CXF
  1. CXF
  2. CXF-4277

STSClient does not use returned KeyInfo size when creating a secret key

    Details

    • Type: Bug Bug
    • Status: Closed
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: 2.4.7, 2.5.3, 2.6
    • Fix Version/s: 2.3.11, 2.4.8, 2.5.4, 2.6.1
    • Component/s: WS-* Components
    • Labels:
      None
    • Estimated Complexity:
      Unknown

      Description

      The STSClient does not use the returned KeyInfo size when creating a secret key. This means that it creates an incorrect secret key in the case where an STS rejects the submitted KeySize, and returns a different KeySize to the client.

        Activity

          People

          • Assignee:
            Colm O hEigeartaigh
            Reporter:
            Colm O hEigeartaigh
          • Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development