Logo Questions Linux Laravel Mysql Ubuntu Git Menu

WSSE - Sign an element inside soapenv:Header

I want to add wsse:security to my soap message. This is my code:

    public Document signSoapMessage(SOAPMessage message) {
    try {
        Document doc = message.getSOAPBody().getOwnerDocument();
        Crypto crypto = CryptoFactory.getInstance(properties); //File

        WSSecHeader secHeader = new WSSecHeader(doc);

        InputStream inStream = new FileInputStream(properties.getProperty("org.apache.ws.security.crypto.merlin.keystore.file"));

        KeyStore ks = KeyStore.getInstance("PKCS12");
        ks.load(inStream, properties.getProperty("privatekeypassword").toCharArray());

        String alias = ks.aliases().nextElement();
        X509Certificate cert = (X509Certificate) ks.getCertificate(alias);

        WSSecSignature sign = new WSSecSignature(secHeader);
        sign.setUserInfo(properties.getProperty("org.apache.ws.security.crypto.merlin.keystore.alias"), properties.getProperty("privatekeypassword"));
        sign.setKeyIdentifierType(WSConstants.BST_DIRECT_REFERENCE); // Binary Security Token - SecurityTokenReference

        Document signedDoc = sign.build(crypto);

        return signedDoc;
    } catch (SOAPException e) {
        return null;
    } catch (WSSecurityException e) {
        throw new RuntimeException("Error: " + e.getMessage());
    } catch (IOException e) {
        return null;
    } catch (CertificateException e) {
        return null;
    } catch (NoSuchAlgorithmException e) {
        return null;
    } catch (KeyStoreException e) {
        return null;

It works for soapenv:Body (It does add wsu:Id and xmlns:wsu parameters)

But there is an extra element in soapenv:Header and it doesn't sign this element. There is no wsu:Id and xmlns:wsu parameters and lack of one ds:Reference.

Example of not signed soap msg:

<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/">
    <!-- this element should be signed but is not - NOT WORKING -->

   <!-- this element should be signed and It does. -->

I compare soap msg from my program to working soap msg from SoapUI project.

When I post a message to web service I get an error: wsse:InvalidSecurity - Soap Header must be signed. While in SoupUI it does works.

So my question is how can I force WSS4j to sign extra element inside soapenv:Header ?

like image 960
Maciej Pulikowski Avatar asked Jun 21 '19 10:06

Maciej Pulikowski

1 Answers

Ok, I have solved the problem.

Normally this code should work in my situation.

//strange static method from apache o.O
List<WSEncryptionPart> wsEncryptionParts = new ArrayList<>();
WSEncryptionPart somethingPart = new WSEncryptionPart("something","somethingNamespace","");

Nevertheless, It doesn't work. It always throws an exception:

org.apache.wss4j.common.ext.WSSecurityException: No message with ID "noXMLSig" found in resource bundle "org/apache/xml/security/resource/xmlsecurity". Original Exception was a org.apache.wss4j.common.ext.WSSecurityException and message No message with ID "noEncElement" found in resource bundle "org/apache/xml/security/resource/xmlsecurity"

I could not find an answer to what is wrong with my soap message or code.

However, after a time of debugging of org.apache.wss4j.dom.message.WSSecSignature. I felt that something is wrong with the class. I decided to modify a method build(Crypto cr).

public Document build(Crypto cr) throws WSSecurityException {
        LOG.debug("Beginning signing...");
        if (this.getParts().isEmpty()) {

            // --- Here is my edit - And it works!

            WSEncryptionPart aaa = new WSEncryptionPart("something","somethingNamespace","");

            // ----------------------------------

        } else {
            Iterator var2 = this.getParts().iterator();

            while(true) {
                while(true) {
                    if (!var2.hasNext()) {
                        break label33;

                    WSEncryptionPart part = (WSEncryptionPart)var2.next();
                    if (part.getId() == null && "STRTransform".equals(part.getName())) {
                    } else if ("KeyInfo".equals(part.getName()) && "http://www.w3.org/2000/09/xmldsig#".equals(part.getNamespace()) && part.getElement() == null) {
                        Element keyInfoElement = this.getKeyInfoElement();

        List<javax.xml.crypto.dsig.Reference> referenceList = this.addReferencesToSign(this.getParts());
        if (this.bstToken != null) {

        return this.getDocument();

Of course, the solution is quite weak. Yet, at least it works now.

The problem exists in the newest version:

wss4j-ws-security-dom 2.2.2

wss4j-ws-security-common 2.2.2

like image 56
Maciej Pulikowski Avatar answered Nov 03 '22 09:11

Maciej Pulikowski