Uploaded image for project: 'WSS4J'
  1. WSS4J
  2. WSS-263

Store secret key from signature processor

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 1.5.10
    • 1.6, 1.5.11
    • WSS4J Axis Integration
    • None

    Description


      When the Signature Processor uses a secret key extracted from a SAML Assertion to verify a signature it does not store the secret key, meaning that the calling code is not able to use the secret key. This causes a problem in WS-Trust, where an endpoint cannot use the secret key as the protection token to communicate with the client.

      Attachments

        Activity

          People

            coheigea Colm O hEigeartaigh
            coheigea Colm O hEigeartaigh
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: