Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-5046

EncryptedSupportingTokens used with EncryptBeforeSigning does not encrypt Username token

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 2.6.2, 2.7.5
    • 2.6.8, 2.5.11, 2.7.6
    • WS-* Components
    • All platforms

    • Moderate

    Description

      In some cases, the <EncryptedSupportingTokens> policy assertion does not encrypt the supporting token. When the policy contains the <EncryptBeforeSigning> assertion, <SignedParts> and <EncryptedParts> assertions along with the <EncryptedSupportingTokens> assertion for a username token, the username token is not encrypted in the outbound SOAP message.

      Attachments

        1. asymbind_patch.txt
          3 kB
          Syed Abdul Wadood
        2. encrypted_supporting_tokens_policy.xml
          2 kB
          Syed Abdul Wadood

        Activity

          People

            coheigea Colm O hEigeartaigh
            sawadood Syed Abdul Wadood
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - 72h
                72h
                Remaining:
                Remaining Estimate - 72h
                72h
                Logged:
                Time Spent - Not Specified
                Not Specified