Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-5133

CXF STS renewed token not itself renewable.

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 2.7.5
    • 2.7.6, 2.6.10
    • STS
    • None
    • Windows XP, Java 1.7

    • Unknown

    Description

      When renewing a security token (a SAML assertion in my test case) the returned token cannot be renewed again (nor can the original). This is true even if the <Renewing/> element is present in the renewal RST message.

      It seems that the SAMLTokenRenewer class does not put the STSConstants.TOKEN_RENEWING_ALLOW and STSConstants.TOKEN_RENEWING_ALLOW_AFTER_EXPIRY properties on the SecurityTOken placed in the token store, which are required for renewal to later take place.

      Attachments

        Activity

          People

            coheigea Colm O hEigeartaigh
            ethan.wallwork Ethan Wallwork
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: