Uploaded image for project: 'WSS4J'
  1. WSS4J
  2. WSS-474

Missing the 'EncodingType' attribute in element built by STRTransformUtil#createBSTX509

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 1.6.9
    • 1.6.12
    • None
    • None

    Description

      I have an incoming request that is being rejected due to a failure in signature validation. The message has a signature over a STR (using key identifier) and is produced by a different security engine (Oracle OSB).
      I suspected some issues / different implementations in the canonicalization process, so I checked logs on the client side and finally compared the canonicalized fragments being digested on both sides.
      The problem is that afaics they look different, basically the fragment on server side seem to be missing the 'EncodingType' attribute in the element that's built in WSS4J (1.6.x) STRTransformUtil#createBSTX509.

      Attachments

        1. STR-KI-REF-EncodingType.diff
          2 kB
          Alessio Soldano

        Activity

          People

            coheigea Colm O hEigeartaigh
            asoldano Alessio Soldano
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: