[
https://issues.apache.org/jira/browse/CXF-9253?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18123379#comment-18123379
]
Freeman Yue Fang commented on CXF-9253:
---------------------------------------
Hi Fabio,
Thanks for the detailed analysis, the diagnosis is spot on.
Firstly, updating a dependency in a patch release is normal for CXF. Since
these two changes only work together, I think the expected solution is to keep
them aligned.
Also, I'd prefer not to make the legacy behaviour the default behind an opt-in
property. The CXF and WSS4J changes are two halves of one hardening change:
signature confirmation now matches on the full signature value instead of a
32-bit hash. Keeping the old format as the default would leave most deployments
on the weaker check until they found and set the property, and we'd also have
to carry, deprecate and later remove that property.
My 2 cents.
Best Regards
Freeman
> 4.1.9 breaks WSS4J WSHandler:checkSignatureConfirmation unless 4.0.2 is used
> ----------------------------------------------------------------------------
>
> Key: CXF-9253
> URL: https://issues.apache.org/jira/browse/CXF-9253
> Project: CXF
> Issue Type: Bug
> Affects Versions: 4.1.9
> Reporter: Fabio Burzigotti
> Priority: Major
> Fix For: 4.1.9
>
>
> WSS4J 4.0.2 introduced two changes related to signature values:
> 1.
> [https://github.com/apache/ws-wss4j/commit/2d4a0e7da15be3e97d83b20b739886cea724b5b4]
> - change in WSHandler, to store strings instead of integers for signature
> values.
> 2.
> [https://github.com/apache/ws-wss4j/commit/347cead366e516710281d1c2a7b58a1513c28ec5]
> - change in WSHandler, to support producers that still use integer signature
> values.
> Apache CXF 4.1.9 behavior changed from 4.1.8, on order to align with (1), see
> [CXF 4.1.9 PR #3529|https://github.com/apache/cxf/pull/3529/changes]
> unconditionally changed the _sendSignatureValues_ format. Accordingly WSS4J
> [was bumped to 4.0.2|https://github.com/apache/cxf/pull/3527]
> The latter represents a hard requirement to depend on such version, but it is
> shipped via a micro release, that would usually be integrated with no further
> changes expected.
> As a confirmation, we've experimented with JBossWS CXF tests and one failure
> is caused by the Apache CXF version bump, unless WSS4J is bumped too (4.0.1
> -> 4.0.2), since the producer doesn't take the 4.0.1 use case (int signature
> values) into account.
> It seems reasonable to introduce the new behavior (storing strings) in 4.1.9,
> but maybe - given it's a patch release - it could preserve the legacy
> behavior as a default, externalize opt-in via configuration property, to
> eventually deprecate and then replace in a minor/major update.
> An alternative could be to have it documented that users upgrading to Apache
> CXF 4.1.9 must also update WSS4J to 4.0.2.
> WDYT?
--
This message was sent by Atlassian Jira
(v8.20.10#820010)