Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-3524

Support Derived Keys with the Symmetric Binding + SAML Assertions

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 2.4
    • 2.4.1
    • WS-* Components
    • None
    • Blocked on External

    Description

      There are a couple of problems with using Derived Keys pointing towards SAML Assertions when using the symmetric binding:

      1) The SymmetricBindingHandler can't handle creating a reference to SAML Assertion if the security token does not have a (un)attached Reference to the Assertion.
      2) In the holder-of-key case, using a derived key will cause the holder-of-key requirements processing to fail.

      Creating a JIRA + patch for this, as it depends on a fix in WSS4J 1.6.1 which is not released yet.

      Attachments

        1. cxf-3524.patch
          7 kB
          Colm O hEigeartaigh

        Activity

          People

            coheigea Colm O hEigeartaigh
            coheigea Colm O hEigeartaigh
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: