What is signed SOAP request
SOAP request can be signed using SSL certificates. It can be use to sign multiple parts in SOAP request message like, timestamp, WSA address, user name, message body etc.Then this signed message is verified by SOAP service at server where it verifies the parts of message using the available certificates. The certificate which is used by client to sign the request, must be available at server side as a trusted certificate otherwise SOAP service will not accept the request and throw the error like "Request signed by untrusted certificate".
Callback Handler
We need to create the implementation of callback handler where we configure the password details for the certificate keystore. Below is an implementation of the same.public CallbackHandler keystorePasswordCallback() { return (c)->{ WSPasswordCallback pc = (WSPasswordCallback) callbacks[0]; pc.setPassword("keystore_password"); }; }
WSS4J Security Interceptor
We configure a security interceptor which we set the callback handler and configure the parts of Soap message which need to be verified. Also we set a security properties file having the details of JKS, password etc. It is used by interceptor to verify the client's public key which it has as a trusted certificate in it's JKS. Below is the code for security interceptor.@Bean public WSS4JInInterceptor signatureInterceptor() { Map<String, Object> sigProps = new HashMap<>(); sigProps.put(WSHandlerConstants.PW_CALLBACK_REF, keystorePasswordCallback()); sigProps.put(WSHandlerConstants.ACTION, WSHandlerConstants.TIMESTAMP + " " + WSHandlerConstants.USERNAME_TOKEN + " " +WSHandlerConstants.SIGNATURE); sigProps.put(WSHandlerConstants.SIG_PROP_FILE, "security.properties"); }
Security.properties
This security file contains setting for WSS4J for the signature verification. Below are the contents of this file.org.apache.ws.security.crypto.provider=org.apache.ws.security.components.crypto.Merlin org.apache.ws.security.crypto.merlin.keystore.type=jks org.apache.ws.security.crypto.merlin.keystore.password=keystore_password org.apache.ws.security.crypto.merlin.keystore.file=keystore.jks
Setting up interceptor with Spring bus
Spring bus is an extension to CXF and works as interceptor provider. Here we need to register our security interceptor, so it will verify each incoming request. Below is the configuration for spring bus.@Bean(name = Bus.DEFAULT_BUS_ID) public SpringBus springBus() { SpringBus springBus = new SpringBus(); springBus.getInInterceptors().add(signatureInterceptor()); return springBus; }You may check below post on Soap service development using Spring boot & CXF.
https://www.thetechnojournals.com/2020/01/soap-services-with-spring-boot-and.html
You are giving such interesting information.What is a work certificate in Switzerland It is great and beneficial info for us, I really enjoyed reading it. Thankful to you for sharing an article like this.
ReplyDeleteI have seen some posts on this website and I think that your blog is very interesting and has lots of excellent information. Thank you for sharing this. Find cyber Security companies in India.
ReplyDeleteI am grateful to this blog site providing special as well as useful understanding concerning this subject. Switch to NBN
ReplyDelete