Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-5424

JAX-RS Security Code can not validate signed SAML2 bearer assertions without KeyInfo

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 3.0.0-milestone2
    • JAX-RS Security
    • None
    • Unknown

    Description

      Signed SAML2 Bearer assertions may not always have XML Signature KeyInfo elements available. The JAX-RS security code fails to validate such assertions but it should be able to optionally validate them without KeyInfo

      Attachments

        Activity

          People

            Unassigned Unassigned
            sergey_beryozkin Sergey Beryozkin
            Votes:
            1 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: