You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@cxf.apache.org by "Alessio Soldano (JIRA)" <ji...@apache.org> on 2013/02/07 15:21:17 UTC

[jira] [Assigned] (CXF-4789) EndorsingSupportingTokens do not respect ProtectTokens assertion from paired binding policy

     [ https://issues.apache.org/jira/browse/CXF-4789?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Alessio Soldano reassigned CXF-4789:
------------------------------------

    Assignee: Colm O hEigeartaigh

Assigning to Colm for later moving WSS4J dependency to 1.6.10.
                
> EndorsingSupportingTokens do not respect ProtectTokens assertion from paired binding policy 
> --------------------------------------------------------------------------------------------
>
>                 Key: CXF-4789
>                 URL: https://issues.apache.org/jira/browse/CXF-4789
>             Project: CXF
>          Issue Type: Bug
>          Components: WS-* Components
>    Affects Versions: 2.4.8
>            Reporter: Alessio Soldano
>            Assignee: Colm O hEigeartaigh
>
> I've a wsdl containing both a SymmetricBinding and an EndorsingSupportingTokens policies. The binding one specifies ProtectTokens assertion. As a consequence as per WS-SecurityPolicy 1.2 Section 8.9, the signature for the endorsing supporting token should sign both the first signature and the endorsing token, while it seems the latter is currently not covered.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira