。不幸的是,修复版本 WSS4J 1.6.10 在直接删除时失败,并出现其他一些错误。我正在扩展 Wss4jSecurityInterceptor 以在节点周围移动。如果可行,我将添加解决方案。
    【解决方案2】:

    Spring Web 服务(最新版本使用 WSS4J 1.6.5)不公开任何用于更改布局的属性。在 Wss4jSecurityInterceptor 中的 WSS4J 调用之后,我必须添加一个拦截器以编程方式在肥皂消息中的时间戳节点周围移动。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 2011-04-24
      • 1970-01-01
      • 2012-09-20
      • 1970-01-01
      • 2011-10-13
      • 2014-07-30
      • 1970-01-01
      相关资源
      最近更新 更多