You are not logged in.

Unanswered posts



Important! This site has been replaced. All content here is read-only. Please visit our brand-new community at https://community.talend.com/. We look forward to hearing from you there!



#1 2014-10-03 20:46:40

wholz72
Member
12 posts

wholz72 said:

Problem with WS-Security from Client-Side

Hi there,
I developed a webservice with WS-Security, some costumers works with it without any problems.
Now I've a costumer, he can't connect to this service because of some problems of his software... is it possible to help him with some changes in the configuration? He can't change anything in his software.

the possibility of:

“The Nonce of a UsernameToken must contain a Base64 EncodingType as per the Basic Security Profile 1.1 specification: You can disable Basic Security Profile enforcement in CXF by setting the SecurityConstants property "ws-security.is-bsp-compliant" to "false"”
we tested without any success..

his example of request:

"<SOAP-ENV:Header>
<wsse:Security SOAP-ENV:mustUnderstand="1" xmlns:wsse="">
<wsse:UsernameToken xmlns:wsse="">                       
<wsse:Username xmlns:wsse="">Username</wsse:Username>
<wsse:Password Type=""  xmlns:wsse="">Password</wsse:Password>
<wsu:Created xmlns:wsu="">2014-09-26T13:52:05.274Z</wsu:Created>
<wsse:Nonce xmlns:wsse="">pcDxvAc+9phr5JrnvxeJ5g==</wsse:Nonce>
</wsse:UsernameToken>
</wsse:Security>
</SOAP-ENV:Header>"

my example request via SOAPUI:

"<soapenv:Header>
<wsse:Security xmlns:wsse="" xmlns:wsu="">
<wsse:UsernameToken wsu:Id="UsernameToken-41413B728CF7E395B614117328261961">
<wsse:Username>Username</wsse:Username>
<wsse:Password Type="">Password</wsse:Password><wsse:Nonce EncodingType="">59Y4JmEZXNixwyuBoNouWQ==</wsse:Nonce><wsu:Created>2014-09-26T12:00:26.180Z</wsu:Created>
</wsse:UsernameToken></wsse:Security>
</soapenv:Header>"

thanks for help!

Last edited by wholz72 (2014-10-03 20:49:28)

Offline

#2 2014-10-06 12:01:15

coheigea
Talend Team


coheigea said:

Re: Problem with WS-Security from Client-Side

I've verified with WSS4J that the first example request passes when BSP (Basic Security Profile) compliance is turned off. So the problem appears to be that turning off BSP compliance via "ws-security.is-bsp-compliant" is not working with your configuration.
Could you clarify whether you are using WS-SecurityPolicy to configure the service, or just manually adding the WSS4JInInterceptor? If the latter, then the "ws-security.is-bsp-compliant" tag won't work, as this only works with WS-SecurityPolicy. If this is the case, then you can turn off BSP compliance via setting "isBSPCompliant" to "false".
If this doesn't work, could you also paste the service configuration?
Colm.

Offline

#3 2014-10-06 12:25:48

wholz72
Member
12 posts

wholz72 said:

Re: Problem with WS-Security from Client-Side

coheigea wrote:

I've verified with WSS4J that the first example request passes when BSP (Basic Security Profile) compliance is turned off. So the problem appears to be that turning off BSP compliance via "ws-security.is-bsp-compliant" is not working with your configuration.
Could you clarify whether you are using WS-SecurityPolicy to configure the service, or just manually adding the WSS4JInInterceptor? If the latter, then the "ws-security.is-bsp-compliant" tag won't work, as this only works with WS-SecurityPolicy. If this is the case, then you can turn off BSP compliance via setting "isBSPCompliant" to "false".
If this doesn't work, could you also paste the service configuration?
Colm.

Hi Colm,

I addet the security in the Talend Open Studio at the service... and via the jaas: addet the username and passwort in the karaf-console...
This works with all other clients...

here my config:



# cat org.talend.esb.job.client.sts.cfg ### # #%L # Talend :: ESB :: Job :: Controller # %% # Copyright (C) 2011 Talend Inc.
# %%
# Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License.
# You may obtain a copy of the License at #
#     
#
# Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and # limitations under the License.
# #L%
###

#STS endpoint configuration
#sts.wsdl.location =
sts.wsdl.location =

sts.x509.wsdl.location =

sts.namespace =
sts.service.name = SecurityTokenService
sts.endpoint.name = UT_Port
sts.x509.endpoint.name = X509_Port

#STS properties configuration
ws-security.sts.token.username = myclientkey ws-security.sts.token.usecert = true ws-security.is-bsp-compliant = false ws-security.sts.token.properties = file:${tesb.home}/etc/keystores/clientKeystore.properties
ws-security.encryption.username = mystskey ws-security.encryption.properties = file:${tesb.home}/etc/keystores/clientKeystore.properties


# cat org.talend.esb.sts.server.cfg ### # #%L # TESB :: STS :: CONFIG # %% # Copyright (C) 2011 Talend Inc.
# %%
# Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License.
# You may obtain a copy of the License at #
#     
#
# Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and # limitations under the License.
# #L%
###

stsServiceUrl=/SecurityTokenService/UT
stsX509ServiceUrl=/SecurityTokenService/X509
jaasContext=karaf
signatureProperties=file:${tesb.home}/etc/keystores/stsKeystore.properties
signatureUsername=mystskey
bspCompliant=false
useMessageLogging=false
samlTokenLifetime=1800

thanks
Wolfgang

Offline

#4 2014-10-16 15:55:23

coheigea
Talend Team


coheigea said:

Re: Problem with WS-Security from Client-Side

Hi Wolfgang,
Sorry for the delay in replying. The answer is that there is no way to disable Basic Security Profile compliance in the container configuration files right now. To disable Basic Security Profile compliance, you will need to open up the .kar + change the blueprint configuration for the service, adding "<entry key="ws-security.is-bsp-compliant" value="false"/>" as a JAX-WS property. For example:
<jaxws:endpoint xmlns:jaxws=""
            id="DoubleItService"
            implementor="#genericServiceProvider"
            xmlns:tns=""
            serviceName="tns:DoubleItService"
            endpointName="tns:DoubleItServicePort"
            address="/DoubleItService"
            wsdlLocation="classpath:/DoubleItService_0.1.wsdl">
        <jaxws:properties>
             <entry key="ws-security.ut.validator">
                <bean class="org.apache.ws.security.validate.JAASUsernameTokenValidator">
                    <property name="contextName" value="karaf" />
                </bean>
            </entry>
            <entry key="ws-security.is-bsp-compliant" value="false"/>
            <entry key="use.service.registry" value="false" />
        </jaxws:properties>
        <jaxws:features>
               <p:policies xmlns:p="">
                <wsp:Policy xmlns:wsp="">
                     <wsp:PolicyReference URI="org.talend.esb.job.token.policy" />
                 </wsp:Policy>
            </p:policies>
          </jaxws:features>
    </jaxws:endpoint>
Colm.

Offline

#5 2015-03-23 16:47:43

shvmudunuru
Member
4 posts

shvmudunuru said:

Re: Problem with WS-Security from Client-Side

Hi,
How can we open the .kar file to change the blueprint configuration?

Offline

#6 2017-03-20 14:03:10

kalpeshbadhe
Member
11 posts

kalpeshbadhe said:

Re: Problem with WS-Security from Client-Side

You can use winrar to open kar file.
Right click on .kar and select open with win rar.

Offline

Board footer

Talend Contributor Agreement - Talend Website Privacy Policy