Uploaded image for project: 'WSS4J'
  1. WSS4J
  2. WSS-301

WSS4J 1.6 incorrectly using XML-Security ResourceResolvers

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 1.6.1
    • 1.6.2
    • None
    • None

    Description

      WSS4J 1.6.x is incorrectly using XML-Security ResourceResolvers to "resolve" DOM Elements for use in signature creation and verification. WSS4J uses a custom IdResolver implementation to call a custom ResourceResolverSpi instance. This IdResolver implementation uses "internal" org.jcp.* classes, and this is causing problems when using JDK 1.6 for signature creation and validation in some containers (Jetty).

      WSS4J should be using the JSR-105 API instead to find and supply elements for signature/creation.

      Attachments

        1. wss4j-1.6.2-SNAPSHOT.jar
          362 kB
          Colm O hEigeartaigh

        Activity

          People

            coheigea Colm O hEigeartaigh
            coheigea Colm O hEigeartaigh
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: