Logo Questions Linux Laravel Mysql Ubuntu Git Menu

SOAPFaultException "MustUnderstand headers (oasis-200401-wss-wssecurity-secext-1.0.xsd) are not understood"

I try to get information from web service that uses PasswordText WSS type. Firstly, I test it using soapUI and successfully got data. Then I implemented authentication on Java, writing SecurityHandler:

public final class SecurityHandler implements SOAPHandler<SOAPMessageContext> {


public boolean handleMessage(SOAPMessageContext messageContext) {
    boolean outInd = (Boolean) messageContext.get(MessageContext.MESSAGE_OUTBOUND_PROPERTY);
    if (outInd) {
        try {
            WSSecUsernameToken builder = new WSSecUsernameToken();
            builder.setUserInfo(_username, _password);

            Document doc = messageContext.getMessage().getSOAPPart().getEnvelope().getOwnerDocument();
            WSSecHeader secHeader = new WSSecHeader();
            builder.build(doc, secHeader);
        } catch (Exception e) {
            LOGGER.error("Unable to handle SOAP message", e);
            return false;
    return true;


I checked doc object with XMLUtils.PrettyDocumentToString(doc) and saw, that it look likes XML sent by soupUI - all authentication information (login, password, nonce and created time) were on place, mustUnderstand attribute of Security tag was true.

Then I faced with error:

javax.xml.ws.soap.SOAPFaultException: MustUnderstand headers:[{http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd}Security] are not understood

I found advices to remove mustUnderstand attribute from Security tag, but it not helps. Do you have any ideas?


Web service endpoint is on HTTPS.

Policy part from WSDL:

<wsp:Policy wsu:Id="BasicHttpBinding_RelateService_policy">
                            <sp:HttpsToken RequireClientCertificate="false"/>

soapUI request:

<soapenv:Envelope xmlns:ns="http://api.example.com/RelateService/1.0"
        <wsse:Security soapenv:mustUnderstand="1"
            <wsse:UsernameToken wsu:Id="UsernameToken-37"
            <ns:email>[email protected]</ns:email>

My request:

<?xml version="1.0" encoding="UTF-8"?>
<S:Envelope xmlns:S="http://schemas.xmlsoap.org/soap/envelope/">
        <wsse:Security xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd"
            <wsse:UsernameToken wsu:Id="UsernameToken-1">
        <ns5:RetrieveCustomerByEmail xmlns="http://schemas.microsoft.com/2003/10/Serialization/Arrays"
            <ns5:email>[email protected]</ns5:email>
like image 288
Marboni Avatar asked Feb 20 '12 16:02


3 Answers

You could get this error when the service does not handle the headers. The service needs to implement a SOAPHandler with a getHeaders() that would resolve the headers. For the above mentioned fault the correct implementation would be as follows

    public Set<QName> getHeaders() { 
        QName securityHeader = new QName("http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd", 
        HashSet<QName> headers = new HashSet<QName>(); 
        return headers; 

It is also possible to get this when the service is actually not secure, but the client is attempting to use security configuration (possibly using a XWSS security configuration) For this, just check the published wsdl from a browser and make sure it contains the expected security policy (append ?wsdl to its endpoint URL)

like image 74
Joseph Rajeev Motha Avatar answered Oct 01 '22 02:10

Joseph Rajeev Motha

I found the solution. Following dependencies were required:


Good article on this topic and some pitfalls of cxf: http://www.logicsector.com/java/how-to-create-a-wsdl-first-soap-client-in-java-with-cxf-and-maven/

like image 32
Marboni Avatar answered Oct 01 '22 02:10


Here is what worked for me. Basically, it's an application of the idea pronounced by @Joseph Rajeev Motha (although I found it elsewhere, here: https://dwuysan.wordpress.com/2012/04/02/jax-ws-wsimport-and-the-error-mustunderstand-headers-not-understood/#comment-215 ), but his answer does not provide boilerplate, and without it, the answer is pretty mysterious.

Please note that this sequence applies to the standalone case (where you publish an Endpoint yourself).

Step 1

Create a SOAPHandler that will 'understand' the header:

public class WSSESecurityUnderstandPretender implements SOAPHandler<SOAPMessageContext> {
    public Set<QName> getHeaders() {
        final QName securityHeader = new QName(

        final Set<QName> headers = new HashSet<>();

        // notify the runtime that this is handled
        return headers;

    public boolean handleMessage(SOAPMessageContext context) {
        // we must return true, or else the runtime will return
        // wrong wrapper element name (like makeTransfer instead of
        // makeTransferResponse)
        return true;

    public boolean handleFault(SOAPMessageContext context) {
        // we must return true, or else the runtime will return
        // wrong wrapper element name (like makeTransfer instead of
        // makeTransferResponse)
        return true;

    public void close(MessageContext context) {

Step 2

Create a handler-chain.xml file and put it on classpath:

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>

Step 3

Annotate your implementation class (class that is annotated with @WebService) with a reference to the handler chain file:

@HandlerChain(file = "handler-chain.xml")

Step 4

Publish your endpoint:

Endpoint endpoint = Endpoint.publish(url, impl);

An important note

handleMessage() and handleFault() defined by the handler must return true. Otherwise, you will get strange errors like 'Unexpected wrapper element' because a different wrapper element name will be used.

like image 4
Roman Puchkovskiy Avatar answered Oct 01 '22 02:10

Roman Puchkovskiy